Dimon Says Anthropic’s Mythos Has Raised Cyber Risk Tenfold for JPMorgan

JPMorgan CEO Jamie Dimon says cyber risk at the bank rose tenfold after Anthropic released Mythos, citing newly exposed vulnerabilities and the need for stronger defenses.
Jamie Dimon speaking at a London technology summit with cybersecurity graphics on a screen Jamie Dimon speaking at a London technology summit with cybersecurity graphics on a screen

Updated:

JPMorgan Chase Chief Executive Jamie Dimon said on Tuesday, October 6, that cyber risk at the bank had risen tenfold following the release of Anthropic’s Mythos AI model. Speaking with Bloomberg TV’s Tom Mackenzie at JPMorgan’s annual technology summit in London, Dimon described cyberattacks as the bank’s biggest risk and said advanced AI had exposed vulnerabilities that were not previously known.

Dimon’s estimate was a warning about the scale of the threat, not a report of a specific breach or a measured increase in attacks. He said Mythos had not yet been released when he identified cyber as JPMorgan’s leading risk in his chairman’s letter. The comparison underscores the concern that tools capable of finding software weaknesses could also help attackers exploit them.

Dimon’s warning follows earlier concerns about Mythos

Anthropic released Mythos in April to a restricted group that included JPMorgan, according to Reuters reporting in July. The model drew attention for its ability to identify cybersecurity vulnerabilities, a capability that can help defenders locate and repair flaws but may also present risks if similar capabilities are misused.

Advertisement

In July, Dimon called the risks posed by Mythos a real issue and said access to advanced AI capabilities needed to be controlled. His latest remarks sharpened the warning by putting a number on the change in cyber risk he believes followed the model’s release. The available reporting does not explain how JPMorgan calculated the tenfold figure, or specify whether it refers to the likelihood of an attack, the potential severity of an incident, or a broader internal assessment.

AI presents both security benefits and hazards

Dimon acknowledged that AI could contribute to advances in areas such as medicine, road safety and materials science. But he also warned that AI agents and systems such as Mythos could create or reveal vulnerabilities, giving malicious actors new ways to cause harm. He said the concern was legitimate, while rejecting what he characterized as an exaggerated or panicked response.

For banks, the stakes include more than the security of internal systems. Financial institutions depend on technology to process transactions and provide services, and a serious cyber incident could disrupt operations or put sensitive data at risk. Dimon did not describe a particular incident at JPMorgan, nor did the report identify a direct financial impact from Mythos.

Cross-industry coalition targets infrastructure risks

Dimon pointed to the Alliance for Critical Infrastructure as part of the response. The organization’s stated mission is to bring together critical-infrastructure operators to strengthen resilience and reduce systemic risk; Dimon chairs its board. The alliance connects sectors whose operations are interdependent, with the aim of improving coordination against threats.

Investing.com described the coalition as a 50-company group spanning six industries, including technology, finance, water and transportation. Its formation reflects the view that cyber threats can extend beyond one company: disruptions to essential services or shared systems may affect multiple sectors. The report did not specify new measures announced at the summit, a timetable for the alliance’s work, or how participating firms would assess its effectiveness.

What remains unclear

Dimon said JPMorgan was working to address the risks, but the public remarks reported from the interview offered few operational details. The company has not, in the reporting available, published a methodology behind the tenfold estimate or said that the figure represents a formal forecast. It is therefore best understood as Dimon’s description of how sharply he believes the threat environment has changed.

His remarks add to wider debate over controlled access to powerful AI systems and the balance between using them to improve cyber defenses and limiting potential misuse. For now, the next steps described publicly are the ongoing defensive work at JPMorgan and the alliance’s broader coordination effort; no specific deadline, new policy or further announcement was identified in the report.

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Advertisement