JPMorgan Chase CEO Jamie Dimon said the cybersecurity risks facing financial institutions have increased dramatically with the emergence of more capable artificial intelligence systems, singling out Anthropic’s Mythos model as a major escalation in the threat landscape.
“The risks went up 10-fold after Mythos,” Dimon told Bloomberg TV on Tuesday.
“AI created vulnerabilities that we didn’t know about, and we always worried about cyber before these things,” he added.
Register for the next Tekedia Mini-MBA.
Register for Tekedia AI in Business Masterclass.
Join Tekedia Capital Syndicate and co-invest in great global startups.
The assertion is considered weighty because cybersecurity has long ranked among Dimon’s most serious concerns for JPMorgan, one of the world’s largest banks. The growing capabilities of AI systems are now changing that risk from a familiar problem of defending networks and systems into a more dynamic contest in which attackers can potentially discover vulnerabilities, automate attacks, and adapt faster.
Dimon’s warning also comes as frontier AI developers face increasing scrutiny over whether their most advanced models can be reliably controlled when given greater autonomy.
The concern surrounding Mythos is not simply that AI can generate malicious code. More capable models can operate as agents, allowing them to perform sequences of tasks with less human intervention. That raises the potential for AI systems to identify weaknesses, interact with computer environments, and pursue objectives at a speed and scale that conventional cybersecurity teams may struggle to match.
Dimon acknowledged the seriousness of that possibility but rejected the idea that businesses should respond with panic.
“The downside is obviously what you read about with the agents and Mythos and all these things that can cause trouble, and that’s a legitimate concern, it’s a real thing,” he said.
“I’m not going to get hysterical over, ‘Is it existential or not?’ What we’re doing is rolling up our sleeves and going to work to fix it,” he added.
AI Changes The Cybersecurity Equation
For banks, the significance of capable AI extends across both offensive and defensive cybersecurity. Financial institutions already operate under constant pressure from ransomware, phishing, fraud, credential theft, and attacks against critical infrastructure. AI can potentially lower the cost and technical expertise required to conduct some of those attacks while also allowing defenders to process much larger volumes of security data.
The problem is that the same technology can therefore strengthen both sides of the contest.
Dimon’s comments suggest that JPMorgan is seriously concerned about vulnerabilities that conventional security systems may not have been designed to detect. AI systems can interact with software in ways that expose unexpected weaknesses, potentially creating attack surfaces that emerge only when advanced models are given access to tools, code repositories, or external systems.
“AI created vulnerabilities that we didn’t know about,” Dimon said.
The observation points to a problem beyond the traditional arms race between hackers and cybersecurity teams. Companies must now consider whether the deployment of AI itself creates new vulnerabilities inside systems that previously appeared secure.
The issue becomes more complicated as companies move from using AI as a passive assistant toward deploying autonomous agents capable of executing tasks. An AI model that simply generates text presents a different security profile from one that can access databases, write and execute code, communicate with external services, or make decisions on behalf of a company. Each additional capability can create another pathway through which an attacker could exploit the system or manipulate its behavior.
Frontier AI Safety Concerns Intensify
Dimon is the latest prominent business executive to warn about the risks accompanying more powerful AI models. His comments come amid broader debate over the safety of frontier AI systems, particularly following separate incidents disclosed by Anthropic and OpenAI during safety testing that raised questions about how reliably advanced models can be constrained.
Those episodes have contributed to renewed calls from researchers, technology executives and some lawmakers for stronger safeguards and greater international coordination around frontier AI development.
The debate is increasingly moving beyond concerns about misinformation or job displacement toward the possibility that highly capable models could be misused to conduct cyberattacks or amplify other forms of malicious activity. Cybersecurity is particularly sensitive because AI does not necessarily need to discover an entirely new form of attack to create greater danger. Making existing techniques faster, cheaper and more accessible could be enough to materially change the threat environment.
For a global bank such as JPMorgan, the implications extend across a vast technology infrastructure, including customer systems, payment networks, trading platforms, internal applications and third-party providers. That helps explain why Dimon is framing the issue as an operational problem that requires continuous investment rather than as a question that can be settled by determining whether AI represents an “existential” threat.
The Financial Sector Faces A Dual Challenge
JPMorgan and other financial institutions also have an unusual position in the AI debate because they are simultaneously major users of the technology and potential targets of AI-enabled attacks. Banks are using AI for fraud detection, customer service, software development, risk analysis, and other functions. Greater adoption can improve efficiency and security in some areas, but it also increases the number of AI systems that need to be secured, resulting in a difficult trade-off.
Restricting AI too aggressively could prevent financial institutions from gaining the defensive and productivity benefits of the technology. Moving too quickly could expose sensitive systems to vulnerabilities that companies have not yet learned how to identify.
Dimon’s response is essentially to treat the problem as a new phase of cybersecurity rather than a reason to abandon AI.
His warning that the risk “went up 10-fold after Mythos” points to the speed at which the threat landscape may be changing. His subsequent comments suggest that JPMorgan’s approach will be to increase defensive capabilities as AI becomes more powerful.
The broader implication is that AI security may become as important as model performance in determining how quickly businesses can deploy autonomous systems. As companies give AI models access to more sensitive data, software, and decision-making processes, cybersecurity safeguards will increasingly determine the practical limits of adoption.
The question for Dimon is not whether advanced AI poses risks. He has already made clear that he believes it does. The more immediate challenge is whether banks and other large organizations can build security systems capable of keeping pace with models that are becoming more capable, autonomous, and difficult to predict.



