JPMorgan Chase CEO Jamie Dimon does not mince words. Speaking at the Pennsylvania Defense and Innovation Summit on July 15, he called the risks posed by Anthropic’s Mythos AI model a “real issue” and said advanced AI capabilities must be controlled.
His exact phrasing: “You’re giving ballistic missiles to individuals with Mythos.”
That is not hype from a security vendor. That is the CEO of America’s largest bank looking at an AI that can find software vulnerabilities at superhuman scale and saying the technology has outrun the guardrails.
What Is Mythos, Anyway?
Anthropic released Mythos in April 2026 to a small group of select customers, including JPMorgan. The model is designed to identify cybersecurity vulnerabilities in software and infrastructure. Unlike earlier AI tools that could scan code, Mythos reasons across interconnected systems, finds attack chains, and explains their impact in natural language.
Banks love this stuff. Financial institutions are under constant pressure to find and fix flaws before attackers exploit them. AI that automates that work is a competitive advantage.
The problem is that the same capability that helps defenders also helps attackers. A model that can spot a vulnerability in a bank’s payment system can do the same for a criminal targeting that system. The only difference is intent.
The Government Said “Stop”
In June 2026, the US government ordered Anthropic to restrict access to its top models, Fable 5 and Mythos 5, to US nationals only over national security concerns. Foreign researchers, developers, and customers were cut off. Washington worried that adversaries could use these models to find weaknesses in critical infrastructure: hospitals, energy networks, financial systems.
Anthropic later restored access after implementing new safeguards. But the incident showed that the government is no longer treating AI vulnerability scanners as ordinary enterprise tools. They are strategic weapons.
Then on July 14, the White House formally launched Gold Eagle, a coordination group that brings AI developers and critical infrastructure operators together to share vulnerability discoveries. It is a direct response to the exact problem Dimon was describing: when AI finds a flaw, who gets told, and how fast?
Why This Matters Right Now
According to IBM’s 2025 Cost of a Data Breach report, only 13 percent of organisations reported breaches involving AI tools, but 97 percent of those lacked proper AI access controls. Meanwhile, Verizon’s 2026 Data Breach Investigations Report found that vulnerability exploitation has overtaken stolen credentials as the top breach vector, accounting for 31 percent of breaches.
Attackers are using AI to find and exploit holes faster than organisations can patch them. The organisations that will survive this period are not the ones with the fanciest AI tools. They are the ones with basic controls around what AI they use, who can deploy it, and what data it can touch.
What You Should Do
- Audit your AI tools now. Know what your team is using. Consumer AI assistants without enterprise controls are not just privacy risks. They are entry points.
- Segment access. AI tools that can scan your production systems should not also have access to customer data or financial records. Separate duties. Monitor activity.
- Patch exposed orchestration platforms. Tools like Langflow, Ollama backends, and open-source AI workflow builders are favourite targets. If any are internet-facing, restrict access or move them behind VPN.
- Demand vendor transparency. If you are using AI security tools, ask your vendor what controls they have on model export, training data provenance, and who can query the system.
“The skill floor for running ransomware has dropped to whatever it costs to run an agent.” IBM’s 2025 Cost of a Data Breach report said it. JPMorgan’s Dimon just proved it in plain English.
