A few years back, anyone who warned that AI could become a national security threat sounded like they’d watched one too many sci-fi movies. That changed this week when Jamie Dimon, CEO of JPMorgan Chase, stood up at a defense summit and said what a lot of us in security have been thinking quietly: advanced AI models are now powerful enough to find software vulnerabilities better than most human analysts, and that makes them dangerous in the wrong hands.
Dimon’s exact words: “you’re giving ballistic missiles to individuals with Mythos.”
He wasn’t being dramatic. He was talking about Anthropic’s Mythos AI, which JPMorgan had early access to. The model is genuinely impressive at identifying security flaws. Banks raced to get it because it scans code and spots weaknesses faster than a room full of security engineers. That’s the promise. The problem is the same capability that finds a bug in a bank’s payment system could also find it in a hospital’s patient records system, a power plant’s control software, or a water treatment facility’s monitoring system.
Government In, Government Out
Here’s what actually happened. Anthropic released Mythos in April 2026 to a small group that included JPMorgan. By June, the U.S. government ordered Anthropic to restrict access to its top models, including Mythos 5 and Fable 5, to U.S. persons only. The concern was that foreign nationals could use the model to discover and weaponize vulnerabilities in critical infrastructure. A few weeks later, after Anthropic added safeguards, restrictions were lifted. Then reports emerged that CISA, the Cybersecurity and Infrastructure Security Agency, was already using Mythos to scan government software.
That sequence tells you everything about the double-edged nature of powerful AI. The government blocks it, then the government adopts it. Banks want it, then banks worry about it. The technology isn’t good or evil, but it is powerful, and we’re still figuring out the guardrails.
The Numbers Are Already Bad
78% of organizations are reporting AI incidents or vulnerabilities, according to Enterprise Times this week. Trend Micro’s latest research found that AI systems were ground zero for cyber risk in the second half of 2025, with critical flaws rising across every layer of the AI stack. Lava Labs, a security research firm, just released a report on AI data centers being built faster than they can be secured. The top risk: firmware and hardware integrity. The model runs on hardware that can be compromised below the operating system level, where most security tools can’t see it.
What You Can Actually Do
If you’re running any system that uses AI, here are three practical steps.
Know what data your AI can touch. An AI coding assistant connected to your source code is a prime target. An AI chatbot with access to customer records is a liability. These aren’t hypotheticals. Researchers showed earlier this month that a specifically crafted GitHub Issue could trick AI-powered workflows into exposing private repository data without authentication.
Lock down shadow AI on endpoints. Trend Micro researchers warned that shadow AI, where employees use unauthorized AI tools, is becoming the biggest endpoint risk. Those tools often send sensitive company data to external APIs you didn’t approve.
Ask your vendors hard questions. If you’re buying an enterprise AI product, ask what vulnerabilities it can discover, who has access to the model, and what happens when it finds a zero-day. Most vendors won’t have good answers. The WEF 2026 report found that 87% of executives now identify AI vulnerabilities as the fastest-growing cyber risk, but confidence and actual controls are miles apart.
The regulatory picture is moving fast. The White House launched its Gold Eagle initiative this month, designed to speed up vulnerability detection using AI and coordinate responses between government and critical infrastructure operators. CISA is actively using Mythos. The UK rolled out an agentic AI defence plan. Governments are trying to build the framework while racing to use the tools themselves.
That’s the uncomfortable truth. The people worried about AI risk are also the ones deploying it fastest.
“Advanced AI is now better at finding software vulnerabilities than human analysts. The question is whether we can control who uses that capability, and the honest answer so far is no.”
