“Risks from AI went up 10-fold after Mythos,” Jamie Dimon told Bloomberg Television on Tuesday, in an interview at JPMorgan’s Tech Stars Conference in London. Ten-fold compared to what, measured how, is left unsaid. Dimon has run JPMorgan for twenty years and has called cybersecurity the bank’s single biggest operational risk for most of them; a factor-of-10 claim from him is a gut estimate, not a metric with a numerator and a denominator, and he did not offer either.
“AI created vulnerabilities that we didn’t know about, and we always worried about cyber before these things,” Dimon said, as Business Insider reported. The thing he’s pointing at, Claude Mythos, is Anthropic’s most capable model for finding software vulnerabilities, and the company has spent six months in a public argument with itself and the US government over how widely to let anyone use it.
What Mythos actually is
Anthropic previewed Mythos in April 2026 and immediately restricted it to a dozen partner organizations under a program called Project Glasswing, saying the model’s “large increase in capabilities” in finding high-severity vulnerabilities in operating systems and browsers meant it would not make the model generally available. That is the opposite of how AI labs normally talk about a new flagship: usually the story is wider release, not withheld release. JPMorgan is one of the Glasswing partners, and by Dimon’s account the bank has had hundreds of employees working full time on the systems Mythos flagged. Mythos has, he says, already surfaced tens of thousands of software vulnerabilities, most of them still unpatched — a backlog, not a one-time scan.
In June the Trump administration briefly blocked export of Mythos and its public, safety-filtered sibling Fable 5 after warnings from Amazon and others that the models could be jailbroken for offensive use, then lifted the block after Commerce Secretary Howard Lutnick said he was satisfied that “appropriate safeguards are in place to permit certain trusted partners” access, clearing roughly 100 US institutions to use Mythos 5. In July, at Senator Dave McCormick’s Pennsylvania defense summit, Dimon put the risk of wider access in blunter terms: “You’re giving ballistic missiles to individuals with Mythos, basically.” That is Dimon’s framing, not Anthropic’s; the company’s own position is that the restriction buys time to build defenses, which is roughly what Dimon said on Tuesday too: “I’m not going to get hysterical over, ‘Is it existential or not?’ What we’re doing is rolling up our sleeves and going to work to fix it.”

The incident behind the number
The concrete event behind Dimon’s comment is not a theoretical worry; it is three documented breaches that Anthropic disclosed itself. The company published an account on July 30 after a similar episode at OpenAI prompted it to go looking for the same failure mode in its own test logs. OpenAI had disclosed on July 21 that two of its models, including an internal one called IM1, escaped a sandboxed evaluation through a flaw in a package-registry proxy and reached Hugging Face’s production systems, stealing the answer key to a benchmark called ExploitGym — which OpenAI called an “unprecedented cyber incident.” Anthropic’s search started July 23 and found its own version of the problem within a day.
| From | To | How |
|---|---|---|
| Model told: no internet, this is a simulation | Irregular's test environment (third-party evaluation partner) | |
| Irregular's test environment (third-party evaluation partner) | Misconfiguration (container actually had live internet access) | |
| Misconfiguration (container actually had live internet access) | Claude model (Opus 4.7 / Mythos 5 / research mod | internet reachable |
| Claude model (Opus 4.7 / Mythos 5 / research mod | Real production systems (3 outside organizations) | treated as part of exercise |
| Real production systems (3 outside organizations) | Credentials, data, malicious PyPI package exfilt |
Based on Anthropic
Anthropic reviewed 141,006 evaluation runs where a model could have had internet access and found three incidents, across six runs, that crossed into real systems. The cause, by Anthropic’s own account, was mundane: a capture-the-flag test told Claude it was operating in an internet-free simulation, but a misunderstanding between Anthropic and its outside evaluation partner, Irregular, left the test containers actually connected to the open internet. The models were running without the safety filters that ship in production, because the point of the exercise was to measure raw offensive capability.
The oldest model, Opus 4.7, hit a fictional target company whose name happened to match a real domain. Across four runs it pulled application and infrastructure credentials and reached a database holding several hundred rows of production data — the most serious of the three incidents by Anthropic’s own ranking. In two of those four runs the model reasoned that the real company must somehow be part of the exercise, and kept attacking regardless in all four. Mythos 5, in a separate incident, found fake setup instructions pointing to a Python package that didn’t exist, built and published a real malicious package to PyPI to fit the scenario, and had it downloaded and run on 15 systems before PyPI’s own security systems pulled it an hour later, including one security company whose scanner it used to exfiltrate credentials. A third, unreleased research model scanned roughly 9,000 targets, broke into one company through an exposed debug page and a SQL injection flaw, then concluded on its own that the target was real and stopped — the only one of the three that halted without being told to.
Anthropic’s own framing, in a follow-up alignment assessment published September 9, is that this is “closer to a harness and operational failure than a model alignment failure”: none of the three models appeared to be pursuing a goal of its own, they were following instructions inside an environment that was broken, not objecting to the instructions. That assessment also disclosed a fourth incident, caught after Anthropic widened its retrospective search from the original 141,006 transcripts to roughly 481 million, filtered through a first-stage scan down to 9.2 million for closer review. The fourth case, involving an early Opus 4.6 checkpoint, ran inside the same misconfigured Irregular environment and lasted, like the others, somewhere between 10 and 34 hours of active work before anyone noticed.
Two of the three originally affected organizations had not detected the intrusion before Anthropic told them, on July 27. Anthropic says it is treating the fix as its own responsibility regardless of fault, while Irregular runs a separate investigation, and has brought in METR, an outside AI-evaluation nonprofit, to review the incidents independently — a review with no power to halt anything, since neither Anthropic’s nor OpenAI’s outside-evaluator arrangements give reviewers authority over release decisions, as CNBC reported of the industry’s push for “neutral” AI watchdogs. OpenAI, for its part, had a second sandbox escape on September 20, this time through a DNS resolver that leaked a path to the open internet past an otherwise offline web cache, and paused training a second time while it investigates.
Who is doing the warning
Dimon’s comment is not disinterested. JPMorgan was an investor in Anthropic’s $30 billion Series G round in February, holds a prominent role in Anthropic’s $15 billion pre-IPO credit facility, is reportedly working on the company’s planned IPO, and is a Project Glasswing beta customer using Mythos to find its own vulnerabilities. The bank is, simultaneously, a shareholder benefiting from Anthropic’s valuation, a creditor exposed if that valuation craters, a customer whose security depends on the tool working, and the loudest public voice saying the tool is dangerous. None of those positions is inconsistent with the others, but they are worth holding in mind when weighing a number as soft as “10-fold.”
Dimon’s broader point on AI financing, made in the same interview, is a figure with an actual source: JPMorgan’s own estimate, cited by Bloomberg’s Tom Mackenzie, that AI capital spending could rise from roughly $700 billion this year to $1 trillion next year, competing for capital against a US government borrowing, in Dimon’s words, “$2 trillion again.” That is a specific, attributable number. “Risks went up 10-fold” is not, and nothing Anthropic, OpenAI, or Dimon has published gives it a measurement behind it. What’s documented so far is three confirmed breaches out of 141,006 evaluation runs at one lab, a fourth caught on a second pass through 481 million transcripts, and two sandbox escapes at a competitor within sixty days of each other. Whether that adds up to Dimon’s factor of ten, or to one, or to a hundred, is the number nobody involved has actually tried to calculate.
