AI Agents Are Getting More Powerful — And Banks Are Already Preparing for the Risk

 The latest developments in artificial intelligence are showing us something important: the conversation around AI is slowly moving away from simply asking “How powerful is the model?” and toward a much more practical question — “What happens when that power is connected to real-world systems?”

Two developments this week make that shift particularly clear. On one side, JPMorgan Chase CEO Jamie Dimon has warned that Anthropic’s powerful cybersecurity-focused AI model Mythos has dramatically increased the cyber risk landscape. On the other side, South Korea’s Financial Security Institute has introduced a dedicated security-evaluation standard for AI agents used in the financial sector. One development highlights the growing risk; the other shows how institutions are beginning to respond.

A warning from one of the world's biggest banks



Speaking in an interview with Bloomberg TV on October 6, JPMorgan Chase CEO Jamie Dimon said that risks from AI had “gone up 10-fold after Mythos.” He also said that AI has created vulnerabilities that organizations did not previously know existed.

That statement deserves attention, especially because it is coming from the head of one of the world's largest financial institutions. Banks have been dealing with cyberattacks for decades, so cybersecurity is not a new concern for JPMorgan. What has changed is the capability of the tools available to both attackers and defenders.

Dimon's “10-fold” figure should not be interpreted as a scientifically measured global statistic. He was giving his assessment of how the threat landscape has changed, rather than presenting a published study with a defined baseline. But the underlying concern is very real. Anthropic itself has described Mythos as a highly capable cybersecurity model and has restricted access to it through trusted programs rather than making the less-restricted version generally available.

And this is where things become particularly interesting.

When AI can find vulnerabilities faster than humans

Traditional cybersecurity depends heavily on security researchers finding weaknesses, testing them, reporting them, and helping organizations fix them. That process can take a significant amount of time because humans have to investigate thousands of potential weaknesses.

Advanced AI models are beginning to change that equation.

Anthropic's recent cybersecurity program reported that its partners identified at least 129,000 verified software vulnerabilities between April and July 2026, including more than 33,000 rated critical or high severity. Anthropic also said its own scanning found another 5,500 vulnerabilities through October.

That sounds like good news — and in many ways it is. Finding vulnerabilities before criminals find them could make software considerably safer.

But the same capability can become dangerous if it is available to people who want to exploit those vulnerabilities instead of fixing them.

This is the fundamental problem with powerful cyber-capable AI: the technology does not inherently know whether the person using it is trying to protect a system or attack it.

The bigger concern is not just the model

There is another part of this story that is easy to miss.

The risk becomes much larger when a powerful model is connected to an AI agent.

A normal chatbot can explain how something works. An agent can potentially search for information, interact with websites, execute code, call APIs, use credentials and continue working through a multi-step task. Once the model is given these capabilities, the question is no longer simply whether the model can generate a dangerous instruction.

The question becomes: What can the system actually do?

Anthropic's own documentation says that Mythos 5.1 is available only through trusted access programs and that it has been given safeguards specifically designed around cybersecurity and other high-risk capabilities. Anthropic has also reported that earlier Mythos evaluations demonstrated a significant jump in cyber capabilities, including the ability to discover and exploit unknown vulnerabilities in testing environments previously.

That is why Dimon's warning is significant even if we do not take the “10×” number literally. The underlying issue is that the defensive and offensive sides of cybersecurity may both be accelerating at the same time.

South Korea is responding in a very different way

While Dimon is warning about the growing risk, South Korea has taken a concrete regulatory and security step.

The country's Financial Security Institute (FSI) announced on October 7 that it has established a dedicated “Financial Sector AI Agent Security Evaluation” standard for AI agents used in the financial industry.

This is important because an AI agent inside a bank is fundamentally different from an ordinary software application.

An agent might be able to access customer information, communicate with other systems, interact with APIs, perform transactions or make decisions based on information it gathers. If something goes wrong, the consequences can extend far beyond an incorrect chatbot response.

A traditional software bug might cause an application to crash. An AI agent with excessive permissions could potentially take an incorrect action, expose information, interact with the wrong system or continue pursuing a task in an unexpected way.

That creates a new security problem — one that cannot be solved simply by checking whether the underlying model produces accurate answers.

From “AI testing” to “agent testing”

This is probably the most important lesson from South Korea's new standard.

For years, AI evaluation has focused heavily on things such as accuracy, reasoning, coding ability, benchmarks, and safety tests. Those measurements are still important, but they are not enough when AI systems become autonomous.

Financial institutions need to ask questions such as:

What permissions does the agent have?

What happens if it receives a malicious instruction?

Can it access information outside its assigned task?

Can it call an external API without human approval?

Can it recognize when an action is dangerous?

Can the organization stop it immediately if something goes wrong?

These are questions about the agent as a system, not simply the AI model as a piece of software.

South Korea's decision therefore represents a broader movement toward treating AI agents as their own security category within high-risk industries.

The two developments are connected

At first glance, Jamie Dimon's warning and South Korea's new security standard might look like completely separate stories.

They are actually two sides of the same story.

Dimon is essentially saying: the capabilities are becoming powerful enough that the cybersecurity threat landscape is changing.

South Korea is responding: then we need a formal way to evaluate and control these systems before putting them into financial environments.

That combination could become increasingly common.

As AI agents move into banking, healthcare, government, manufacturing, and critical infrastructure, organizations will probably need more than traditional software security. They will need to understand not only whether an AI model is safe, but also what the agent can do when it is given access to real systems.

The future may be about controlling capability, not stopping AI

There is an important distinction here.

Neither of these developments suggests that AI should simply be stopped. In fact, AI could become one of the most useful tools in cybersecurity. A model capable of finding thousands of vulnerabilities could help defenders identify weaknesses before attackers do.

The challenge is controlling who gets access to that capability, what the AI is allowed to do, and how closely its actions are monitored.

That is why Anthropic has created restricted access programs for its most cyber-capable systems, while organizations such as financial institutions are beginning to develop their own security evaluation frameworks.

The next stage of AI development may therefore be less about simply building a smarter model and more about building smarter boundaries around that model.

And perhaps that is the real lesson from these two updates.

The future of AI security will not depend only on how intelligent the AI becomes. It will also depend on how carefully we control what that intelligence is allowed to do.

For banks, governments, and other critical organizations, that distinction could become one of the most important cybersecurity questions of the AI era.

Sources

Post a Comment

0 Comments