AI’s Risk to Financial Systems
This is an edition of The Atlantic Daily, a newsletter that guides you through the biggest stories of the day, helps you discover new ideas, and recommends the best in culture.
Sign up for it here.
Today’s AI agents have become exceptional hackers, and they’re already posing a threat to some of the most important infrastructure in modern life: banks.
In both finance and tech, industry leaders are well aware of the dangers, and they’re gearing up for a fight.
Earlier this year, as Anthropic prepared to release a powerful new model called Mythos, the firm gave an early preview of the AI to a select group of companies, aiming to help them shore up their defenses.
JPMorganChase was on the list, and more banks were reportedly added as Anthropic expanded the program.
After the rollout, Treasury Secretary Scott Bessent and then–Fed Chair Jerome Powell met with the heads of Bank of America, Citigroup, Goldman Sachs, and other major financial institutions to discuss the potential implications of the new model, which Anthropic claimed could “surpass all but the most skilled humans at finding and exploiting software vulnerabilities.” What makes AI agents different from past cybersecurity threats is that they move at machine speeds and can be summoned in groups.
These bots can attack in swarms, hunting for cracks in companies’ back-end systems.
The Office of the Comptroller of the Currency, which oversees many U.S. banks, wrote in a report to Congress this summer that AI has increased the “speed, scale, and sophistication of cyber-attacks targeting financial institutions.” Research from last year suggests that finance is likelier than other industries to face AI-enabled cyberattacks, but we can already see these threats playing out in the tech sector.
Tech companies typically send out weekly software patches—updates and bug fixes, essentially—on what’s known as Patch Tuesday.
In the age of agentic threats, the volume of those updates has ballooned.
Microsoft patched nearly 1,000 issues earlier this month, an all-time record.
The trend was accelerating before Mythos arrived, but, per J.P.
Morgan’s analysis , the most advanced models have dramatically changed the cyber-risk landscape, leading to a “tsunami of patches.” Insiders have developed a word for it: “Patchmaggedon.” There’s also the risk that AI companies might lose control of the agents they send out into the world.
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theatlantic.com — the content belongs to The Atlantic.