Frontier AI models compress vulnerability exploitation timelines, requiring bank cybersecurity risk to be repriced
AI summary card
Frontier AI models compress vulnerability exploitation timelines, requiring bank cybersecurity risk to be repriced
J.P. Morgan believes that Frontier Models such as Mythos and GPT-5.5 elevate bank cybersecurity risk into a more concerning and insufficiently priced risk than credit risk, and could drive valuation divergence among global banks.
- The report argues that bank valuations do not yet adequately reflect cybersecurity risk, especially because the lack of comparable disclosures makes it difficult for investors to judge each bank’s level of preparedness.
- Frontier AI models can compress the cycle of zero-day vulnerability discovery and exploitation from months or years to hours, making legacy core systems, third-party supply chains, and concentrated cloud dependencies the main points of vulnerability.
- The core transmission mechanism of cyber incidents may not be credit losses, but rather social-media-amplified deposit outflows and liquidity discounts, which means infrastructure resilience testing and deposit-run liquidity haircut testing deserve greater emphasis.
- Large U.S. G-SIBs may have an advantage in cybersecurity preparedness relative to European and other regional banks because of their higher absolute technology investment and earlier exposure to the latest AI and quantum technologies.
- Regulators have already accelerated their response, including the EU’s DORA, the ECB’s cyber resilience stress tests, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.
Report interpretation
Overview
This report focuses on the impact of frontier AI models on cybersecurity risk in global banks. J.P. Morgan argues that as models such as Mythos and GPT-5.5 significantly improve vulnerability discovery, attack-chain execution, and reverse engineering of closed-source software, the cybersecurity threat facing the banking sector is rising from a traditional operational risk to a core risk that could trigger systemic liquidity pressure. Because bank disclosures are insufficient and infrastructure differences are large, the market has not yet fully priced this risk.
Core views
The core views include: first, cybersecurity risk is more likely than credit risk to become the trigger for the next banking crisis, because cyber incidents may cause deposit runs and liquidity volatility; second, traditional methods of measuring risk through capital frameworks are insufficient, and more attention should be paid to infrastructure resilience and deposit liquidity stress testing; third, technology investment, access to frontier models, legacy-system complexity, and third-party supply-chain management will determine divergence among banks; fourth, large U.S. G-SIBs are relatively advantaged, while European banks may face pressure because their absolute technology budgets are lower and their access to the latest models is slower; fifth, regulators and governments are accelerating the rollout of requirements for cyber resilience, AI supply chains, and frontier-model governance.
Analysis framework
The report uses a thematic research and relative-comparison approach, analyzing AI cyber capability leaps, banking infrastructure vulnerabilities, regional differences in technology investment, regulatory policy progress, and valuation multiples within the same framework. Its judgment is based on AISI’s cyber assessments of Mythos and GPT-5.5, Anthropic’s open-source vulnerability scanning disclosures, comparisons of global bank technology spending, ECB and DORA regulatory initiatives, policy responses in the United States and the United Kingdom, and a risk breakdown covering legacy core systems, open-source libraries, vendor firmware, and concentrated cloud dependence.
Methodology notes
Treat cyberattacks as events that may trigger deposit runs and liquidity discounts, rather than handling them only as capital or credit risks.
The report emphasizes that social media may amplify deposit-flow volatility and recommends assessing banks’ ability to withstand cyber incidents through infrastructure resilience testing and deposit-run liquidity haircut testing.
Use the share of technology spending, absolute technology budget, and the ability to gain earlier access to the latest AI models to measure banks’ cybersecurity preparedness.
The report argues that technology has scale effects; large U.S. banks have higher absolute technology investment and are closer to the AI frontier ecosystem, so they are relatively more capable than global peers of promptly discovering, patching, and defending against new vulnerabilities.
Identify the attack surface created by old code such as COBOL, multi-platform historical M&A, lagging vendor patching, open-source library vulnerabilities, and concentrated cloud dependence.
The report points out that Frontier Models can understand and exploit old code that was previously difficult to audit fully, potentially exposing banks with legacy systems and those dependent on external vendors to higher risk.
Track regulatory responses such as DORA, ECB cyber stress tests, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.
The report believes regulatory focus is shifting from capital stress toward operational resilience, patching efficiency, AI supply-chain transparency, and coordinated remediation of critical software vulnerabilities.
Asset mapping & comparison
Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).
- Large U.S. G-SIB banksRelative beneficiaries / more defensive
- Strengths
- Higher absolute technology spending and closer proximity to the frontier AI and quantum ecosystem, potentially allowing earlier access to the latest models and defensive tools.
- Weaknesses
- Their scale and interconnectedness are high, so if a cyber incident occurs, the systemic impact could also be greater.
- Comparison
- Compared with European banks and peers in other regions, the report believes large U.S. banks have an advantage in cybersecurity preparedness and technology access.
- Risks
- AI-driven reductions in attack costs, concentrated supply-chain dependence, geopolitical attacks, and deposit-flow volatility may still pose major risks.
- European banksRelatively under pressure
- Strengths
- DORA and the ECB cyber resilience stress tests improve regulatory discipline and operational resilience requirements.
- Weaknesses
- Absolute technology budgets are typically lower than those of large U.S. banks, and access to some of the latest frontier AI models is slower.
- Comparison
- The report cites European banks at about 9x 2028E P/E, below U.S. G-SIBs at about 12.5x P/E, and believes the valuation gap can be partly explained by cybersecurity preparedness.
- Risks
- Legacy systems, patch cycles, regulatory compliance costs, and delayed model access may lead to a higher risk premium.
- Japanese megabanksNeutral / follower-type exposure
- Strengths
- Valuation multiples are close to those of U.S. G-SIBs, and they have the resource base of large financial institutions.
- Weaknesses
- The report does not provide evidence of AI model access and technology-investment advantages comparable to those of the United States.
- Comparison
- 2028E P/E is about 12x, below U.S. G-SIBs at about 12.5x but above European banks at about 9x.
- Risks
- If technology investment, patching speed, or frontier-model access lag, they may face cybersecurity repricing risks similar to those of other global banks.
- Banks with heavy legacy core-system and vendor dependenceHigh-risk exposure
- Strengths
- If they have stable customer deposits and sufficient resources, they can still reduce risk through patching, isolation, and resilience testing.
- Weaknesses
- Old code, COBOL systems, multi-platform historical M&A, and lagging third-party firmware patching expand the attack surface.
- Comparison
- Compared with banks that have more modern architectures and higher technology investment, these institutions are more easily exposed to historical vulnerabilities discovered and exploited by AI models.
- Risks
- Zero-day vulnerabilities, supply-chain vulnerabilities, closed-source software reverse exploitation, and patch delays may trigger customer trust and liquidity shocks.
- DeFi/digital asset ecosystemIndirectly affected
- Strengths
- The Ethereum Foundation already has a post-quantum research team and a Lean Ethereum roadmap aimed at achieving more complete post-quantum protection before 2029.
- Weaknesses
- DeFi still depends on cryptography, smart contracts, and open network infrastructure, and quantum computing and AI attacks will expand potential vulnerabilities.
- Comparison
- Both traditional banks and DeFi face AI cyber threats, but DeFi’s dependence on cryptography and open-source components is more direct.
- Risks
- Quantum computing, smart-contract vulnerabilities, key-management failures, and AI-driven attacks may undermine user trust.
- Cybersecurity, cloud, and AI infrastructure vendorsDemand beneficiaries but rising concentration risk
- Strengths
- Project Glasswing shows that AI companies, cloud providers, chipmakers, cybersecurity companies, and financial institutions can collaborate to improve critical software security.
- Weaknesses
- If multiple financial institutions depend on the same AI platform or cloud platform, a single vulnerability may create concentration risk.
- Comparison
- These vendors may benefit from growing bank security investment, but they are also becoming targets of regulatory and systemic-risk scrutiny.
- Risks
- Platform vulnerabilities, insufficient supply-chain transparency, incomplete SBOMs, and synchronized cross-institution attacks may threaten financial stability.
Key data
- Global banks’ technology cost ratioAround 17% of operating expenses on average in 2025Definitions of technology spending are not fully consistent across banks, but this can serve as a starting point for discussions with management about cybersecurity investment.
- European bank cost growth forecastAbout 1.8% per year on average in 2025-28EThe report believes cybersecurity and technology investment needs may create upward pressure, although AI-driven cost savings may partially offset this.
- 2028E valuation multiple comparisonU.S. G-SIBs about 12.5x P/E; European banks about 9x P/E; Japanese megabanks about 12x P/EThe report argues that the valuation premium of U.S. G-SIBs relative to global peers can be partly explained by stronger cybersecurity preparedness and lower implied CoE.
- Mythos cyber capability assessment73% success rate on expert-level hacker tasksAISI’s assessment shows that Mythos can autonomously discover and exploit vulnerabilities and execute multi-stage attack chains.
- Speed of improvement in AI cyber task capabilitySince late 2024, completable task length has roughly doubled every 4.7 monthsAISI had previously estimated in November 2025 that it doubled every 8 months; Mythos and GPT-5.5 significantly exceed that prior trend.
- Anthropic open-source project scanScanned more than 1,000 open-source projects and found 23,019 vulnerabilities, of which 6,202 were high or critical severityThe report uses this to illustrate the systemic exposure of open-source libraries in bank client-facing platforms and internet infrastructure.
- ECB cyber resilience stress testCovered 109 banks in 2024, of which 28 underwent deeper assessmentThis test is more qualitative in nature; the results feed into SREP and generate bank-specific improvement recommendations, without directly affecting Pillar 2 Guidance.
Impact & implications
The investment implication is that bank valuations may increasingly depend on cybersecurity preparedness rather than just short-term earnings. Banks with ample technology investment, sticky deposit bases, large excess deposits, and earlier access to frontier AI and quantum technologies may receive higher valuation multiples and lower implied costs of capital. In contrast, banks with complex legacy systems, heavy vendor dependence, slow patch cycles, insufficient disclosure, and relatively low technology budgets may face greater liquidity and reputational shocks in the next cyber incident. Regulatory pressure may also push banks to increase spending on infrastructure, patch management, authentication, and operational resilience.
Risks
- Frontier Models significantly lower the threshold for zero-day vulnerability discovery and exploitation, enabling attackers to build multi-stage attack chains more quickly.
- Cyber incidents may amplify deposit outflows through social media, triggering liquidity pressure rather than traditional credit risk.
- Legacy core banking systems, old COBOL code, multi-platform historical M&A, and lagging vendor patching expand the attack surface.
- Concentrated dependence on open-source libraries, third-party firmware, AI software supply chains, and cloud platforms may create synchronized cross-institution exposure.
- External use of agentic AI in financial services will expand third-party connections and the automated attack surface.
- Quantum computing may weaken existing cryptographic systems and pose a long-term threat to banks and DeFi markets.
- Geopolitical and state-sponsored cyberattacks are increasing, and banks may face more sophisticated and persistent attackers.
- Rising cybersecurity investment and regulatory compliance requirements may push up costs, especially for banks with lower technology budgets.
What to watch
- Each bank’s technology spending as a share of operating expenses and absolute technology budget, especially differences among large U.S., European, and Japanese banks.
- Whether banks can access the latest frontier models such as Mythos and GPT-5.5, and whether they participate in collaborative defense projects such as Project Glasswing.
- Regulatory developments including the ECB, DORA, SREP, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.
- Bank management disclosures regarding core systems, back-office and middle-office infrastructure, external vendor dependence, and patch cycles.
- Methods for stress-testing liquidity haircuts under deposit-flow volatility, social-media transmission, and cyber incidents.
- The speed of remediation for open-source library and vendor firmware vulnerabilities, SBOM transparency, and concentrated dependence on critical platforms.
- Whether banks reintroduce stronger authentication and control measures such as hardware tokens, security keys, transaction cooling-off periods, and circuit-breaker mechanisms.
- Migration progress of post-quantum cryptography in Ethereum and banking systems.