Quick Summary
Covering the latest research from top Wall Street investment banks

Frontier AI models compress vulnerability exploitation timelines, requiring bank cybersecurity risk to be repriced

Institution
J.P. Morgan
Date
2026-06-29
Authors
Amit Ranjan
Company
-
Ticker
-
Industry
Banks/Financial Services
Rating
-
NeutralLow confidenceThe report argues that frontier AI models significantly increase the speed of zero-day vulnerability discovery and exploitation, and that cybersecurity could trigger banking crises through deposit outflows and liquidity pressure; large U.S. G-SIBs with higher technology investment and earlier access to models are relatively advantaged.
AuthorsAmit Ranjan
CoverageEurope、Other
Business segmentsGlobal banks、European banks、U.S. large banks、Japanese megabanks、Core banking systems、Cloud and third-party ICT supply chain、DeFi/digital currencies
Research firm divisions/subsidiariesJ.P. Morgan Securities plc(Other)、JPMorgan Chase & Co.(Other)

AI summary card

Frontier AI models compress vulnerability exploitation timelines, requiring bank cybersecurity risk to be repriced

J.P. Morgan believes that Frontier Models such as Mythos and GPT-5.5 elevate bank cybersecurity risk into a more concerning and insufficiently priced risk than credit risk, and could drive valuation divergence among global banks.

This report does not provide stock ratings, target prices, or upside potential; its core view is that cybersecurity preparedness will drive valuation divergence among banks, and large U.S. G-SIBs may earn a relative valuation premium due to lower implied CoE and stronger technology investment.
Global banksCybersecurityFrontier ModelsMythosGPT-5.5AI riskLiquidity riskG-SIBDORAQuantum computing
  • The report argues that bank valuations do not yet adequately reflect cybersecurity risk, especially because the lack of comparable disclosures makes it difficult for investors to judge each bank’s level of preparedness.
  • Frontier AI models can compress the cycle of zero-day vulnerability discovery and exploitation from months or years to hours, making legacy core systems, third-party supply chains, and concentrated cloud dependencies the main points of vulnerability.
  • The core transmission mechanism of cyber incidents may not be credit losses, but rather social-media-amplified deposit outflows and liquidity discounts, which means infrastructure resilience testing and deposit-run liquidity haircut testing deserve greater emphasis.
  • Large U.S. G-SIBs may have an advantage in cybersecurity preparedness relative to European and other regional banks because of their higher absolute technology investment and earlier exposure to the latest AI and quantum technologies.
  • Regulators have already accelerated their response, including the EU’s DORA, the ECB’s cyber resilience stress tests, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.

Report interpretation

Overview

This report focuses on the impact of frontier AI models on cybersecurity risk in global banks. J.P. Morgan argues that as models such as Mythos and GPT-5.5 significantly improve vulnerability discovery, attack-chain execution, and reverse engineering of closed-source software, the cybersecurity threat facing the banking sector is rising from a traditional operational risk to a core risk that could trigger systemic liquidity pressure. Because bank disclosures are insufficient and infrastructure differences are large, the market has not yet fully priced this risk.

Core views

The core views include: first, cybersecurity risk is more likely than credit risk to become the trigger for the next banking crisis, because cyber incidents may cause deposit runs and liquidity volatility; second, traditional methods of measuring risk through capital frameworks are insufficient, and more attention should be paid to infrastructure resilience and deposit liquidity stress testing; third, technology investment, access to frontier models, legacy-system complexity, and third-party supply-chain management will determine divergence among banks; fourth, large U.S. G-SIBs are relatively advantaged, while European banks may face pressure because their absolute technology budgets are lower and their access to the latest models is slower; fifth, regulators and governments are accelerating the rollout of requirements for cyber resilience, AI supply chains, and frontier-model governance.

Analysis framework

The report uses a thematic research and relative-comparison approach, analyzing AI cyber capability leaps, banking infrastructure vulnerabilities, regional differences in technology investment, regulatory policy progress, and valuation multiples within the same framework. Its judgment is based on AISI’s cyber assessments of Mythos and GPT-5.5, Anthropic’s open-source vulnerability scanning disclosures, comparisons of global bank technology spending, ECB and DORA regulatory initiatives, policy responses in the United States and the United Kingdom, and a risk breakdown covering legacy core systems, open-source libraries, vendor firmware, and concentrated cloud dependence.

Methodology notes

  • Risk frameworkCybersecurity-driven liquidity stress framework

    Treat cyberattacks as events that may trigger deposit runs and liquidity discounts, rather than handling them only as capital or credit risks.

    The report emphasizes that social media may amplify deposit-flow volatility and recommends assessing banks’ ability to withstand cyber incidents through infrastructure resilience testing and deposit-run liquidity haircut testing.

  • Peer comparisonComparison of technology spending and frontier-model access

    Use the share of technology spending, absolute technology budget, and the ability to gain earlier access to the latest AI models to measure banks’ cybersecurity preparedness.

    The report argues that technology has scale effects; large U.S. banks have higher absolute technology investment and are closer to the AI frontier ecosystem, so they are relatively more capable than global peers of promptly discovering, patching, and defending against new vulnerabilities.

  • Infrastructure assessmentLegacy core systems and supply-chain exposure analysis

    Identify the attack surface created by old code such as COBOL, multi-platform historical M&A, lagging vendor patching, open-source library vulnerabilities, and concentrated cloud dependence.

    The report points out that Frontier Models can understand and exploit old code that was previously difficult to audit fully, potentially exposing banks with legacy systems and those dependent on external vendors to higher risk.

  • Policy trackingGlobal cyber resilience regulatory watch

    Track regulatory responses such as DORA, ECB cyber stress tests, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.

    The report believes regulatory focus is shifting from capital stress toward operational resilience, patching efficiency, AI supply-chain transparency, and coordinated remediation of critical software vulnerabilities.

Asset mapping & comparison

Structured mapping from thesis to named assets (strengths, weaknesses, peers, risks).

  • Large U.S. G-SIB banks
    Relative beneficiaries / more defensive
    Strengths
    Higher absolute technology spending and closer proximity to the frontier AI and quantum ecosystem, potentially allowing earlier access to the latest models and defensive tools.
    Weaknesses
    Their scale and interconnectedness are high, so if a cyber incident occurs, the systemic impact could also be greater.
    Comparison
    Compared with European banks and peers in other regions, the report believes large U.S. banks have an advantage in cybersecurity preparedness and technology access.
    Risks
    AI-driven reductions in attack costs, concentrated supply-chain dependence, geopolitical attacks, and deposit-flow volatility may still pose major risks.
  • European banks
    Relatively under pressure
    Strengths
    DORA and the ECB cyber resilience stress tests improve regulatory discipline and operational resilience requirements.
    Weaknesses
    Absolute technology budgets are typically lower than those of large U.S. banks, and access to some of the latest frontier AI models is slower.
    Comparison
    The report cites European banks at about 9x 2028E P/E, below U.S. G-SIBs at about 12.5x P/E, and believes the valuation gap can be partly explained by cybersecurity preparedness.
    Risks
    Legacy systems, patch cycles, regulatory compliance costs, and delayed model access may lead to a higher risk premium.
  • Japanese megabanks
    Neutral / follower-type exposure
    Strengths
    Valuation multiples are close to those of U.S. G-SIBs, and they have the resource base of large financial institutions.
    Weaknesses
    The report does not provide evidence of AI model access and technology-investment advantages comparable to those of the United States.
    Comparison
    2028E P/E is about 12x, below U.S. G-SIBs at about 12.5x but above European banks at about 9x.
    Risks
    If technology investment, patching speed, or frontier-model access lag, they may face cybersecurity repricing risks similar to those of other global banks.
  • Banks with heavy legacy core-system and vendor dependence
    High-risk exposure
    Strengths
    If they have stable customer deposits and sufficient resources, they can still reduce risk through patching, isolation, and resilience testing.
    Weaknesses
    Old code, COBOL systems, multi-platform historical M&A, and lagging third-party firmware patching expand the attack surface.
    Comparison
    Compared with banks that have more modern architectures and higher technology investment, these institutions are more easily exposed to historical vulnerabilities discovered and exploited by AI models.
    Risks
    Zero-day vulnerabilities, supply-chain vulnerabilities, closed-source software reverse exploitation, and patch delays may trigger customer trust and liquidity shocks.
  • DeFi/digital asset ecosystem
    Indirectly affected
    Strengths
    The Ethereum Foundation already has a post-quantum research team and a Lean Ethereum roadmap aimed at achieving more complete post-quantum protection before 2029.
    Weaknesses
    DeFi still depends on cryptography, smart contracts, and open network infrastructure, and quantum computing and AI attacks will expand potential vulnerabilities.
    Comparison
    Both traditional banks and DeFi face AI cyber threats, but DeFi’s dependence on cryptography and open-source components is more direct.
    Risks
    Quantum computing, smart-contract vulnerabilities, key-management failures, and AI-driven attacks may undermine user trust.
  • Cybersecurity, cloud, and AI infrastructure vendors
    Demand beneficiaries but rising concentration risk
    Strengths
    Project Glasswing shows that AI companies, cloud providers, chipmakers, cybersecurity companies, and financial institutions can collaborate to improve critical software security.
    Weaknesses
    If multiple financial institutions depend on the same AI platform or cloud platform, a single vulnerability may create concentration risk.
    Comparison
    These vendors may benefit from growing bank security investment, but they are also becoming targets of regulatory and systemic-risk scrutiny.
    Risks
    Platform vulnerabilities, insufficient supply-chain transparency, incomplete SBOMs, and synchronized cross-institution attacks may threaten financial stability.

Key data

  • Global banks’ technology cost ratioAround 17% of operating expenses on average in 2025Definitions of technology spending are not fully consistent across banks, but this can serve as a starting point for discussions with management about cybersecurity investment.
  • European bank cost growth forecastAbout 1.8% per year on average in 2025-28EThe report believes cybersecurity and technology investment needs may create upward pressure, although AI-driven cost savings may partially offset this.
  • 2028E valuation multiple comparisonU.S. G-SIBs about 12.5x P/E; European banks about 9x P/E; Japanese megabanks about 12x P/EThe report argues that the valuation premium of U.S. G-SIBs relative to global peers can be partly explained by stronger cybersecurity preparedness and lower implied CoE.
  • Mythos cyber capability assessment73% success rate on expert-level hacker tasksAISI’s assessment shows that Mythos can autonomously discover and exploit vulnerabilities and execute multi-stage attack chains.
  • Speed of improvement in AI cyber task capabilitySince late 2024, completable task length has roughly doubled every 4.7 monthsAISI had previously estimated in November 2025 that it doubled every 8 months; Mythos and GPT-5.5 significantly exceed that prior trend.
  • Anthropic open-source project scanScanned more than 1,000 open-source projects and found 23,019 vulnerabilities, of which 6,202 were high or critical severityThe report uses this to illustrate the systemic exposure of open-source libraries in bank client-facing platforms and internet infrastructure.
  • ECB cyber resilience stress testCovered 109 banks in 2024, of which 28 underwent deeper assessmentThis test is more qualitative in nature; the results feed into SREP and generate bank-specific improvement recommendations, without directly affecting Pillar 2 Guidance.

Impact & implications

The investment implication is that bank valuations may increasingly depend on cybersecurity preparedness rather than just short-term earnings. Banks with ample technology investment, sticky deposit bases, large excess deposits, and earlier access to frontier AI and quantum technologies may receive higher valuation multiples and lower implied costs of capital. In contrast, banks with complex legacy systems, heavy vendor dependence, slow patch cycles, insufficient disclosure, and relatively low technology budgets may face greater liquidity and reputational shocks in the next cyber incident. Regulatory pressure may also push banks to increase spending on infrastructure, patch management, authentication, and operational resilience.

Risks

  • Frontier Models significantly lower the threshold for zero-day vulnerability discovery and exploitation, enabling attackers to build multi-stage attack chains more quickly.
  • Cyber incidents may amplify deposit outflows through social media, triggering liquidity pressure rather than traditional credit risk.
  • Legacy core banking systems, old COBOL code, multi-platform historical M&A, and lagging vendor patching expand the attack surface.
  • Concentrated dependence on open-source libraries, third-party firmware, AI software supply chains, and cloud platforms may create synchronized cross-institution exposure.
  • External use of agentic AI in financial services will expand third-party connections and the automated attack surface.
  • Quantum computing may weaken existing cryptographic systems and pose a long-term threat to banks and DeFi markets.
  • Geopolitical and state-sponsored cyberattacks are increasing, and banks may face more sophisticated and persistent attackers.
  • Rising cybersecurity investment and regulatory compliance requirements may push up costs, especially for banks with lower technology budgets.

What to watch

  • Each bank’s technology spending as a share of operating expenses and absolute technology budget, especially differences among large U.S., European, and Japanese banks.
  • Whether banks can access the latest frontier models such as Mythos and GPT-5.5, and whether they participate in collaborative defense projects such as Project Glasswing.
  • Regulatory developments including the ECB, DORA, SREP, the U.S. AI cybersecurity clearinghouse, and cooperation between the BoE and AISI.
  • Bank management disclosures regarding core systems, back-office and middle-office infrastructure, external vendor dependence, and patch cycles.
  • Methods for stress-testing liquidity haircuts under deposit-flow volatility, social-media transmission, and cyber incidents.
  • The speed of remediation for open-source library and vendor firmware vulnerabilities, SBOM transparency, and concentrated dependence on critical platforms.
  • Whether banks reintroduce stronger authentication and control measures such as hardware tokens, security keys, transaction cooling-off periods, and circuit-breaker mechanisms.
  • Migration progress of post-quantum cryptography in Ethereum and banking systems.
Zhejiang ICP No. 2022035445-5
Disclaimer: Market data, charts, indicators, research views, and other information provided on this website are intended solely for information display, research communication, and educational reference. They should not be regarded as personalized investment advice, securities recommendations, trading instructions, solicitations, or guarantees of return. While we strive to improve the reliability of our data and content, such information may still be subject to delays, errors, incompleteness, or untimely updates due to source differences, methodological limitations, system processing, or market volatility. Users should exercise independent judgment based on their own circumstances and bear all risks and responsibilities arising from the use of this website.

Settings

Sign in to view recent logins