Security / Jul 16, 2026 / 4 min
The Ballistic Missile on JPMorgan's Payroll
On July 15, Jamie Dimon told a Pennsylvania defense summit that broad access to Anthropic's Mythos AI is like handing out ballistic missiles — while his bank remains the only lender inside Project Glasswing, stress-testing the same model Washington keeps on a guest list.
Jamie Dimon just compared Anthropic's Mythos AI to ballistic missiles at a defense summit where Donald Trump headlined $10 billion in Pennsylvania investments — while JPMorgan remains the only bank authorized to deploy the same model through Project Glasswing. The contradiction is the story: America's biggest lender is stress-testing the weapon its CEO says must never go public.
What Dimon said:
- At Senator Dave McCormick's Pennsylvania Defense and Innovation Summit on July 15, Dimon called Mythos risks "a real issue" and said Washington is "on top of it."
- His line: "You're giving ballistic missiles to individuals with Mythos, basically."
- Reuters and Business Insider reported the remarks from Carlisle's U.S. Army War College, where Trump, Defense Secretary Pete Hegseth, and Palantir's Mike Gallagher also appeared.
What JPMorgan is already doing:
- Anthropic launched Project Glasswing on April 7 with JPMorgan as its only bank among launch partners including AWS, Apple, Google, Microsoft, and NVIDIA.
- The bank uses Mythos Preview to find high-severity software vulnerabilities in its own systems and coordinate with vendors.
- Quartz reported that a month after gaining access, Dimon said the bank had hundreds of employees working full time to strengthen its systems.
- JPMorgan's 2026 technology budget: roughly $19.8 billion, with heavy AI spend.
Why Washington keeps intervening:
- Mythos 5 can identify operating-system vulnerabilities Anthropic itself deemed too dangerous for broad release.
- On June 12, Commerce slapped export controls on Mythos 5 and Fable 5 after Amazon researchers documented a jailbreak that elicited exploit code.
- Anthropic cut access for all users for 18 days. Controls lifted June 30; Mythos 5 returned to a vetted U.S. organization list on June 26.
- House Homeland Security Chair Andrew Garbarino separately said a closed-door Mythos demo showed the model draining bank accounts on command — and admitted 95% of Congress doesn't understand the threat.
The two-tier defense problem:
- Glasswing expanded from ~50 to ~200 organizations in June, but JPMorgan remains the sole named bank with Mythos access.
- UK banks were initially excluded; OpenAI later offered GPT-5.5-Cyber to nine British institutions including HSBC and NatWest.
- Anthropic dropped an NDA that had kept Mythos findings inside Glasswing, freeing JPMorgan to share vulnerabilities with community and regional banks — but only what JPMorgan chooses to pass along.
- Smaller lenders outside the guest list depend on a megabank's goodwill for intelligence about flaws in shared software.
The summit context:
- McCormick's two-day event drew 1,300 attendees and announced nearly $10 billion in defense and technology investments supporting 4,000+ Pennsylvania jobs.
- Dimon spoke on an "Investing in America" panel alongside McCormick, hours before Trump's headline address.
- The setting matters: this wasn't a fintech conference. It was a defense-industrial showcase where AI cyber weapons sat beside shipbuilding and munitions deals.
Convina's view: Dimon's missile metaphor is honest — and accidentally indicting. You cannot warn that Mythos is too dangerous for individuals while your bank is the only lender cleared to aim it at your own code. Glasswing turns cyber defense into a velvet-rope club where JPMorgan gets the weapon, community banks get whatever crumbs get forwarded, and Congress gets a scary demo it still can't regulate. The guest list isn't safety. It's hierarchy.