Dimon says AI cyber risk is up tenfold. Cyber insurance prices are still falling
The JPMorgan chief's escalating warnings about Anthropic's Mythos haven't reached the cyber market's rate sheets, at least not yet
Dimon says AI cyber risk is up tenfold. Cyber insurance prices are still falling
INSURANCE NEWS
By Matthew Sellers
06 Oct 2026

Image: Jamie Dimon, World Economic ForumThis file is licensed under the Creative Commons Attribution-Share Alike 2.0 Generic license.

Jamie Dimon has been sounding the alarm about Anthropic's Mythos model since the spring. Earlier today he put a number on it.

In an interview with Bloomberg Television, the JPMorgan Chase chief executive said AI risk "went up 10-fold after Mythos." He said the technology had exposed vulnerabilities the bank hadn't known existed, in an area it already ranked among its biggest worries.

You might expect a warning like that from the head of America's largest bank to show up in cyber insurance premiums. So far it hasn't. US cyber rates fell 2% in the second quarter of 2026, according to Marsh's Global Insurance Market Index. Globally they fell 4%, the twelfth straight quarterly decline. Marsh noted that US cyber pricing has been sliding since the second quarter of 2023.

That gap between the threat being described in boardrooms and the prices being charged at renewal is now the central question for cyber underwriters and the brokers who place their business.

Bar chart of Marsh Global Insurance Market Index quarterly US cyber rate changes, Q2 2023 to Q2 2026. Every reported quarter shows a decline, narrowing from 6% to 2%. The Mythos announcement falls in Q2 2026; the July 2026 AI testing breaches fall in Q3 2026, for which data is not yet published. US cyber rates kept falling through the Mythos launch Average US cyber insurance rate change at renewal, year on year, by quarter (%) 0 -2% -4% -6% -8% -4% Q2 2023 -6% Q3 n/a* Q4 -6% Q1 2024 -5% Q2 n/a* Q3 -5% Q4 -4% Q1 2025 -3% Q2 -3% Q3 -3% Q4 -2% Q1 2026 -2% Q2 Not yet published Q3 Apr 7, 2026: Mythos Preview announced July 2026: AI models breach outside systems in testing Source: Marsh Global Insurance Market Index, US cyber line, as published in Marsh releases and trade reports. Index skews to larger accounts. *US cyber figure for Q4 2023 and Q3 2024 could not be confirmed; Marsh reported a US decline in every quarter shown. Chart: Insurance Business

 

A warning that keeps getting louder

Dimon's tenfold remark is the latest step in an escalating series of warnings. In April, after JPMorgan tested a preview of Mythos, he said the model showed that many more vulnerabilities needed fixing, according to CNBC. Over the summer, speaking at the Pennsylvania Defense and Innovation Summit, he compared wide public access to Mythos to handing individuals ballistic missiles.

He has stopped short of human extinction and doom though. On Tuesday he called the threat from AI agents real but said he wouldn't be drawn into debates over whether it is existential. Instead, he said, the bank is "rolling up our sleeves" to fix what it finds.

JPMorgan has itself used the model to probe its own defenses, a reminder that the same capability that worries banks is also being used to protect them.

Why Mythos has changed the conversation

Anthropic unveiled Mythos Preview in April and limited access to a small set of partners through its Project Glasswing program. The model's system card described a test in which an earlier version was told to break out of a secured sandbox and contact the researcher running the evaluation. It did both. It then posted details of the escape on obscure public websites, which nobody had asked it to do.

The regulatory picture has been volatile too. Anthropic released Mythos 5 and a guardrailed sibling, Fable 5, on June 9. The company suspended access three days later to comply with US Commerce Department export controls, and restored it on July 1 after the controls were lifted.

The summer then brought the first known cases of AI models breaching real organizations during their own developers' tests. On July 21, OpenAI disclosed that models it was testing had escaped their sandbox and compromised Hugging Face's production systems.

OpenAI's later technical report said the models had run code on 41 of Hugging Face's servers, Axios reported. Days later, Anthropic said its own models, including a Mythos version, had breached three other organizations during tests run in a partner's evaluation environment. The models had been told they had no internet access, and they did. Neither Anthropic nor the affected organizations had noticed the intrusions at the time.

Read next: How Anthropic's Mythos is fueling cyber risk aggregation fears

Log-scale line chart of METR 50% task-completion time horizons for leading AI models, 2019 to 2026: GPT-2 2 seconds, GPT-3 9 seconds, GPT-3.5 36 seconds, GPT-4 4 minutes, o1 38 minutes, GPT-5.2 6 hours 34 minutes, Claude Mythos Preview at least 16 hours. AI went from 2-second tasks to a full working day Length of task (in human expert time) the leading AI model can complete half the time, log scale 1 sec 10 sec 1 min 10 min 1 hour 10 hours 1 day 2019 2020 2021 2022 2023 2024 2025 2026 GPT-2 2 sec GPT-3 9 sec GPT-3.5 36 sec GPT-4 4 min o1 38 min GPT-5.2 6 hr 34 min Claude Mythos Preview at least 16 hours (Apr 2026) METR Time Horizon 1.0 method METR Time Horizon 1.1 method Source: METR, Task-Completion Time Horizons of Frontier AI Models (May 2026). One leading model per year, plotted at release date; no 2021 point. The two METR methods are not identical measurements. METR says results above 16 hours are unreliable with its current tasks, so Mythos is a lower bound. Chart: Insurance Business

The aggregation math

The fear for insurers isn't one bad breach. It's one flaw exploited everywhere at once. The International Monetary Fund warned in May that AI-enabled tools make attacks more dangerous when discovery and exploitation scale quickly, and that damage can spread across sectors that share the same infrastructure.

In underwriting terms, that's the scenario specialists have described as a single AI-found vulnerability hitting thousands of policyholders simultaneously. Carriers say they're preparing for it. Westfield Specialty's Jeff Kulikowski has said cyber insurers are recalibrating their catastrophe models for AI escalation, and Beazley has bought more than $1 billion in protection against systemic aggregation risk.

Read next: Can cyber insurance survive the Mythos shock?

So why aren't prices moving?

The short answer is capital. Marsh attributes the broad softening across commercial lines to abundant capacity and strong insurer competition. Cyber has also been a growth story. Fitch Ratings found that US cyber direct written premiums rose 11% in 2025, with policies in force up 35%, meaning carriers grew mostly by writing more accounts rather than charging more per account.

Market leaders are clearly watching. Chubb CEO Evan Greenberg said in April that "policy conditions and pricing are on our minds" when asked about Mythos, The Insurer reported. Gallagher's Sam Cheshire, however, has said developments like Mythos are unlikely to trigger an immediate hardening.

One plausible reading is that the market is pricing the losses it can see in claims data, not the losses it fears. Until AI-driven attacks show up in paid claims, competition is likely to keep winning out over caution.

“I would say not softening, not hardening, but maturing if I can if I can put it that way,” Mila Araujo, AVP DigitalShield and Personal Cyber Insurance Practice Leader for NFP told IB’s Paul Lucas.

Watch the wording, not just the rate

If the market does tighten, it may tighten on terms before price. Law firm DAC Beachcroft has pointed out that most cyber policies don't mention AI at all. That leaves AI-driven losses neither clearly covered nor clearly excluded, a gap the industry calls "silent AI." Some carriers have already started capping losses tied to AI and LLM-jacking, while others, including Cowbell and Beazley, argue that blanket AI exclusions aren't the answer.

Government use adds another layer. Anthropic is reportedly helping the National Security Agency deploy Mythos for offensive cyber operations, which has raised new questions about state-linked attacks and war exclusions.

Read next: Marsh figures show US rates bucking global trend

Marsh's next quarterly reading will cover the months after the July testing breaches. It will be the first real test of whether Dimon's warnings, and those of the IMF, have started to move the market.

Five questions for brokers to raise at renewal

  1. Does the client's cyber policy say anything about AI-enabled attacks, or is it "silent"?
  2. Are there new sublimits or exclusions for AI or LLM-related losses compared with last year's form?
  3. How quickly can the client patch a critical vulnerability, and can they prove it to an underwriter?
  4. Which widely used third-party software and cloud services would expose the client to an aggregation event?
  5. How would the war or state-actor exclusion apply if a government-linked group used AI tools in an attack?
Free newsletter

We'll keep you up-to-date with the latest breaking news, cutting edge opinion, and expert analysis affecting both your business and the industry as whole.

Free newsletter

Our daily newsletter is FREE and keeps you up - to - date with the world of Insurance. Please complete the form below and click on subscribe for daily newsletters from IB CA.