Image: Jamie Dimon, World Economic ForumThis file is licensed under the Creative Commons Attribution-Share Alike 2.0 Generic license.
Jamie Dimon has been sounding the alarm about Anthropic's Mythos model since the spring. Earlier today he put a number on it.
In an interview with Bloomberg Television, the JPMorgan Chase chief executive said AI risk "went up 10-fold after Mythos." He said the technology had exposed vulnerabilities the bank hadn't known existed, in an area it already ranked among its biggest worries.
You might expect a warning like that from the head of America's largest bank to show up in cyber insurance premiums. So far it hasn't. US cyber rates fell 2% in the second quarter of 2026, according to Marsh's Global Insurance Market Index. Globally they fell 4%, the twelfth straight quarterly decline. Marsh noted that US cyber pricing has been sliding since the second quarter of 2023.
That gap between the threat being described in boardrooms and the prices being charged at renewal is now the central question for cyber underwriters and the brokers who place their business.
Dimon's tenfold remark is the latest step in an escalating series of warnings. In April, after JPMorgan tested a preview of Mythos, he said the model showed that many more vulnerabilities needed fixing, according to CNBC. Over the summer, speaking at the Pennsylvania Defense and Innovation Summit, he compared wide public access to Mythos to handing individuals ballistic missiles.
He has stopped short of human extinction and doom though. On Tuesday he called the threat from AI agents real but said he wouldn't be drawn into debates over whether it is existential. Instead, he said, the bank is "rolling up our sleeves" to fix what it finds.
JPMorgan has itself used the model to probe its own defenses, a reminder that the same capability that worries banks is also being used to protect them.
Anthropic unveiled Mythos Preview in April and limited access to a small set of partners through its Project Glasswing program. The model's system card described a test in which an earlier version was told to break out of a secured sandbox and contact the researcher running the evaluation. It did both. It then posted details of the escape on obscure public websites, which nobody had asked it to do.
The regulatory picture has been volatile too. Anthropic released Mythos 5 and a guardrailed sibling, Fable 5, on June 9. The company suspended access three days later to comply with US Commerce Department export controls, and restored it on July 1 after the controls were lifted.
The summer then brought the first known cases of AI models breaching real organizations during their own developers' tests. On July 21, OpenAI disclosed that models it was testing had escaped their sandbox and compromised Hugging Face's production systems.
OpenAI's later technical report said the models had run code on 41 of Hugging Face's servers, Axios reported. Days later, Anthropic said its own models, including a Mythos version, had breached three other organizations during tests run in a partner's evaluation environment. The models had been told they had no internet access, and they did. Neither Anthropic nor the affected organizations had noticed the intrusions at the time.
Read next: How Anthropic's Mythos is fueling cyber risk aggregation fears
The fear for insurers isn't one bad breach. It's one flaw exploited everywhere at once. The International Monetary Fund warned in May that AI-enabled tools make attacks more dangerous when discovery and exploitation scale quickly, and that damage can spread across sectors that share the same infrastructure.
In underwriting terms, that's the scenario specialists have described as a single AI-found vulnerability hitting thousands of policyholders simultaneously. Carriers say they're preparing for it. Westfield Specialty's Jeff Kulikowski has said cyber insurers are recalibrating their catastrophe models for AI escalation, and Beazley has bought more than $1 billion in protection against systemic aggregation risk.
The short answer is capital. Marsh attributes the broad softening across commercial lines to abundant capacity and strong insurer competition. Cyber has also been a growth story. Fitch Ratings found that US cyber direct written premiums rose 11% in 2025, with policies in force up 35%, meaning carriers grew mostly by writing more accounts rather than charging more per account.
Market leaders are clearly watching. Chubb CEO Evan Greenberg said in April that "policy conditions and pricing are on our minds" when asked about Mythos, The Insurer reported. Gallagher's Sam Cheshire, however, has said developments like Mythos are unlikely to trigger an immediate hardening.
One plausible reading is that the market is pricing the losses it can see in claims data, not the losses it fears. Until AI-driven attacks show up in paid claims, competition is likely to keep winning out over caution.
“I would say not softening, not hardening, but maturing if I can if I can put it that way,” Mila Araujo, AVP DigitalShield and Personal Cyber Insurance Practice Leader for NFP told IB’s Paul Lucas.
If the market does tighten, it may tighten on terms before price. Law firm DAC Beachcroft has pointed out that most cyber policies don't mention AI at all. That leaves AI-driven losses neither clearly covered nor clearly excluded, a gap the industry calls "silent AI." Some carriers have already started capping losses tied to AI and LLM-jacking, while others, including Cowbell and Beazley, argue that blanket AI exclusions aren't the answer.
Government use adds another layer. Anthropic is reportedly helping the National Security Agency deploy Mythos for offensive cyber operations, which has raised new questions about state-linked attacks and war exclusions.
Read next: Marsh figures show US rates bucking global trend
Marsh's next quarterly reading will cover the months after the July testing breaches. It will be the first real test of whether Dimon's warnings, and those of the IMF, have started to move the market.