Breaking Geopolitics News & AnalysisWednesday, September 23, 2026
TechnologyNorth America

AI’s Risk to Financial Systems

The Atlantic
September 23, 2026 at 10:46 PM
15 views
AI’s Risk to Financial Systems

The tech may soon become an existential risk to humanity, but it’s already a risk to many Americans in a more mundane way: their banks.

This is an edition of The Atlantic Daily, a newsletter that guides you through the biggest stories of the day, helps you discover new ideas, and recommends the best in culture. Sign up for it here.

Today’s AI agents have become exceptional hackers, and they’re already posing a threat to some of the most important infrastructure in modern life: banks.

In both finance and tech, industry leaders are well aware of the dangers, and they’re gearing up for a fight. Earlier this year, as Anthropic prepared to release a powerful new model called Mythos, the firm gave an early preview of the AI to a select group of companies, aiming to help them shore up their defenses. JPMorganChase was on the list, and more banks were reportedly added as Anthropic expanded the program. After the rollout, Treasury Secretary Scott Bessent and then–Fed Chair Jerome Powell met with the heads of Bank of America, Citigroup, Goldman Sachs, and other major financial institutions to discuss the potential implications of the new model, which Anthropic claimed could “surpass all but the most skilled humans at finding and exploiting software vulnerabilities.”

What makes AI agents different from past cybersecurity threats is that they move at machine speeds and can be summoned in groups. These bots can attack in swarms, hunting for cracks in companies’ back-end systems. The Office of the Comptroller of the Currency, which oversees many U.S. banks, wrote in a report to Congress this summer that AI has increased the “speed, scale, and sophistication of cyber-attacks targeting financial institutions.”

Research from last year suggests that finance is likelier than other industries to face AI-enabled cyberattacks, but we can already see these threats playing out in the tech sector. Tech companies typically send out weekly software patches—updates and bug fixes, essentially—on what’s known as Patch Tuesday. In the age of agentic threats, the volume of those updates has ballooned. Microsoft patched nearly 1,000 issues earlier this month, an all-time record. The trend was accelerating before Mythos arrived, but, per J.P. Morgan’s analysis, the most advanced models have dramatically changed the cyber-risk landscape, leading to a “tsunami of patches.” Insiders have developed a word for it: “Patchmaggedon.”

There’s also the risk that AI companies might lose control of the agents they send out into the world. Earlier this year, OpenAI revealed that its agents had defied instructions, breaching containment and hacking the servers of a company called Hugging Face. They also stole employee data and conspired to hide the evidence from their human managers. It was an incident that “exposed the speed of AI’s development,” as my colleague Josh Tyrangiel noted, “but also the lax oversight of the humans supposedly keeping tabs on it.” OpenAI has since disclosed several other lapses, and similar AI hacking incidents have occurred at Google, Anthropic, and Meta.

What might happen if AI agents manage to identify substantial weaknesses in a bank’s code base? It’s hard to say with any certainty. But because banks underpin nearly every aspect of modern life, outages or disruptions to back-end systems could ripple across digital commerce. That some of the dangers associated with frontier AI are inherently unknowable can make preparing difficult. The companies building these tools don’t always understand the extent of a model’s capabilities until it’s been fully trained—OpenAI’s chief scientist has written that “AI is grown more than designed.”

In spite of all this, the cybersecurity experts I spoke with made clear that the financial-services industry isn’t panicking. That’s in part because these agents and frontier models can also be used to prevent cyberattacks. Today’s engineers understand that defending against machine intelligence might itself require machine intelligence; firms are already deploying these tools for fraud detection, risk management, and more. Mike Silverman, the head of strategy and innovation at the Financial Services Information Sharing and Analysis Center, told me that companies are using AI to beef up what’s known as anomaly detection—early-warning systems for potential threats—as well as other kinds of data monitoring. A cybersecurity executive at one of the largest banks in the United States told me that the industry’s Security Operations Centers—defense hubs traditionally managed by human beings—are exploring the possibility of developing their own agents, and that engineers across the sector are now designing systems with AI’s capabilities in mind.

Because the financial sector has long been a target of scams, frauds, and data breaches, it’s already on high alert. But not every institution is equally capable of handling new threats; some smaller banks may lack the resources and security expertise of larger firms. As AI models advance, these tools may expose the difference between those who can afford to prepare for what’s coming, and those who can’t.

Related:


Here are three new stories from The Atlantic:


Today’s News

  1. Iranian President Masoud Pezeshkian told the United Nations General Assembly that Iran would not be made to surrender in its war with the United States, a day after President Trump threatened to “annihilate” the country. Pezeshkian said Iran remained open to diplomacy to end the conflict.
  2. The Justice Department defended Trump’s banning of CNN, MS NOW, and Politico from the White House, arguing that the outlets’ reporting has raised national-security concerns. The three news organizations are suing to restore their access.
  3. Harvey Weinstein was sentenced to 15 years in prison for sexually assaulting the former Project Runway production assistant Miriam Haley in 2006. The sentence closes his New York criminal case, though he still faces resentencing for a separate conviction in California.


Dispatches

Explore all of our newsletters here.


Evening Read

a row of backpacks
Paul Bersebach / Orange County Register / Getty

Why I’m Sending My Black Son to Private School

By Jenisha Watts

Since before he could even talk, I’ve been worrying about where to send my son to school. I know that having a choice to make at all is a mark of status: I am part of a group of parents who have enough money, time, and education to decide what is best for our children. And the fact that I can make a choice means that I can make the wrong one. So whenever I meet an educated Black parent, I inevitably ask for their advice about school. I remember one person answering, “We took the Nikole Hannah-Jones approach.”

I knew exactly what he meant. A decade ago, I read the cover story Nikole wrote for The New York Times Magazine about her and her husband’s struggle to decide where to send their daughter, Najya, to school. They ended up putting her in a “high-poverty, all-black school” because they believed that middle-class families had a responsibility to such neglected institutions …

I have always admired Nikole’s writing, and over the years, she has become a confidant and friend. Although many on the internet have accused Nikole of sacrificing her daughter for her ideals, I think she’s courageous. Still, as my son approaches school age, I realize that I could never make the choice she made.

Read the full article.


More From The Atlantic


Culture Break

A diver finding treasure underwater
Illustration by Alisa Gao / The Atlantic

Read. Dustin Illingworth recommends six titles that are no longer fashionable, if they ever were—but should you manage to read one, you might love it.

Reminisce. Annie Dillard, who died last week, kept much of her personal life carefully outside the scope of her nonfiction, Diana Saverin writes. She explores the enduring mysteries of what Dillard left out of Pilgrim at Tinker Creek.

Play our daily crossword.


Rafaela Jinich contributed to this newsletter.

When you buy a book using a link in this newsletter, we receive a commission. Thank you for supporting The Atlantic.