Follow us
31 August 2026

AI could lift bank returns to 14%—but half of projects fail

Mythos, rogue agents, and the cybersecurity threat no one fully controls

The risks are not hypothetical. In April, US Treasury Secretary Scott Bessent and Federal Reserve Chairman Jerome Powell convened top US bankers specifically to warn about cybersecurity dangers linked to Mythos, the latest model from Anthropic, the creator of Claude. A company statement acknowledged that Mythos had uncovered flaws in existing computer operating systems that "have in some cases survived decades of human review and millions of automated security tests."

Bank server room infrastructure illustrating cybersecurity risks from AI systems
Illustration © Toptenplay

Anthropic agreed to restrict Mythos to a handful of corporate clients in what the company described as "an urgent attempt to put these capabilities to work for defensive purposes." The episode illustrates how quickly AI capabilities can outpace the safeguards designed to contain them.

The threat is not limited to external attacks. As generative AI evolves into agentic models—systems that make decisions autonomously—banks face risks from within their own vendor ecosystems. "Risk is coming in through the back door, with vendors’ agents liaising with each other," Mousavizadeh warns. Firewalls may not be sufficient to prevent a rogue AI agent from infecting or co-opting connected systems.

Eric Alter, who recently retired as an AI engagement leader at Marsh in the UK, frames the structural problem bluntly: "Any financial institution works on a three- to five-year plan, while the tech horizon is six to 12 months. By the time a tool is deployed, it’s obsolete." Regulators, he and others note, tend to react only after a crisis—which, given AI’s potential reach across the financial system, may come too late.

JPMorgan leads the patent race; ING bets on AI mortgage applications

The competitive landscape is already tilting. Seven of the top 10 names in Evident’s latest AI Banking Index are headquartered in North America, led by JPMorgan Chase, Capital One, and Royal Bank of Canada. Patent activity tells a starker story: just three US banks—JPMorgan Chase, Capital One, and Bank of America—account for 75% of the entire industry’s AI-related patents.

AI-powered bank customer service workstation with chat interface and headset
Illustration © Toptenplay

"European banks are one step behind, without the same access to an AI startup ecosystem," Mousavizadeh says. "The US has a lot of open doors for talent to move back and forth." Talent, EY’s Gupta agrees, is "the key factor to solve for."

Some European institutions are nonetheless carving out notable positions. Commerzbank launched an AI-generated customer service avatar named Ava roughly a year ago; it now handles more than 30,000 inquiries a month and resolves three-quarters of them. Italy’s UniCredit developed the DealSync platform, which identifies thousands of merger and acquisition opportunities for midsize companies across Austria, Germany, and Italy. Dutch bank ING has deployed AI in call centers and, according to Chief Operations Officer Marnix van Stiphout, is targeting a 2026 rollout of a mortgage application process handled entirely by an AI agent.

Trust, several experts argue, may ultimately be the banks’ most durable asset in this transition. Unlike the internet pioneers who enjoyed decades of utopian goodwill, AI arrives already shadowed by skepticism. "Moving so fast, it’s very hard to get the right balance of risk and innovation," Fernandez cautions.

75%
Just three US banks—JPMorgan Chase, Capital One, and Bank of America—hold three-quarters of all AI-related patents in the banking industry, according to Evident Insights.
Advertisement
Share on Facebook