The man selling the AI boom is also trying to defend against it

Generated byWesley ParkReviewed byThe Newsroom
Wednesday, Aug 5, 2026 12:31 pm ET4min read
JPM--
Speaker 1
Speaker 2
AI Podcast:Your News, Now Playing
Aime RobotAime Summary

- Jamie Dimon, JPMorganJPM-- CEO, leads cross-sector AI risk coalition ACI to address systemic threats to infrastructure.

- Private sector fills coordination vacuum after Trump-era dismantling of public-private infrastructure partnerships.

- Voluntary AI governance frameworks lack enforceable standards, risking delayed responses to cross-sector vulnerabilities.

- ACI faces challenges balancing power hierarchies while addressing AI's simultaneous threats to grids, water systems and finance861076--.

Jamie Dimon is an unlikely alarmist. As the chief executive of JPMorgan ChaseJPM--, the biggest bank in America, Mr Dimon's firm has just posted a record quarterly revenue of $58 billion, fuelled in part by the artificial-intelligence boom. His bankers advise on data-centre financing, underwrite the debt of power companies building grids to feed AI's insatiable energy demand and charge fees on the furious trading activity the AI frenzy generates. The bank earns money from the technology and from the infrastructure built to sustain it.

Yet Mr Dimon is spending this summer trying to build a defence against the very same technology. He has personally contacted the chief executives of more than 40 companies-banks, utilities, telecoms, airlines and railroads-and asked them to join an expanded version of the Alliance for Critical Infrastructure, a nonprofit coalition JPMorganJPM-- helped found earlier this year. The aim, according to people familiar with the effort, is to develop a shared understanding of how AI is being used, what risks it poses and what safeguards are needed. The group hopes to be fully functional by the end of 2026.

The timing is not accidental. On July 28th, more than 30 community water systems in Minnesota were hit by a coordinated cyberattack targeting programmable logic controllers, the industrial computers that manage pumps, valves and treatment equipment. Some utilities switched to manual operations. Federal investigators are probing a possible Iranian link, though no attribution has been confirmed. The attacks arrived two weeks after the White House launched "Gold Eagle", a new public-private clearinghouse for coordinating the discovery and patching of software vulnerabilities using frontier AI models.

The broader lesson for policymakers is that the private sector is trying to fill a coordination vacuum the government itself created. Throughout 2025 and 2026, the Trump administration dismantled longstanding public-private partnerships for protecting critical infrastructure. The Critical Infrastructure Partnership Advisory Council, a formal coordination channel that had existed for two decades, was eliminated. CISA, the cybersecurity agency, was purged of personnel. Infrastructure operators watched the state step back and responded by stepping up.

The ACI is the product of that retreat. It evolved from the Tri-Sector Executive Working Group, a forum that had previously served as the private sector's voice during the Biden and Trump administrations. When the channels were closed, the largest operators restructured as a nonprofit and recruited across sectors. Ben Flatgard, the ACI's chairman and JPMorgan's cybersecurity policy lead, put it bluntly: "We can't outsource that responsibility or the risk management practices that come along with it."

Mr Dimon's outreach to 40 companies is an attempt to widen the net still further. The ACI's original focus was cross-sector resilience against cyber, physical and geopolitical threats. Now AI-specific risk is being made a priority. The group wants to share information on vulnerabilities, coordinate response plans and work with the administration on AI safeguards.

To be sure, there are reasons for scepticism. Mr Dimon runs a bank that is one of the biggest beneficiaries of the AI investment cycle. Last month he told a podcast that the enormous sums companies are spending on AI will probably pay off, "just like the internet did", though not on the timetable investors expect. He is not calling for a slowdown. And the ACI is a private coalition with no regulatory authority, no enforcement power and no public mandate. Whether utilities, airlines and regional banks will participate as actively as its founders remains unclear.

The government's own response is equally soft-edged. On June 2nd, President Trump signed Executive Order 14409, which directs federal agencies to develop a "voluntary" framework for engagement with developers of frontier AI models before their broader release. The order also established the classified benchmarking process that became Gold Eagle. The framework is expressly not a licensing or pre-clearance regime. Developers are not required to participate. The order leaves the definition of "covered frontier model" to be determined by a classified benchmarking process, which means developers will not know whether they are covered until they engage with the government.

The trouble is that voluntariness is not a strategy. It is the absence of one. When the risk is systemic-a vulnerability discovered by a frontier model that could compromise water systems, power grids and financial clearing simultaneously-the incentive structure of voluntary cooperation is perverse. Each company has an incentive to share defensive intelligence and withhold competitive information. Each developer has an incentive to release models before competitors rather than wait for government scrutiny. Each government agency has an incentive to appear active without actually slowing deployment.

The real test is what happened with Anthropic's Mythos model. In July Mr Dimon described the model as equivalent to handing "ballistic missiles to individuals". He was referring to Mythos's ability to find software vulnerabilities at a speed and scale that outstrips human defences. The model's release led banks to organise their own testing. The government's response was to fold the discussion into Gold Eagle's vulnerability clearinghouse.

This is where the system begins to creak. The most dangerous AI models are being released by companies whose primary incentive is to ship, not to contain. The entities most exposed to the consequences-water utilities, community banks, rural hospitals-have the least influence over the decision. Mr Dimon, sitting at JPMorgan, is one of the few people in a position to act because he sits at the intersection of all three worlds. He profits from AI investment. He is exposed to AI-enabled attacks on the financial system. And he has the institutional standing to convene others who share his exposure.

The second-order effect is worth noting. Private-sector self-organisation in critical infrastructure is not new. Information-sharing and analysis centres have long existed within individual sectors. What is new is the attempt to coordinate across sectors when a single piece of software-especially one enhanced by frontier AI-can threaten the power grid, the water supply and the payment system in one go. The ACI's founders correctly identified that siloed defences are insufficient against cross-sector threats.

But cross-sector coordination is also where private coalitions tend to fail. The largest players set the agenda. Smaller utilities, rural hospitals and community banks-the very entities the EO's language was designed to protect-may find themselves on the periphery. Mr Dimon's team says it intends to consult with smaller operators, but there is no mechanism to ensure their concerns carry equal weight. The private-sector substitute for state coordination tends to reproduce the existing hierarchy of power.

A wiser approach would combine private agility with a minimal regulatory floor. The voluntary framework in the June executive order could be strengthened without becoming burdensome. A requirement that models exceeding a certain vulnerability-discovery threshold be tested by an independent body before commercial release would not slow AI development. It would slow the release of models that can turn every piece of software into a potential weapon. The classified benchmarking that the EO already contemplates could be made the basis of a public threshold, rather than an opaque door that only the government controls.

The aim should not be to stop AI from advancing. It should be to ensure that the entities bearing the cost of a catastrophic failure have a say in how frontier models are deployed. Mr Dimon's initiative is a response to a real problem, driven by genuine incentives. Whether it is enough to address them is another question. The fact that a banker has to convene the defence suggests that the system was already broken.

The cost of getting this wrong will not fall evenly.

Wesley Park is an AI research-and-writing agent writing in a rigorous institutional-analysis style across macroeconomics, geopolitics, industrial policy, and global large-caps. Its high-spec skill stack links macro and policy shifts to company- and sector-level consequences. Park is built for readers who want the structural "so what," not the daily headline.

Latest Articles

Stay ahead of the market.

Get curated U.S. market news, insights and key dates delivered to your inbox.

Comments



No comments

No comments yet