Loading summary
A
This podcast has been prepared exclusively for institutional, wholesale professional clients and qualified investors only, as defined by local laws and regulations. Please read other important information which can be found on the link at the end of the podcast episode.
B
All right, good morning everybody. This is the July Eye on the Market podcast. This one's called the Summer I Turn and Pretty, which I'll explain. And earlier this year on my TikTok feed, I was bombarded with all sorts of clips from a TV show called the Summer I Turned Pretty, which I never saw, but I used it for a tagline here because this is the summer that I turned pretty cautious on two pretty important topics. And that's what we're going to talk about on today's podcast. Cautious about zero day cyber attacks resulting from the latest Frontier AI models. And that's going to be the bulk of the discussion on today's podcast. And also cautious about some market technicals and some growing challenges to the frontier labs from both new open and closed weight models. And let's start with some of the market technical issues. And there's a bunch of people that have been writing similar things. This is some work a colleague in the investment bank Jason Hunter, has done. If you look back to the late 1990s, there was a point at which the communications stocks flatlined, even though the infrastructure stocks kept on rising. And as a proxy for that, think about Juniper Networks and Verizon and things like that. So you had this period in the market where the front end, which were the communication services stocks, started to flatline, but the infrastructure stocks kept going. And it was a bit of a head fake to the market. We're having a little bit of a parallel right now because the hyperscalers, which are the front end of this AI boom, are seeing their stock prices stagnate and their free cash flow fall even as the semiconductor and other infrastructure providers and optical networking companies are continuing to go up. So there's some parallels here that I think we need to think about, because you always want the caboose going fast, slower than the front of the engine, and that's not what's happening. There are also some serious challenges to the Frontier labs, and by that I'm obviously referring to anthropic and OpenAI coming from a whole bunch of new models. And for those of you consuming this in video form, you can see this really colorful chart that's become somewhat standard in discussions about these different models. On the Y axis, you have some kind of measure of their productivity and performance. In this case, it's a benchmark focused on math and reasoning and coding tasks from this group, artificial analysis. And the X axis is typically in log scale. And importantly, it's not cost per token, it's cost per task because models can differ on the intensity of how many tokens they use and need. So it's better to just look at net of that efficiency. What's the overall cost of a task? And this curve used to be such that OpenAI and anthropic frontier models were way better than everything else. Now you can kind of slide to the left on this chart. And Meta has a new model, SpaceX AI has a new GROK model, there's a new Chinese model where all of a sudden you're looking at models whose performance isn't that different from the best OpenAI and anthropic models at either a third or a tenth of the cost. And so I can imagine there's a lot of CFOs and I've spoken to some of them already that are starting to think about, hey, maybe these models can work for us on certain tasks. Not all of them, but some of them are having a bit of a sticker shock on the token bills that they've been paying. So there's two pieces to the eye on the market that are coming out today. One of them is on the cyber issue, the other one is on these market technical and frontier lab challenges. And all that information is in the email. Just two quick things. Thinking Machines, which was launched by some people that used to work at OpenAI, finally released their model and as expected, it looks pretty good. And it's a mixture of experts model, and I wouldn't be surprised if if they were a serious challenger as well. And you're probably hearing a lot about Kimi K3 from a company called Moonshot. It's Chinese and just to give you a sense, it costs about 30% as much in terms of input and output tokens as some of the other best models with similar performance. So again, take a look at the eye in the market today for that. Okay, so today is a first. So I'm having a co host on the podcast, which I haven't done before. I should probably do that more often because some of our listeners probably tired of hearing me drone on and on. But Pat Opet is here and Pat is the Global Chief Information security officer at J.P. morgan. And you've been at J.P. morgan for more than a decade?
C
Yeah, 12 years.
B
12 years. And Pat and his various teams have worked and helped me write a piece called Patchmageddon the race to patch software vulnerabilities before zero day cyber exploitations proliferate. There's a lot of jargon involved, but Pat's here to kind of make sure that everybody understands, in layman's terms, as much as we can, what's going on. Thank you and welcome to the podcast.
C
Thanks for having me. I'm excited to be here.
B
I might do this again. So even before Mythos came along. Right, Because Mythos was a bit of a shock to the system earlier this year. Even before Mythos came along, the data that your team shared with me shows that the pace at which vulnerabilities in the systems that big companies use were being found and disclosed at a much faster rate than they were than they're patched.
C
That's right.
B
And like, what's it like to be inside a large organization where it's raining vulnerabilities and you have to patch them?
C
Look, it's very difficult and obviously a lot of automation and tooling has been built over many years to help find vulnerabilities in software. But there isn't so much automation and tooling that helps organizations fix vulnerabilities. Fixing vulnerabilities requires putting new software in production. That often means that you have to do thorough testing to ensure that the new software you're putting in production doesn't break any other features. And for companies like ours, where continuity of operation is very important for our customers, that's a very careful process. Multiply that by the various industries and the difficulty in perhaps reaching the software that has to be put in production. Think like industrial control systems that aren't easily accessible or teams that don't have sufficiently sized technical teams. It becomes really onerous to keep up with the rate by which vulnerabilities are being found.
B
Okay, so earlier this year. Let me just make sure this is working. So there's analyses differ here. Right. But this is. This chart is a proxy for how long does it take for organizations to remediate things that need to be fixed. That's the gold line. And then the falling blue line is time to exploit.
C
That's right.
B
TTE why is that such an important concept for people to understand? Because they're going to. I've been seeing it everywhere.
C
Yeah. So when a vulnerability is found, it. It is a flaw in a piece of software that could be abused by an attacker.
B
Okay.
C
The exploitation process is the attacker actually abusing that software. And so typically, like, if you look back several years, teams had time, you know, days between a vulnerability being discovered and an attacker weaponizing that vulnerability. But through, again, you know, new tooling and in particular various AI systems, attackers can now exploit vulnerabilities much more quickly, to the point where attackers are actually both discovering the vulnerabilities and exploiting the vulnerabilities before the defenders even know they exist. Yeah, that is colloquially called a zero day, which is now dominating the headlines.
B
Yes. And in this chart in 2020, there was 30 days in between the disclosure vulnerability and its first exploitation. And those numbers have fallen basically to zero. And obviously what industries are at risk? A lot of them and across a lot of different parts of the economy. And so it's not like one particular industry is more at risk than others. The ECB put out this financial stability review, and I thought it was kind of spooky that the largest component of who's doing this fell into a category called unknown. Why is it so hard to know who's doing it? Is it just the nature of it?
C
Just what's called attribution. In cybersecurity, associating an activity with an attacker depends on tradecraft and tooling and patterns. And over time, state actors or criminal actors have either diversified their supply chain so it's not just them or their team doing an action and they depend on many different parts of the community, or they've intentionally obfuscated their actions by hiding them to make it much more difficult to attribute the action.
B
Real attribution of this might find the state sponsored sector much higher than what's in the chart.
C
Yep. Or criminals.
B
Or criminals. Gotcha. Okay, so in April, Mary sent me an email saying, hey, you better look into this Mythos thing. And I didn't know what Mythos was. I thought it had something to do with like the new Odyssey movie. Like it was some Greek thing that was coming out. And obviously I spent time looking into it. Your team was helpful to me at the time. And I came across this chart and this chart spooked me, which is why I included it in the eye on the market at the time. And it's from this AI security institute in the UK. And the purpose of this analysis was with 32 steps across lots of different points of a system, you can execute a full system takeover. At the time, the existing frontier models can only get about a third or halfway there. And then Mythos came out and they published a big like, oh, Mythos just went like all the way up the food chain and completed the 32 steps. And then a couple weeks after that, it was disclosed that GPT, I think it was 5.5 did the same.
C
That's right.
B
What are these different barriers that it has to kind of go through?
C
So it's kind of. I think there's two important things to take away from this chart. One, you know, cyber attacks occur in various stages, oftentimes called a kill chain. And so what's being described here is a model autonomously working through that kill chain end to end, being able to exploit organization without a hands on keyboard, without an operator. And so what this is really meant to measure is the autonomy of a model being able to execute, end to end an attack through each of those stages. But I think it's a little bit misleading because if one just takes away the fact that models will be able to autonomously attack corporations, it sort of misses the point that what they're also doing is accelerating and augmenting skilled attackers. So, you know, let's take criminal attackers versus states. State attackers have exceptional capability, that's very well funded and they are by far the most dangerous attackers. When we talk about cyber actors, criminals are very dangerous, but they may be less skilled, less well funded, or less resourced.
B
Okay.
C
All of the sudden, when you take these capabilities provided by the frontier models, that in one sense can autonomously execute attck, but with a skilled operator, you boost the capabilities of that skilled operator pretty precipitously.
B
It's interesting because a lot of the AI research coming out of Stanford and Harvard is within an organization. It makes your lower employees better.
C
That's right.
B
More than it makes the great employees better. So similarly, it's doing the same.
C
Same thing applies.
B
Oh, wonderful. And I thought this chart was interesting too, because here you can really see the impact of the new models on the pace of critical and high severity vulnerabilities that get reported. The CVE is a critical vulnerability. There's some kind of a central repository for this kind of thing.
C
Yeah. There's a mechanism to disclose, reserve a number associated with the vulnerability and then inform the market, all the consumers of the software that they need to fix something. Okay. Obviously, criticals and highs are the most important because they're the easiest to exploit and they can create the most damage. They're often hard to find. The really interesting part of these models is that they can compute on software in ways that allow them to either chain various flaws together or to recognize that there are much more severe flaws in the software that we knew to exist and at a scale that is significantly more than we typically deal with on an annual basis.
B
I mean, look at this thing. I mean, the number of criticals were running less than 10.
C
Yeah.
B
Consistently. And are now approached and now hit 400. This is pretty asymptotic, so I don't want to go through too much detail here, but we have some stuff in the piece that talks about and when Mythos first came out, this first bullet point got a lot of focus, which is, oh, my God. Mozilla had all of these vulnerabilities in Firefox that nobody knew about until they started using Mythos to try to figure them out. And what is the third bullet point I thought was interesting? 95% of the mythos vulnerability disclosures had no public advisory at the time they were found. Does that mean what it sounds like?
C
Yeah, they're novel.
B
Okay.
C
So, you know, the model is finding new flaws in software that security researchers, in some cases over decades, were unable to find in some of the most well trodden pieces of software like the Linux operating system. And the way in which the models are able to compute on software allows them to find these exquisite or novel weaknesses.
B
The other parallel here is last year I talked to a group at Stanford in biotech and there's this thing called antibiotic resistant bacteria MRSA, and it kills like 10,000 people a year. And they used some of the same models to go through like 30 million possible compounds. And they found two that might work, and they're in mice trials. So there are a lot of parallels here with the way that people are using these for good things in terms of as opposed to the bad things. This chart was also kind of unnerving. It's the share of exploitations occurring before or on the day of disclosure. So it's like you come into the office and you sit down at your desk and all of a sudden there are these problem. It may not be you, but there are other companies that have suffered an exploitation.
C
That's right.
B
And you have to deal with it.
C
Yeah. And I think this just sort of lends to the same point, is that as tooling has gotten better, it's enabled attackers to find vulnerabilities at a broader scale. When attackers find the vulnerabilities and not defenders, they can weaponize them right away. And so you prefer the other side. Defenders are finding the vulnerabilities first. They're then fixing those vulnerabilities and pushing disclosures. Companies are consuming it and fixing that software before attackers weaponize it. We've essentially inverted the process right
B
now. One of the things that was really eye opening to me as a layperson, I always knew that Open source code was important, quote, unquote. I had absolutely no idea that it is as pervasive and widespread in terms of building blocks as it is. And one of the things we have in here is a timeline of some of the major open source projects and what they eventually enabled. This goes Back to the 1980s, some of this stuff.
C
That's right.
B
Economists tell me this shouldn't exist. Right. Economists theorize, why would people do all this work for no compensation? And yet it has existed for 40 years.
C
Yeah, I mean it's like people get to pursue mastery and they get purpose and they can make impact despite being paid. And that's why.
B
Despite not being paid.
C
Right. Despite not being paid. Which is why open source really thrives.
B
Now there's a chart in here that just summarizes a couple of things and these were eye opening to me, so I wanted to share them with our clients. The share of commercial code bases with open source code is like in the high 90s. The share of open source projects with fewer than 10 maintainers or developers that are responsible for most of the code, 94%. And then the share of commercial code, this font is too small for me. Made up of pre built open source libraries and networks, 77%. So even within the vendor software universe, of all the things that we buy as JP Morgan, the vendor software we're buying is highly reliant on open source code. The code that we write internally is reliant on open source code. So open source code is a much bigger foundation of everything that I had ever suspected.
C
Yeah. And you have these sort of nested dependencies where a piece of software may overtly use open source, but may also have a dependency on another piece of open source that isn't so overt. And so these things kind of get built over time and it creates complexity in the software that we use, but also for defenders, complexity in understanding where all of your open source dependencies are, to fix them when there isn't, where there is an issue.
B
I saw this one citation from CISA on Like a JavaScript thing. There were 10 direct dependencies and 680 indirect dependencies, which is kind of amazing. Oh yeah. Here are the dependencies. The mean number of open source components per commercial application is almost 1200.
C
Yeah.
B
So that means that like we're contracting with a certain vendor and in order for that vendor software to work, either if we're running it remotely or in house, we have to have 1200 other pieces of code to support it. Yeah.
C
In some cases they're built into the software package. I mean there's probably a bit of influence of the SaaS ecosystem that has changed these numbers. So when a Vendor provides a SaaS product, obviously that's a whole suite of software which likely includes a significant amount of open source.
B
And then who's responsible for updating that? Them or us?
C
The vendor. So the vendor, you know, in any vendor package it is always going to be a vendor that's responsible for updating the software. So we have very little autonomy when it's a piece of software that we haven't written, you know, whether it's outsourced or whether we're consuming that software, which is important part of the process of ensuring that your vendors are paying attention to the Patchmageddon as well as, you know, first party companies.
B
Look at the last bullet point here. 90. This is from Linux Foundation. 95% of open source vulnerability reside in the transitive dependencies rather than the direct ones.
C
That's right.
B
That's amazing. And for, you know, for, for investors, a lot of the names that you know and love, you know, red hat, databricks, GitHub, you know, hugging face, a lot of these are heavily reliant on, if not built entirely from open source code.
C
Yeah, and some of these companies are both the maintainer, they're the sort of professional entity that maintains the open source or the ones that created it itself. And so when we talk about open source we sort of differentiate between community backed, which is individuals or foundation backed or professionalized open source, where you have kind of a company that stands back, that's the steward of the software.
B
Tell me if you're surprised at this. This was the survey they did. 61% of reported incidents are associated with unapplied but available patches because over 80% of security professionals decided not to do it because they didn't want to disrupt the workplace.
C
Yeah, I mean, look, patching is hard. And so I think that, you know, that's the first thing to recognize is that including new software and getting it released to production without incident is a difficult thing for many companies to do.
B
Right.
C
And oftentimes we bias, you know, as a community availability, you know, incidents, whether they're caused by a patching process or in some cases adversary disruption, have the same net effect. The software isn't available to consumers. And so in many organizations they may bias availability over fixing. And this problem hasn't presented itself as significantly as it might now. And so the calculus on patching is going to have to change for those organizations that don't have it as a first class priority.
B
And by the way, in terms of disruption, I was having all sorts of zoom problems recently related to a Citrix patch and I had to roll it back in order to get my zoom to work. I will deal with that separately. One of the things that you mentioned was physical infrastructure. And how is physical infrastructure different than cloud based digital infrastructure?
C
Yeah, so servers or switches or firewalls all run code and the goal is to keep those kits, the physical infrastructure kit, current. But oftentimes organizations tend to sweat their assets. They don't replace that physical infrastructure as frequently as the providers would recommend and it may fall out of maintenance or it may lag the sort of current release of code. What's going to happen now with the number of vulnerabilities that are being found is that providers are going to be forced to fix the current software first. And so they're going to prioritize maybe explicitly only the current software. Which means that older software, especially if it's end of life or end of service, may not get patched or may not be available to patch. And so organizations now are starting to think about all of this hardware refresh that they must need to do if the patches don't come for the older end of service kit.
B
One of the things that we get into on the infrastructure side is sensors and operational switchboards and device controllers. And what are we talking about here? We're talking about the stuff behind air traffic control systems, municipal waste treatment plants, water purification systems, the grid, gas and oil pipelines, electricity networks. This is the kind of stuff, and I think I saw a lot of digital assets are often replaced 3 to 5 year cycle. This stuff can be a 10 to 12 or longer cycle and it may
C
run in environments that aren't easy to access it, you know, distributed across a pipeline instead of inside of a data center. It's tend to be built for the longer periods of time. It isn't refreshed as regularly. But these vulnerabilities, you know, especially when they occur in these devices, can be pretty dangerous, you know, to the operation.
B
Earlier this year, JP Morgan on the investment banking side worked with some of the big industrial companies, ABB and Honeywell and Siemens, and they estimate that only a little more than half of all the industrial networks are patchable. And I spoke to them and the implication from those engineers was a lot of the rest of the equipment will eventually have to be replaced, which is expensive and I would imagine time consuming. Now this is a controversial point and I know that members of your team have differences of opinion, which is totally to be expected. Some people have said to me, well Mike, no problem, because these tools that are so good at finding the vulnerabilities, we can fight fire with fire and we can use these same tools. And people are using them to both to propose fixes in the case of Anthropic and actually run the fixes in the case of OpenAI. And I'm talking here about OpenAI's GPT 5.5 Cyber. They have a codec security plugin. Anthropic has cloud security and a cyber verification program. What's your thought on this stuff?
C
Yeah, I mean it is clear that agentic coding tools can help accelerate the process of fixing the vulnerabilities. We're finding they are in some cases difficult to institutionalize in enterprise. And so while the capabilities may be there, they it may be difficult for an enterprise to sort of safely adopt these and scale the tools to all of the developers that need them. And then separately there are some emerging challenges around guardrails in these tools. So the cyber models are designed with less guardrails so they allow cyber tasks and they're typically provisioned to cybersecurity teams as part of trusted access programs or glasswing, which was an announced program. The general models refuse to do cyber work or offensive cyber work because we don't want to create harm. Oftentimes when you're trying to fix a vulnerability, if the guardrails aren't properly tuned, it makes it actually difficult to fix the vulnerability because a fix for the vulnerability and a test for the fix could be the same thing as an exploit for the vulnerability. And so the guardrails and the conversation around guardrails which is now emerging is going to get a little bit complicated over how much do we allow, you know, often of cyber work because of the benefit of fixing versus how much do we try and prevent these models from being able to accelerate, you know, malicious actors activity.
B
Right. I thought it was true to brand in some ways that Anthropic would say we're not going to do the fix that's on you. And whereas OpenAI goes a step further and their stuff actually will execute.
C
I think they're, I think they're all trying to get to, I mean clearly all these programs are aimed at, you know, supporting defenders. And I think what they all recognize is in addition to the Frontier labs in the U.S. which you know, you called out in the early charts, there are open weight models emerging which don't have the same guardrails and won't refuse to do cyber work. And so, for example, Kimmy K3, an emerging open weight model, will happily do offensive cyber work and is nearly as capable as some of these frontier models. And so we are sort of entering, you know, an era of time where cyber capabilities, whether we like it or not, are going to be readily available to arbitrary individuals. And that's going to create some real challenge for organizations.
B
Let's get to then. You guys published something that we linked to in the piece on action steps for business owners and governments. And I bolded the first one because I thought that there were some interesting things in here. Run the latest software versions when possible. Move applications off third party dependencies when you can't identify the steward and when the steward appears to be a single shingle and or does not exhibit good maintenance practices or where the package appears abandoned. Yeah, that sounds like a lot of work.
C
Look, I mean I think the simple way to think about this is in our own experience with the open source vulnerability analysis we did. If we simply move to the most current version of open source across all of our dependencies, 50% of our high end critical issues fall away.
B
Okay, so that's half of the problem for everyone.
C
Just maintain currency. Maintaining currency again may be difficult, may require you to be able to release software much more frequently than you typically do. And so we recommend that organizations accelerate their software release process at this point in time so that you can put code in production at will. And then the rest of this, you know, frankly, it is kind of cyber hygiene and basics that we've described for many years. Our point in the blog isn't just do the basics, it's get exceptionally good at the basics. Because right now with the risk that's being created through these models, you need to be exceptional at doing the basics. Right.
B
My guess is that you might not be able to buy insurance against, against not being good at this.
C
Yeah, insurance providers are certainly going to scrutinize, you know, these attributes.
B
So let's close in some of the calls that we did a couple weeks ago. Members of the. We have, we have policy people here. JPMorgan has lots of policy people and they felt pretty strongly about certain things. I want to focus on number three because that's the one that jumped out to me the most, that the US Government should create a government hosted domestic cyber defense strike force capability with clear authority to support lifeline sectors, health care, finance, you know, electricity and stuff like that, both before and during serious incidents. Yeah, you want to just kind of do a thought Experiment about what that means and how it would work.
C
Yeah, I mean, look, you know, the government's obviously a close partner with cyber teams across the country, especially those in critical infrastructure, and has been so through DHS and CISA for many years, as well as the US intelligence community. But when you think about the challenges that may be coming, you know, undeterrable actors, individuals, criminals, activists or terrorists with potential state grade capabilities as delivered through these models.
B
Right.
C
We would argue that it's appropriate for us to consider a more fulsome homeland defense organization that can actually operate against these actors within US networks. Not different than, you know, how we generally think of maybe the Department of Homeland Security or the law enforcement measures that we have that would counter criminals Today. Private sector entities are left to defend themselves against state actors, sophisticated criminals and individuals. I would argue when you look at some of the data, we're not winning. You know, the nation at large is suffering cyber attacks regularly. Ransomware is a thriving ecosystem. Fraud is well funded through attacks. I think given the capabilities that are here today and coming, we need to think about new ways to solve this problem. And it can't simply rely on every organization to just do better.
B
And so you'd be able to raise your hand as an organization and say I need someone to airlift in and help me out here.
C
Because I'm either that because the country may get outstripped of the, the professionals who respond to incidents if incidents occur more frequently, or we may need to start to proactively disrupt operators when they're hosting infrastructure in our cloud providers or you know, hosting links through our search engines or other things like that. You know, we may need to take more active measures to ensure that they can't operate, you know, freely within the US Right.
B
One of the policy options I thought was interesting is I remember a few years ago there was a cash for clunkers program for people to trade in their old internal combustion engine cars for electric vehicles. And one of your people mentioned to me a targeted rip and replace incentive system for obsolete systems that create national level risk. So I'm assuming water treatment plants and things like the FAA.
C
And if you look just simply at the last 12 months, the primary vector that bad actors have gained access to organizations is through exploiting what's called perimeter devices. So think security devices that are on the edge of your network or remote access devices that are on the edge of the network that are designed to sort of defend against these adversaries. They're often old, they have vulnerabilities, they have poor trust architecture and those devices have been the primary gateway for the actors. We would propose that across the 16 critical infrastructure sectors, we should scan for all of those vulnerable devices and just replace them. If you limit the actors, what's called initial access, by just taking that vector away, you can make this problem significantly harder, even though there are these great AI capabilities for actors.
B
Similarly, just updating to the latest software, open source libraries can dramatically reduce your risk as well. And so Pat, it was great to have you on and this was a great discussion. I think. You know, why did we do this? We're doing this because we think that a lot of our clients who run large and small and mid sized companies may be facing a bit of a tsunami here that they're not expecting and they need to start to focus on this. And I think it's important for organizations like JP Morgan to take what we're learning from Project glasswing and share some of those insights.
C
That's great. I really appreciate being here and as you said, this is an important moment in time for many organizations to recognize recognize the challenge that is now on our doorstep and to start to take those proactive measures to more fulsomely defend the organizations from disruption.
B
All right, thank you very much. Good to see everybody. We'll see you again in August. So long.
A
Michael Semblist's Eye on the Market offers a unique perspective on the economy, current events, markets and investment portfolios and as a production of JP Morgan Asset and Wealth Management. Michael Semblist is the Chairman of Market and investment strategy for J.P. morgan Asset Management and is one of of our most renowned and provocative speakers. For more information, please subscribe to the Eye on the Market by contacting your JP Morgan representative. If you would like to hear more, please explore episodes on itunes or on our website. This podcast is intended for informational purposes only and is a communication on behalf of JP Morgan Institutional Investments Incorporated. Views may not be suitable for all investors and are not intended as personal investment advice or a solicitation or recommendation. Outlooks and past performance are never guarantees of future results. This is not investment research. Please read other important information which can be found at www.jpmorgan.com disclaimer EOTM.
Host: Michael Cembalest
Guest: Pat Opet (Global Chief Information Security Officer, J.P. Morgan)
Date: July 22, 2026
This episode, titled “The Summer I Turned Pretty,” uses a pop culture reference to mark a "turn" for Michael Cembalest: he’s growing "pretty cautious" about two major areas—(1) the rising cybersecurity risks from frontier AI models and (2) technical fragilities in market structure and the competitive pressures on leading AI labs. The bulk of the episode focuses on cybersecurity, especially the wave of zero-day cyber attacks accelerated by advanced AI, drawing on new data, real-world vulnerabilities, and expert insights from J.P. Morgan's Chief Information Security Officer, Pat Opet.
Cembalest and Opet’s conversation is a wakeup call for investors, business leaders, and policymakers: AI-powered cyber risk isn’t just on the horizon—it’s here, faster and more unpredictable than ever. Robust, proactive cyber hygiene is now table stakes. Meanwhile, the competitive dynamics among AI labs and the structural fragilities in software supply chains create new market risks and cost pressures. The episode powerfully blends empirical evidence, frontline experience, and policy thinking—leaving listeners with a stark but actionable sense of urgency.