JPMorgan's CEO Is Personally Recruiting 40 Companies Into an AI Risk Group. What That Signals for Smaller Institutions
When the CEO of the largest bank in the country starts personally phoning other CEOs about a single issue, that's usually worth ten seconds of attention even if you run an institution a thousand times smaller. That's essentially what's happening right now with AI risk.
Since July, Jamie Dimon has reportedly reached out directly to more than 40 companies, spanning banking, energy, water utilities, telecommunications, airlines, and railroads, to join an expanded version of a group called the Alliance for Critical Infrastructure. JPMorgan helped found the original alliance years ago alongside Mastercard and Berkshire Hathaway Energy, focused on coordinating cross-sector responses to cyber, physical, and geopolitical threats. The new push is repointing that same coalition specifically at AI risk, with the stated goal of being operational by the end of 2026.
Why the largest players are formalizing this now
The timing isn't random. Dimon has been one of the more outspoken large-bank executives about frontier AI risk this year, and the alliance's stated purpose is to build a shared, cross-industry picture of how AI is being used, what it threatens, and what safeguards are actually needed, then bring that picture to policymakers. Notably, the group spans well beyond banking. Water systems, power grids, and telecom networks are being looped in alongside financial services, which tells you something about how AI risk is being understood at the top: less as a single-industry compliance problem and more as a shared infrastructure problem, since so many of these sectors ultimately depend on the same cloud platforms, software vendors, and AI models.
What this means if you're not going to be in that room
A credit union isn't getting a seat at this table, and that's fine. The signal worth taking from it is directional, not procedural. When the largest, best-resourced institutions in the industry are moving to formalize cross-industry AI risk coordination, it's a strong hint about where supervisory expectations are eventually headed for everyone else, the same way large-bank practices around BSA/AML or cybersecurity governance have historically filtered down into examiner expectations for community institutions over time.
The practical takeaway isn't to join an alliance. It's to start building the internal muscle this kind of coalition is trying to build at scale: a clear, current inventory of where AI touches your operations, which vendors are involved, and who inside your credit union owns the answer when a board member or examiner asks "what happens if one of our AI vendors has a security incident." Waiting until that becomes a formal requirement means starting from zero at the worst possible time.
Sources