IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
Jupiter One CEO: Bank industry should measure AI risk by exposure, not access

Jupiter One CEO: Bank industry should measure AI risk by exposure, not access

Tue, 21st Jul 2026 (Today)
Jake MacAndrew
JAKE MACANDREW Interview Editor

The frontier model race has intensified as governments restrict access to some of the most advanced models like Anthropic's Mythos. Paul Forte, Chief Executive of cybersecurity firm Jupiter One, argues that access alone does little to protect an institution. The real determinant of resilience is how well a bank understands its own internal systems.

A recent report from JupiterOne found that the average enterprise generates over 12,000 critical vulnerabilities a week, a volume of signal that exceeds what security teams can review manually.

Forte said there is no single common entry point that AI-driven attacks exploit across financial institutions. Rather, frontier models can identify the specific weakness in a specific bank's unique environment quicker than a human team could, then use that access to move toward an institution's most sensitive systems once infiltrated.

"Access to these models doesn't give you readiness, right? You could give access to 40 banks ... But the outcomes would be different for every one of those banks, depending on their understanding of their internal systems. So the equal access doesn't necessarily give you a level playing field. It just amplifies the gap that exists between those companies that don't understand what they have inside."

Jupiter One built its platform around graph-based architecture, mapping the relationships between an organisation's digital assets, including identities, privileges and access rights, rather than listing them individually. 

Between 30 and 40 per cent of Jupiter One's customer base operates in the financial services sector, according to Forte, including one institution he described as a global Fortune 100 company. He said the firm became involved with that institution early in its response to concerns over frontier AI, helping it build visibility into its own systems.

While the platform itself does not deliver complete understanding of an organisation's environment; rather, it provides the architecture for that understanding, and the outcome still depends on how thoroughly an institution integrates its systems and builds out its data models.

Forte compared a conventional, list-based view of an organisation's systems to a two-dimensional floor plan: it can show where a room sits, but not the fastest route between one point and another, such as a corridor, a window or a lock connecting two parts of a building. He said understanding those connections, rather than the assets themselves, is what determines how quickly a vulnerability can be exploited.

"If you had a blueprint of a house, it would typically be in two dimensions - you could look at that two-dimensional representation of the house and be able to figure out where the master bedroom was, probably. But if I said to you, 'What is the fastest and easiest way to get to the safe that is in the closet in the master bedroom?' You wouldn't know how to do that ... maybe that safe has a stairwell that is behind it that is connected to a window that is in the front of the house - and that becomes the fastest path and the easiest way to get to that safe. You can't get that from a 2D drawing."

He identified two characteristics that leave financial institutions particularly exposed: the sensitivity of the data they hold, and the complexity of systems that have often been built up over many years without a clear map of how they connect.

"Defenders think in terms of lists. Attackers are thinking in graphs," said Forte. "If a defender actually thinks in terms of a graph, and gains understanding of the context and the relationships between the assets in the environment - the defender actually has the advantage because they're on the inside already. They just have to spend the time to understand it."