Go back

JPMorgan’s CIO on AI, Global Financial Systems

30m 43s

JPMorgan’s CIO on AI, Global Financial Systems

JP Morgan's Chief Information Officer discusses the transformative impact of generative AI across the firm, emphasizing its rapid adoption and broad application. AI is now embedded in core operations, from agentic coding tools that accelerate software development to customer service enhancements and wealth management tools like ConnectCoach, which speeds up advisor information access by over 90%. The pace of change is unprecedented, faster than earlier tech cycles, pushing the bank to rethink how it works, not just apply new tools. Key challenges include balancing innovation with risk management, rewiring the software development process for multi-step agentic workflows, and shifting from counting use cases to embedding AI in strategic priorities. ROI measurement is evolving, focusing on interim metrics like code delivery speed while ultimately tying back to business outcomes like revenue and cost of service. The buy vs. build strategy remains pragmatic, favoring external solutions for non-differentiating needs but building custom capabilities for security and scale. Cybersecurity is a critical focus, with JP Morgan collaborating on industry initiatives and publishing guidelines on essential practices like whitelisting connections, managing open source risks, and enabling rapid patching to protect critical infrastructure. The conversation highlights a holistic, adaptive approach to AI, balancing technological advancement with operational resilience and strategic value creation.

Transcription

4927 Words, 27669 Characters

English
[music] Thanks so much, Lori, for being here. I think it's just a little over a year since our last conversation on the Tech Disruptors podcast. I can't believe all the change and really the rate of acceleration of that change, AI model development, adoption. I think your CFO Jeremy Barnum said a couple months ago that you were doubling the use cases and then Jamie Diamond, your CEO a couple weeks ago saying, "I think it's a thousand with 50 to 60 meaningful." So maybe just we can dive right in, you can tell us a little bit about some of these use cases. Where are you seeing the most impact and maybe give us some example of those 50 to 60. Sure. Well, first of all, thanks for having me and thanks for everyone joining. I think this is such a fun time, not only to be in financial services, but to be in technology and the pace of change is so much greater than we've ever seen. When you think about it from a business strategy perspective, we certainly, of course, in technology. A lot of our products and services are built in technology and so there's been a huge opportunity there. We've had coding assistance, now, agentec coding tools deployed to our engineers for over a year now. And coding assistance since October is, we started to see them maturing and it certainly has come a long way from code completion to true multi-step agentec capabilities. And we are just seeing huge opportunity there, sure we can dive deeper, but it's not just about using the tools, it's actually changing the way we work. And that's much more beyond software engineering and terms of now looking at the entire product development cycle across product design data and technology. So that's one big way. But that one's important to us because, again, it's how we create a lot of the products and services and experiences we deliver to customers. We certainly are seeing opportunities across customer service and optimizing better response, personalization at scale and the consumer businesses. That's a huge opportunity when you think beyond the traditional chase, deposit accounts, credit card, but really into connected commerce and how we think about that going forward. Huge opportunity in our wealth management businesses, ConnectCoach is one of the things we've talked about. Our advisors are getting access to information over 90 percent faster. They're able to handle more client calls whenever we see disruption in the market, the speed at which they can answer client questions or proactively outreach. That helps drive revenue. And so I think the exciting thing about where we are in our journey is you're really starting to see knowledge work, technology, I mean a bank is full of knowledge workers really being applying this beyond fraud in all the ways we used to apply it more much more broadly across our businesses. We move over $12 trillion a day in payments. So if clients want to understand how they optimize cash flow, another opportunity of where we're building AI solutions to help them do that. And so many examples. And it does seem like to your point a lot of the focus with AI, people focus on what's the impact to employees and productivity in the cost side, but really the revenue generation inside that seems really exciting. Yeah, yeah, definitely. And you've also talked about driving, change leadership. I mean, this is transformational change and I would imagine. I mean, is this the most accelerated rate of change you've seen in any technology across the company? Definitely. And I think across, just technology in general, when you think about, I've lived through many cycles in technology, being in technology my whole life, whether it was the internet or mobile. And just the moment those technologies came out to the point of broad scale adoption and value realization for the business. And you look at what's happening now, definitely much faster. And just a couple of examples. When the internet came out, it was 10 plus years till we really started seeing meaningful value driven from that. You look at just the speed of adoption of the technologies, whether it was Munchatt, APT came out, very quick adoption. But now enterprise value, we can definitely see, again, looking at the whole product development life cycle and then the business output values, the way to look at it, but acceleration of the coding task. You're starting to see that as we see that broaden across beyond coding. Again, that's just one example, but there is a lot of ways that this is really starting to change. And then as you're quickly, with this quick change, I mean, I can't even imagine trying to drive that change management across an organization at the scale of JP Morgan. Can you talk about what has been sort of the most difficult part of that challenge as it compute, as it data quality, as it talent, as it risk management? I know it's probably some combination of all of the above, but we'd love to hear a little bit more about that. Look, we spend 20 billion in tech, so compute's not usually the problem for us. The challenge is a little bit more, I think, beyond the technology moving quickly and iterating and changing so quickly. The thing that's been a bit of a challenge is really just understanding this whole, we always have to balance. Banks always are great at risk taking and managing risk and innovation. You know, through, we've been through a lot of innovation cycles, we've been in business over 200 years. There's been a lot of innovation cycles that we've lived through. Part of the issue is now you have to really balance the degree at which you take risk and manage that in a safe, secure, resilient way. At the same time, you can't be slow on the innovation front either. And the speed of both of those things, because these models are really good at cybersecurity, which I'm sure we can talk a bit more about as well. The change management, when you look at a technology like this, it is broadly deployed across our entire technology stack. How we think about AI infrastructure, how we think about our data all the way up to the stack, how we deliver our products, platforms, our experiences to our customers, and with the broad technology like that, it actually helps change the way you work. And so we're not just having engineers use the tools and the ways of working before. You almost, to some degree, have to rebuild the factory. I was like the steam engine analogy, which you really didn't get the value out of it by just applying a new technology. You really had to change the way. And I look at, you know, we produce, we manufacture the products and services for the company. How do you actually rewire the factory to get the full value? So longer do you take sort of the product specification, split it up into multiple feature teams, you really rebuild the harness of how software is delivered. And I think the reason I'm mentioning that as some of the hardest parts is the paradigm shift to avoid incrementalism, to not just apply, you know, a new capability on top of everything else. But rewire, if you want to work in a multi-step agentic mode, you have to have the autonomy. How do your governance processes work? How do your evaluation layers work? How does your orchestration work? How is work divided amongst teams? So the first thing you don't run into is, oh, now I have a dependency on this team, so I'm paused. Creating tickets. You know, so you have to really sort of reimagine. And I think that's the hardest part is what God is here today won't get us there tomorrow because it's a huge paradigm shift in the way of working of knowledge workers in particular in software engineering because that's here with us right now. And so it's all those pieces that you have to put together. And that's why M&G me talks about the 50, like we have lots of use cases. It's almost embedded in everything we do. And we've really pivoted away from thinking about use cases to embedding it in our business strategies because AI is a component of the solution, right? It's more about the ultimate, you know, how you create the value. And so we wanted to make sure we weren't just counting use cases, but we're back to what are the top 50 strategic priorities for the firm and how is AI a part of delivering those solutions? And that's really the hardest part that's been pivoting to going forward. And then you can wrap culture people, the ways of working, right to really just all around that. All of that. All of that. All of that. Yeah. And how does that require a change in how you interact with the other business leaders, like CrossJP Morgan, and, you know, just since it is becoming just a fundamental part of the business, is there some kind of organizational, structural change you've contemplated or executed? I think that one of the things we're assessing now with pilot groups, pilot groups that extend across the product development lifecycle is what is that? What does that ways of working look like going forward and that includes anything? What are the tools, capabilities, structures that make sense? For us, we've always been organized. We are managing and running large enterprise technology platforms. We have an organization structure where those CIOs are also deeply embedded in the business. But it is interesting because now we're seeing product teams where everyone used to have distinct roles. But a product leader that is very good at describing the problem can mean into the design a little bit of the vibe coding so you can get a clear view of the product you're trying to build. And of course, we need our engineers to really harden and bring the security and resiliency. But instead of working in a backlog mode, like here's the work, pass it over to the next team in the conveyor belt, it actually is much more dynamic and iterating. And we're going to take these pilot groups and we're going to assess, and that is going to feed into some just strategic work around how we think about all those things going forward. And look, no one has all the answers. I think we're testing and learning more that we have to be agile because the stuff is changing so rapidly that one of the best things we can do strategically is understand how to pivot quickly. And so given that holistic approach, how do you think-- how do you think about ROI on Genai? And is it different than the way you've traditionally thought about it? Just given, as you said, it is so becoming so integrated into the business. Is it just integrated into the overall ROI? Or are you thinking about that separately? You mentioned your 20 billion in spending earlier. Yeah, I mean, it's interesting because in the early days to get momentum, we carved out what we were spending and we carved out value creations specifically from more before Genai, right? Models, say it was fraud or whatever. As we move forward, we realize this is deeply embedded in the fabric of how we deliver. And it's even in the coding world, if you think about what I said, redesigning the factory. I'm changing processes. I'm changing maybe the roles that people play, removing some task, adding new tasks, et cetera. How do I attribute? I think you can cause brain damage almost trying to attribute. Exactly. What piece came out of a process change? What piece came out of AI? What piece came out of-- when I look at a lot of our systems and platforms that rerun at incredible scale, a lot of the cost is still traditional infrastructure compute, et cetera. And so it's funny because I see people call things an AI thing. OK, that was a portion of it, yes. But actually, you have to look at total cost of ownership. We also think about things in a horizon. So there are things we knew we needed to do. We wanted to build our own a genetic platform for various reasons, the cybersecurity, the agentic identity and access management, things like that, that we're going to be across the firm. Those are no regrets moves. Those are horizon zero. We're going to invest in them. We're not going to torture ourselves with ROI, et cetera. We're going to measure execution. We're going to make sure we're building the solutions that work across our business teams. But that's a different method. When you think about some of the ways that we're applying AI in our business, in technology, for example, in software development, we're looking at metrics that measure progress. Like, am I getting more code delivery? I can tell you, with all the agentic tools, we're delivering more code to production. We're speeding up the cycle, et cetera. All those are positive metrics. But none of it matters if I don't get the right business how come on the other side of it. And so now we're pivoting more towards, how do you track those interim measures to make sure the tokens you're spending are creating value, et cetera? But how you not lose sight of the ways we've always measured value in our businesses, the true business outcome metrics. And so it's definitely changing and shifting some of the things in some cases where you're driving efficiency. I should be showing that my cost of serve is coming down, those types of things. But in other cases, I think you'll look at-- we'll have some different interim metrics along the way, but we're really going to ultimately measure on the true business value. What was the revenue generated cost to serve, those kind of things? And I guess along those lines, how do you think about the buy versus build decision and potentially outsourcing to some SaaS vendors? And how did that factor into some of this holistic thinking? Yeah, we had a broad strategy around software anyway, which is if it wasn't competitively differentiating, we didn't build it. We were going to buy. And so I think everybody jumped on sort of SaaS. And there's a lot of SaaS we use, both enterprise SaaS. When I started in this job nine years ago, we had multiple versions of people who are so soft and multiple versions of SAP and our own custom things. And over time, we've consolidated those to somebody enterprise software platforms. I think that's a category where there's still a system of record for us, service now. There's other examples. There's still a system of record for us. I think there's a lot of pressures there should be on them to continue to evolve how do they think about the price they pay for the value they create. That's going to continue to evolve over time. We also use a lot of more fintax or other smaller companies, which again, the game is changing in terms of how you think about Bivers' build. It's harder to replace and frankly, a focused problem issue on those big enterprise platforms. But there are spaces where we put those point solutions that look differentiated. But sometimes for us, the biggest challenge has been getting the scale and meet our security requirements. Now with this world we're living in, it's easier-- I'm going to say easier-- easier to create software faster. And when you think about the true cost of ownership and third party risk from a cyber perspective is one of the greatest areas of risk, right? Especially think about the agentec world. There are definitely places where we would have a different conversation and probably make a decision than where we were a few years ago. And cyber is obviously something that you've always had. A lot to guard against. There are rising risks. Mythos is obviously a concern perhaps. You can share with us your thoughts on what JP Morgan is doing to protect the bank. And then maybe if you have thoughts on the system broadly to cyber. Yeah, look, the models have gotten very good at cyber security from both perspectives, detecting vulnerabilities, but also helping us when we think about the offensive side of cyber to defend and protect the bank and ultimately our clients and customers. And it's true for all the models, because you generally see a normalization of capabilities. Some are better at certain things. And then you see a lead time. And so we were happy to be part of glass wing from the perspective of making sure that not only the technology perspective was brought to the table, but those of us that have responsibility for running critical infrastructure. We're the most globally systemic way important bank in the world. When you look at it relative to the responsibilities we have for critical infrastructure, moving $12 trillion a day. We have global systemic payments that can shut down the economies of the world if we can't move the money. And so it was really important for us to understand the capabilities and work with the model providers in this case, and the topic. But others too, because OpenAI and others have also come out with models to truly understand the power and the capabilities. And so we are definitely working not only across JP Morgan Chase, but across the industry. One of the biggest things we actually wrote a blog, it's on JP Morgan Chase's tech blog, 10 Things. And these were things that we suggested that regardless of if you had the model or not, 10 things every company should think about. So every outbound connection we have is white listed. There was pure proxy piece of work that we've done. We suggested everybody think about that. Really knowing your open source. Are there open sources one of the biggest areas of risk? And the reasons a big area of risk is because as soon as those vulnerabilities are understood, it's in the open source community. And so the big piece that's been working on, and you saw it come through in the executive order, is how do you think about a clearing house to be able to safely disclose the vulnerabilities and do it in a way that you don't crush critical infrastructure before there's an opportunity. Because we know that when a patch comes out, it's within hours many times. You can see someone reverse engineering. And so in that blog, we talked about everything from the fact that for what we call our essential services, that's what supports critical infrastructure, though we have to be able to apply a change within 24 hours. Now think about the implications of that to how you build and deliver, build package deliver software. It fundamentally changes like every, we have of course applications that can do that, but not every application. And so that's something that we suggest everyone works on. Why is because if these things are coming at you at speed, one of your greatest lines of defense is to be able to apply the change quickly, which also means, being smart about the open source you use, is there an active maintainer, et cetera, being smart about staying version current, doing that not only for open source, but across your infrastructure. And these are all, again, these are all things that we lay down in the blog. On the other side of it, it's really good at finding needles in the haystack. So think about anything from on the offer. from inside or threat to fraud, to being able to detect nefarious activity, whether it's from, there's always a lot of talk about nation state, but if you think about these capabilities someday, what if they made their way into open source? Then there's broad access. And so all the things, again, we outlined it in this blog, if it's helpful to anyone. But those are all the things we put out, our clients kept asking us what should we do. And then of course, as you see these models evolve, you can see a world where they're in the build part of the development process. So we're continuously building secure software over time. So lots more to come on this topic. We could probably spend 30 minutes talking about cyber, but it's a whole new world in the way. Usually you used to have security professionals that would understand, and with the way in the maturity of these models, it democratizes that a bit as well, which is both good. But there's a risk side of that too. And I think every company, we all have a lot of work to do to think about this new paradigm and how we prepare ourselves to manage and navigate through it. Yeah. And so obviously cyber has been a big responsibility of your bank for a long time. But also, I guess in the realm of perhaps risks, but also strengths is trust. So trust is something that's always been vital to the bank and the banking system. Trust, I think, is becoming even more important, obviously, in the age of AI and brand. Obviously you have a very strong brand or a couple of brands. So how do you think about that aspect in terms of using agents and customer-facing agents? And how do you think about, you know, are there new answers there in terms of protecting the brand and protecting that trust? Yeah. So I think about it two ways, both, again, offensively and defensively. If we stay focused on how we meet the needs of our customers and clients, because we both have the wholesale side of this and the consumer side of this. How do we get them access to information? I mean, some individuals would choose to go through more of an agentic channel to service their needs. You know, behind the scenes, we're making sure we've got the guardrails in place. The information is correct. And we'll step into this in the right way. We're implementing an agentic solution for employees, you know, we're down the path. Just to test and learn what a true multi-step agentic choosing the right tools. So think about if I had a benefits question and I needed to take an action, or I'm going to visit a location and I need the security and find a desk and all the information around that, having agents behind the scene helping from that perspective. Or the last time I got a new iPhone, I used the agent to help me set it up. And I didn't have to talk to anybody. There's multiple channels and consumers should always, you know, sort of choose the channel of choice. But I think it's our responsibility to provide the options, including an agentic channel. And making sure that we understand that the evaluation layer, the guardrails, of course, were always focused on protecting customer data. We have, you know, since we operate in over 100 countries, we have a lot of laws, rules, and regs. We have to be compliant with. But also doing something internally and testing and learning. One of the biggest things early on, and one of the reasons we wanted to have our own agent platform, is to really think about things like identity and access management. Humans have conscious, you know, and agents are very powerful. But you really have to think about what are the identity and access management patterns? What are agents authorized to do? How do you think about doing those from a least privileged perspective, and making sure that you have the guardrails to test and keep things operating? And so when you step into the external facing, there's some types of transactions outbound calling, et cetera, that may make, you know, more sense. We'll test, we'll learn, we'll keep human in the loop, and we'll continue to evaluate. And then, you know, perhaps stepping back and thinking about, you know, Jamie's annual letter, he talked about just that the transformational change of AI, the breadth, the depth, and we know he doesn't use any of those words lightly. And then certainly all of the leaders are weighing in. When you think about, say the next three to five years, what do you think will drive the biggest structural change or competitive advantage for JP Morgan? Yeah, it's such a three to five years almost. It's hard to predict these days. But I think there's things that matter no matter what. We have over an exabyte of data. We have data is one of the things that still, you know, the depth and breadth of our data is something that can be a competitive advantage. How we serve our customers? Our customers believing that we are a business of trust, that we protect not only the bank, but our customers and clients. I think that's going to matter, no matter what. I think the speed at which we can, you know, it's interesting because there was so much focus early on about the models. I think over time, the models of course are important, but they're going to be foundation models, they're going to be large data models that will create, they'll be open source models, they'll be fine tune models, they'll be all kinds of models. At the end of the day, your ability to deploy this in a safe and secure way, at scale. When you think about the responsibilities we have from a business perspective, you know, that the governance of it, the ability to do it safely and securely. And to maintain that business of trust foundationally for us, those are the most important things we can navigate. And there's going to be lots of different paths around that. We could talk about everything like token cost and how we think about choosing the right model and how you optimize spend. And there's a lot of things that I'll go in the expense bucket. Those things work itself, it worked itself out in the cloud over time. People were over spending in the cloud, we're upside down and figured that out. But the most important thing is maintaining our credibility as a business trust, earning the right to be the most globally systemically important bank in the world, continuing to earn customers. And all of that ties to our brand recognition over time. And then just perhaps broadening out just to get your perspective, if you think about AI broadly across the financial services industry, what do you think the biggest misconception is or misunderstanding, either positive or negative? I think it's hard to answer it with one. I do think there's a lot of incrementalism. A lot of people like to talk about their use cases, etc. I do think how broadly impactful it is and how you really have to think about re-engineering business processes, the talent you need for the, you know, what are the different ways you leverage talent? Of course, there's some tasks going away. And I think this leads into the other one, which is, I don't know about anyone else, but I can tell you that, you know, it's great that our engineers are getting productivity because the backlog of stuff, the ideas, the demand, is like insatiable from a business perspective. And so, yeah, we're able to do code more efficiently. I think time will tell how that looks like. It's amazing to see that we can work more dynamically and get speed to market in products. But with the work we have around glass swing and other things, we're able to absorb that on top of the feature function work that are businesses because of the productivity and the timing of this whole hitting. And so, I think sometimes there's this misconception about, you know, the disconnection of workforce. I do, we do spend a lot of time thinking about it because I think a lot of it will tie to the speed at which the new opportunities and the new jobs can form and how quickly a company can evolve. But the one thing, like I said, is if a company does this at the right pace and speed and grows, again, you can grow and you can grow more efficiently into the cycle. And so, anyway, I think those are a couple of the things that are out there. And who notes? Like, anyone's guess this is good as anyone else. And it's an amazing time and the speed of change is happening. It's actually hard to predict what the future looks like. Yes. And it'll be interesting to see. Hopefully we can get together again another year from now. And perhaps talk about, you know, the ever-evolving pace of change exceeding even our expectations today. Yeah, that would be great. But thank you so much. I really appreciate the discussion. And again, look forward to catching up any of you. Thank you.

Podcast Summary

Key Points:

  1. JP Morgan is experiencing rapid AI adoption, with use cases growing from doubling to over a thousand, with 50-60 deemed meaningful.
  2. Key applications include agentic coding tools for engineers, customer service optimization, wealth management (e.g., ConnectCoach), and payment cash flow solutions.
  3. The pace of AI change surpasses past technologies like the internet or mobile, with faster enterprise value realization.
  4. Major challenges include balancing risk and innovation, rewiring the software development "factory" for agentic workflows, and avoiding incrementalism.
  5. ROI measurement is shifting from separate AI-specific metrics to embedding AI in overall business outcomes, with interim metrics like code delivery speed.
  6. Buy vs. build decisions are evolving, with a preference for buying non-differentiating software but building custom solutions for security and scale.
  7. Cybersecurity is a top priority, with JP Morgan contributing to industry efforts (e.g., Glasswing) and publishing a "10 Things" blog on essential practices like whitelisting connections and rapid patching.

Summary:

JP Morgan's Chief Information Officer discusses the transformative impact of generative AI across the firm, emphasizing its rapid adoption and broad application. AI is now embedded in core operations, from agentic coding tools that accelerate software development to customer service enhancements and wealth management tools like ConnectCoach, which speeds up advisor information access by over 90%. The pace of change is unprecedented, faster than earlier tech cycles, pushing the bank to rethink how it works, not just apply new tools.

Key challenges include balancing innovation with risk management, rewiring the software development process for multi-step agentic workflows, and shifting from counting use cases to embedding AI in strategic priorities. ROI measurement is evolving, focusing on interim metrics like code delivery speed while ultimately tying back to business outcomes like revenue and cost of service. The buy vs.

build strategy remains pragmatic, favoring external solutions for non-differentiating needs but building custom capabilities for security and scale. Cybersecurity is a critical focus, with JP Morgan collaborating on industry initiatives and publishing guidelines on essential practices like whitelisting connections, managing open source risks, and enabling rapid patching to protect critical infrastructure. The conversation highlights a holistic, adaptive approach to AI, balancing technological advancement with operational resilience and strategic value creation.

FAQs

Key use cases include AI-powered coding assistance and agentic tools for engineers, customer service optimization and personalization, wealth management tools like ConnectCoach that speed up advisor information access, and payment optimization for clients moving over $12 trillion daily.

AI adoption is much faster; the internet took over 10 years to show meaningful value, while AI has seen rapid enterprise value realization in a shorter time, especially in coding and product development.

Challenges include balancing innovation with risk management, rewiring workflows to avoid incrementalism, adapting governance and orchestration for agentic models, and managing cultural and organizational change across knowledge workers.

ROI is measured through a mix of interim metrics like code delivery speed and cost of serve, but ultimately tied to true business outcomes such as revenue generation and cost reduction, avoiding over-attribution to AI alone.

The firm buys software that isn't competitively differentiating, like enterprise SaaS, but builds custom solutions for security and scale, reassessing decisions as AI makes development faster and third-party cyber risk more significant.

They white-list outbound connections, monitor open-source vulnerabilities, apply changes within 24 hours for essential services, and collaborate with model providers and industry groups like GLasswing to understand and mitigate threats.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.