Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Standard wording or passing mentionDetail: GeneralSame as last periodNew since the annual report
AXP · NY · Large bank ($50B and above)
Total assets of FDIC-insured bank subsidiaries: $211.3B at the end of 2025
Filings on the SEC website · This bank on Bankgraph
| Report year | Using or planning AI | Explains how AI is controlled | Sees AI as a risk | Other mentions |
|---|---|---|---|---|
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2022 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2023 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2024 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 | ||||
| 2025 |
| In the 2025 report | This bank | Banks of its size |
|---|---|---|
| Using AI now | No | 12 of 43 (28%) |
| Explains how AI is controlled | Yes | 30 of 43 (70%) |
| Sees AI as a risk | Yes | 43 of 43 (100%) |
| Mentions generative AI | Yes | 33 of 43 (77%) |
| Mentions AI agents | Yes | 10 of 43 (23%) |
22 passages new in the 2025 report, 12 passages from the 2024 report no longer there.
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence (AI), resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements in these areas, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Regulators and legislators have heightened their focus on the use of AI and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, which are reshaping how we develop, deploy and manage AI systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), AI-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities (including by AI models) and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts.
For more information on privacy, data protection, data management, artificial intelligence, resiliency and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2025 Form 10-K.
“Our consistently strong performance reinforces that our strategy is working well, supported by our ongoing investments in growth initiatives. During the quarter, we continued to expand the access and experiences we provide across sports, a powerful engagement engine with our Card Members, becoming the Official Payments Partner of the NFL globally and extending our long-term partnership with the NBA. We also shared plans for the largest one-year expansion of our commercial product suite in our history, starting with the launch of our new Graphite Business Cash Unlimited Card. And we continued to drive AI innovation with the announcement of the Amex Agentic Commerce Experiences developer kit and industry-first Agent Purchase Protection.
First-quarter consolidated total revenues net of interest expense were $18.9 billion, up 11 percent year-over-year, or 10 percent on an FX-adjusted basis. The increase was primarily driven by higher Card Member spending, increased net interest income supported by growth in card balances, and strong card fee growth. Consolidated provisions for credit losses were $1.3 billion, compared with $1.2 billion a year ago. The increase reflected higher net write-offs and a lower reserve release compared to the prior year. The first-quarter net write-off rate was 2.0 percent, compared to 2.1 percent a year ago. 3 Consolidated expenses were $13.9 billion, up 11 percent year-over-year. The increase was primarily driven by higher variable customer engagement costs due to increased Card Member spending, the U.S. Platinum Card refresh, and usage of travel- and lifestyle-related benefits, as well as higher operating expenses. The consolidated effective tax rate was 21.4 percent, down from 22.4 percent a year ago, primarily reflecting discrete tax benefits in the current quarter. • American Express was named the Official Payments Partner of the NFL and announced a multi-year partnership extension with the NBA across league platforms, including the WNBA. • Kicking off a major expansion of integrated solutions for businesses of all sizes , the company launched the American Express Graphite ™ Business Cash Unlimited Card. • The company announced the Amex Agentic Commerce Experiences ™ developer kit and industry-first Amex Agent Purchase Protection™. • Resy unveiled the next phase of its dining platform , including the planned integration of Resy and Tock venue networks. • American Express continues to expand the Centurion Lounge ® network, opening new spaces in Las Vegas and New Delhi and announcing plans in three other locations. • The company ranked #4 on Great Place to Work’s ® 2026 list of the 100 Best Companies to Work For ® in the U.S.
We delivered strong results for the first quarter of 2026, reflecting continued momentum across the business and execution of our proven growth strategy. We had strong engagement on our refreshed U.S. Platinum products, expanded our membership assets with new and renewed partnerships, and furthered the development of our artificial intelligence (AI) capabilities in the quarter. Net income for the first quarter was $3.0 billion, or $4.28 per share, compared with net income of $2.6 billion, or $3.64 per share, a year ago.
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence (AI), resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements in these areas, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Regulators and legislators have heightened their focus on the use of AI and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, which are reshaping how we develop, deploy and manage AI systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), AI-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities (including by AI models) and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts.
For more information on privacy, data protection, data management, artificial intelligence, resiliency and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2025 Form 10-K.
Our integrated payments platform and the systems and infrastructure that underlie it provide us with data and analytics, while maintaining our commitment to respect Card Member preferences and protect Card Member and merchant data in compliance with applicable policies and legal requirements. Our models and analytical tools help us reduce fraud and underwrite risk, such as in determinations regarding the extension of credit. We also leverage our technology to provide differentiated value to customers, such as special offers and benefits to Card Members and targeted marketing and other information services for merchants and partners, as well as to develop and improve our customer interfaces and service capabilities to continue to deliver a high-quality customer experience. We also continue to explore ways to deploy new and developing technologies to enhance our payments platform and customer experience, such as uses for generative artificial intelligence (AI) and the integration of our products and services in agentic commerce.
Another aspect of competition is the dynamic and rapid growth of alternative payment and financing mechanisms, systems and products, which include payment facilitators and processors, digital payment, open banking and electronic wallet platforms, point-of-sale lenders and buy now, pay later products, real-time settlement and processing systems, financial technology companies, digital currencies developed by both the private sector and central banks, tokenization, blockchain and similar distributed ledger technologies, prepaid systems and gift cards, and systems linked to customer accounts or that provide payment solutions. The development of agentic commerce solutions, in which autonomous or semi-autonomous AI agents initiate and execute transactions on behalf of users, has accelerated as generative AI technologies have advanced and become more popular. In addition, the use of stablecoins, which can be used for payments in a number of settings, including in e-commerce and cross-border and B2B payments, has grown. The integration of these and other new or evolving technologies has the potential to create new or better competitor products, alter the competitive environment and reshape customer payment experiences, including in ways that disintermediate our relationship with customers. Furthermore, the business models and cost structures of competitors in these areas may differ from ours, such as those of certain financial technology companies, which can provide them with a number of advantages, including differing revenue streams, lower costs, greater scale or ability to pursue and adopt new technologies and less stringent regulatory requirements, and may enable them to disintermediate us from our customers. Additionally, various competitors are integrating more financial services into their product offerings and seeking to attain the benefits of an integrated payments platform, such as ours.
Privacy, Data Protection, Data Management, AI, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, AI, resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements in these areas, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may not be sufficient given the size and complexity of our business and heightened regulatory scrutiny.
Our regulators are increasingly focused on ensuring that our privacy, data protection, data management, AI, resiliency, information security and cybersecurity-related policies and procedures are adequate to inform customers of our data collection, use, sharing, retention and/or security practices, to provide them with choices, if required, about how we use and share their information, and to appropriately safeguard their personal information and account access. Regulators are also focused on end-to-end management of data, technology infrastructure and architecture, technology operations, resiliency and business continuity, and third-party risk management policies and practices, with regulatory expectations continuing to increase as we grow in size. For example, the EU Digital Operational Resilience Act requires EU financial entities to have a comprehensive governance and risk management framework for information and communications technology risk. In addition, regulators and legislators have heightened their focus on the use of AI and machine learning (ML) through the application of existing laws and regulations as well as by adopting new laws and regulations, such as the EU AI Act and AI legislation in several U.S. states (e.g., in California, Colorado and Utah). These new and emerging laws and regulations are reshaping how we develop, deploy and manage AI systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
We are also subject to certain privacy, data protection, data management, AI, resiliency, information security and cybersecurity laws in other countries in which we operate, some of which are more stringent and/or expansive than those in the United States and may conflict with each other. The EU and UK General Data Protection Regulations (GDPR) impose legal and compliance obligations on companies that process personal data of individuals in the EU and UK, irrespective of the geographical location of the company, with the potential for significant fines for non-compliance (up to 4 percent of total annual worldwide revenue). The EU and UK GDPR also include requirements concerning the cross-border transfer of personal data and prompt notification of data breaches, in certain circumstances, to affected individuals and supervisory authorities. We are also subject to certain data protection laws in Member States in the EU, which may be more stringent than the EU GDPR. Other countries have also adopted or are considering similar omnibus privacy laws, including Australia, Brazil, Canada, China, India, Japan, the Philippines, Singapore, South Korea and Thailand. Certain countries also require in-country data processing and/or in-country storage of data or for us to provide foreign governments and other third parties broader access to our data and intellectual property. Data breach and operational outage notification laws or regulatory activities to encourage such notifications and regulatory activity and laws around resiliency, business continuity and third-party risk management are also becoming more prevalent in jurisdictions outside the United States in which we operate.
Our privacy and data protection programs have become the subject of heightened scrutiny and review in certain jurisdictions, including in the EU, and we continue to enhance our privacy program to comply with applicable requirements and regulatory expectations. Our compliance with the various and often diverging legal frameworks around privacy, data protection, AI, resiliency, information security and cybersecurity, as well as increased regulatory and legislative activity in these areas, may result in higher technology, administrative and other operational costs and hinder our ability to deploy and scale technology, innovate quickly and effectively utilize data.
The payments industry is highly competitive, and we compete with networks, issuers, acquirers and other payment service providers and methods of payment, including paper-based transactions (e.g., cash and checks) and electronic transfers (e.g., wire transfers and ACH), as well as evolving and growing alternative mechanisms, systems and products (e.g., web- and mobile-based payment platforms). If we are not able to differentiate ourselves from our competitors, develop compelling value propositions for our customers and/or effectively use emerging technologies to grow in evolving areas such as digital payments and agentic commerce, we may not be able to compete effectively.
Some of our competitors have substantially greater scale and resources than we have and may offer richer value propositions or a wider range of programs and services than we offer or may use more effective strategies to acquire and retain more customers, capture a greater share of spending and borrowings, develop more attractive cobrand card and other partner programs, obtain more favorable terms with merchants and maintain greater merchant acceptance than we have. Competition may also intensify as participants in the payments industry merge or enter into joint ventures or other partnerships or business combinations, which may create advantages in competing with our products and services. Government actions or initiatives may also provide competitors with increased opportunities to derive competitive advantages and may create new competitors, including in some cases a government entity. We may not be able to compete effectively against these threats or respond or adapt to changes in customer behavior, such as Card Member spending and borrowing or merchant acceptance, as effectively as our competitors. Costs such as Card Member rewards and Card Member services expenses could continue to increase as we evolve our value propositions, including in response to increased competition. Competitors may also use AI technologies more effectively than us or partner with companies that do so, which may increase the attractiveness and availability of their products and services and allow them to offer greater value propositions and realize greater operational efficiencies.
The payments industry is complex and continues to undergo changes in response to evolving technologies and customer preferences. Spending on our cards could continue to be impacted by increasing usage of credit and debit cards issued on other networks and real-time settlement transactions, such as bank transfers, as well as adoption of alternative payment mechanisms, systems and products, such as digital currencies. The fragmentation of Card Member spending, such as to take advantage of different merchant or card incentives, for convenience with technological solutions or as a result of point-of-sale practices that impact merchant acceptance (e.g., surcharging or differential acceptance), may continue to increase. Revolving credit balances on our cards could also be impacted by alternative financing providers, such as point-of-sale lenders and buy now, pay later products. Regulatory and legislative changes may also significantly alter the competitive landscape, including by facilitating alternative payment or financing mechanisms, such as recent legislation in the U.S. establishing a regulatory framework for stablecoins, or by imposing constraints on payment or financing mechanisms, such as proposals to cap credit card interest rates. To the extent other payment and financing mechanisms, systems and products continue to successfully expand, our discount revenues earned from Card Member spending and our net interest income earned from Card Member borrowing could be negatively impacted. In addition, companies that control access to consumer and merchant payment method choices at the point of sale or through digital wallets, agentic or other commerce-related experiences, mobile applications or other technologies could choose not to accept, suppress use of, or degrade the experience of using our products or could restrict our access to our customers and transaction data. Such companies could also require payments from us to participate in such digital wallets, experiences or applications or negotiate incentives or pricing concessions, impacting our profitability on transactions. As AI technologies are increasingly integrated into payments and related services, such as through the adoption of agentic commerce, these dynamics may accelerate and new dynamics that are difficult to predict may develop, any of which may disadvantage our business.
The competitive value of our data and demand for our products and services may also be diminished as traditional and non-traditional competitors use other, new data sources and technologies, including generative AI, to derive similar insights and by certain regulations. Open banking initiatives, including those promoted by governments and regulators, may result in a number of challenges to our business model, such as disintermediating us from our customers, steering customers away from our products and services or decreasing our attractiveness to partners. Competitors have also sought to create their own integrated payments platforms and may have competitive advantages in doing so as compared to our business.
American Express cards could become less desirable to consumers and businesses generally due to surcharging, steering or other forms of discrimination, which could result in a decrease in cards-in-force, coverage and transaction volumes, including as a result of related actions we may take to enforce our merchant contractual provisions such as terminating merchant contracts. The impact could vary depending on such factors as: the industry or manner in which a surcharge is levied; how Card Members are surcharged or steered to other card products or payment forms at the point of sale; the ease and speed of implementation for merchants, merchant acquirers, processors, payment facilitators or other merchant service providers, including as a result of new or emerging technologies such as AI and agentic commerce; the size and recurrence of the underlying charges; and whether and to what extent these actions are applied to other forms of payment, including whether it varies depending on the type of card (e.g., credit or debit), product, network, acquirer or issuer. We also increasingly rely on merchant acquirers, processors and payment facilitators to manage certain aspects of our merchant relationships and promote and support the acceptance and usage of our cards, but they may have business interests, strategies or goals that are inconsistent with ours. Discrimination against American Express cards could have a material adverse effect on our business, financial condition and results of operations, particularly where it only or disproportionately impacts credit card usage or card usage generally, our Card Members or our business.
negatively impacted by perceptions about our Card Member base, ability or inability of certain individuals or companies to become customers and their usage of our cards and other products and services, and acceptance of American Express cards by merchants in certain industries, when American Express cards are used for payment for legal, but controversial, products and services, or any government inquiries or legislative scrutiny related to customer acquisition practices or card acceptance or usage. The lack of acceptance, suppression of card usage or surcharging by merchants can also negatively impact perceptions of our brand and our products, lower overall transaction volume and increase the attractiveness of other payment products or systems. Adverse developments with respect to our industry may also negatively impact our reputation, or result in greater regulatory or legislative scrutiny or litigation against us. Furthermore, as a corporation with headquarters and operations located in the United States and a brand name referring to the United States, a negative perception of the United States arising from its political or other positions could harm the perception of our company and our brand. These risks to our brand and reputation, as well as other risks described herein, are heightened by the increasing sophistication and availability of AI technology, including by assisting with the creation of deepfakes, increasing the velocity of distribution of disinformation and potentially altering the payments landscape in ways that disintermediate or create a negative perception of us. Although we monitor developments for areas of potential risk to our reputation and brand, negative perceptions or publicity could materially and adversely affect our business volumes, revenues, liquidity and profitability.
Our industry is subject to rapid and significant technological changes. In order to compete in our industry, we need to continue to invest in technology across all areas of our business, including in transaction processing, data management and analytics, AI & ML (including agentic commerce), customer interactions and communications, open banking and alternative payment and financing mechanisms (including related to digital currencies and blockchain technologies), authentication technologies and digital identification, tokenization, real-time settlement and risk management and compliance systems. Incorporating new technologies into our products and services, including developing the appropriate governance and controls consistent with regulatory expectations, requires substantial expenditures and takes considerable time, and may have unintended consequences or ultimately be unsuccessful. We expect that new technologies in the payments industry will continue to emerge, and these new technologies may be superior to, or render obsolete, our existing technology.
The use of AI & ML technologies, including generative AI and agentic commerce, has increased rapidly and may be transformative to the payments industry, heightening the risks described herein and others in ways that may be unpredictable and disadvantageous to us. Our and our partners’ use of AI & ML is subject to various and evolving risks, including flaws in models or datasets that may result in biased or inaccurate results, especially as generative AI has been known to produce false or “hallucinatory” inferences or outputs. The use of AI may also result in unintended or unexpected outcomes, present significant ethical challenges and heighten risks related to information security, the infringement of intellectual property rights and exposure of proprietary or personal information. We may also face challenges in our ability to safely deploy AI systems and implement appropriate governance and controls, which may not be as burdensome to our competitors, and which may impair our implementation or impose additional risks. The complexity of these technologies can make it difficult to assess proper operation, reduce error, or understand and explain their outputs. Adverse consequences of AI & ML remain uncertain but could include flaws in the decisions, predictions, outputs or analysis such technologies produce, subjecting us to competitive harm, legal liability, heightened regulatory scrutiny, greater prevalence of surcharging or other negative point-of-sale practices and brand or reputational harm, as well as decreased demand for our products and services or increased costs.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), AI-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts. These threats have arisen from external parties, including state-sponsored and nation state actors, as well as insiders who knowingly or unknowingly engage in or enable malicious cyber activities. There are a number of motivations for cyber threat actors, including criminal activities such as fraud, identity theft and ransom, corporate or nation-state espionage, political agendas, public embarrassment with the intent to cause financial or reputational harm, intent to disrupt information technology systems and supply chains, and to expose and exploit potential security and privacy vulnerabilities in corporate systems and websites. Cyber threat actors have rapidly evolved their techniques and increasingly utilize advanced capabilities, including the exploitation of unknown security flaws in software and hardware and the integration of advanced forms of AI and other new technology, which can increase the efficacy, severity, frequency and ease of execution of cyberattacks. In addition, new computing technologies, such as quantum computing, may enable threat actors to compromise data encryption and other protective measures.
Our and our partners’ networks and systems are subject to constant attempts to disrupt business operations and capture, destroy, manipulate or expose various types of information relating to corporate trade secrets, customer information (including Card Member, travel, dining and loyalty program data), colleague information and other sensitive business information (including acquisition activity, non-public financial results and intellectual property). For example, we and other U.S. financial services providers have been the target of attacks, such as denial-of-service attacks, social engineering and the impersonation of current or prospective employees and contractors, in some cases conducted by nation state-affiliated actors. We develop and maintain systems and processes aimed at detecting and preventing information security and cybersecurity incidents and fraudulent activity, including our cyber crisis response procedures, which require significant investment, maintenance and ongoing monitoring and updating as technologies and regulatory requirements change, new vulnerabilities and exploits are discovered and as efforts to overcome security measures become more sophisticated. In addition, our own usage of generative AI and other emerging technologies may increase our vulnerabilities or limit our ability to detect intrusion.
Despite our efforts and the efforts of third parties that process, transmit or store our data and data of our customers and colleagues or support our operations, such as service providers, merchants and regulators, the possibility of information, operational and cybersecurity incidents, malicious social engineering, password mismanagement, corporate espionage, fraudulent or other malicious activities and human error or malfeasance cannot be eliminated entirely and will evolve as new and emerging technologies are deployed by threat actors, including the potential use of advanced forms of AI and quantum computing, and we increasingly use platforms that are outside of our network and control environments. For example, we are aware that certain of our third-party service providers and joint ventures have been the victims of ransomware and other cyberattacks, in some instances that affected our data or services provided to us. Furthermore, recently introduced products and services, such as checking accounts and non-card lending, may lead to an increase in the number or types of cyberattacks and our exposure to fraud and other malfeasance. Risks associated with such incidents and activities include theft of funds and other monetary loss, disruption of our operations and the unauthorized disclosure, release, gathering, monitoring, misuse, modification, loss or destruction of confidential, proprietary, trade secret or other information (including account data information). An incident may not be detected until well after it occurs and the severity and potential impact may not be fully known for a substantial period of time after it has been discovered. We are subject to varied cybersecurity regulations and incident reporting requirements, which could require us to disclose incidents that may not have been resolved or fully investigated at the time of disclosure, leading to customer confusion, regulatory scrutiny and negative publicity and exacerbating risks related to the incident itself. Our ability to address incidents may also depend on the timing and nature of assistance that may be provided by relevant governmental or law enforcement agencies.
We face risks from fraudulent activity associated with Card Members, merchants and others, including through bad actors obtaining access to our customer accounts and information and frauds committed by our customers against us. Large financial services firms such as American Express and our customers are regularly targeted by a range of fraudulent activity, including fraud on our card and banking products, false disputes, account takeovers, identity theft and electronic-transaction related crimes, with sophisticated perpetrators increasingly utilizing a range of advanced techniques and multiple parties acting in concert. New or emerging technologies, such as generative AI capabilities, have increased these fraud risks. For example, we have seen our customers targeted by elaborate and voluminous social engineering attacks, which may utilize advanced methods of deception, such as synthetic voice and conversation generation. Information and cybersecurity breaches and other operational incidents that we or third parties experience also increase our fraud risk. Additionally, our introduction of new products and services, expansion into new jurisdictions or usage of new partners or vendors may create new fraud risks or heighten existing risks. While we have policies and procedures designed to address fraud risks, such as customer authentication controls and fraud detection systems, they may be insufficient to accurately predict, prevent or detect fraud.
We rely on third-party service providers, cobrand partners, merchants, dining partners, affiliate marketing firms, merchant acquirers, processors, payment facilitators, network partners and other third parties for services that are integral to our operations and are subject to the risk that activities of such third parties may adversely affect our business. As outsourcing, specialization of functions, third-party digital services and technology innovation within the payments industry and related service functions increase (including with respect to mobile technologies, tokenization, big data, AI and cloud-based solutions), more third parties are involved in processing payment transactions, handling our data and supporting our operations and we may require significantly greater scale from these third parties. For example, we rely on third parties for the timely transmission of accurate information across our global network, card acquisition and provision of services to our customers.
We use models and automation throughout our business, including to inform and support decision making, manage risks, estimate financial values and forecast liquidity and funding needs. Although we have a governance framework for model development and independent model validation, the modeling methodology or key assumptions could be erroneous or the models could be misused. In addition, issues with completeness, accuracy and timeliness of data inputs, the quality or effectiveness of our data aggregation and validation procedures, and the quality and integrity of formulas and algorithms, could result in ineffective or inaccurate model outputs and reports. Models based on historical data sets might not be accurate predictors of future outcomes, such as when we lack recent precedent or recent precedent deviates from current circumstances because of changes in customer behavior, the credit or demographic profiles of our Card Members, the geopolitical or macroeconomic environment or otherwise. We periodically review our models, and updates that we make may result in significantly different outputs. Additionally, we increasingly use models that leverage AI, which are subject to additional risks such as biased or inaccurate results or lowered interpretability. The complexity of these models and our limited transparency into the AI may make it difficult to understand certain outputs or identify errors. Certain models, such as models used to estimate reserves for credit losses under Current Expected Credit Loss (CECL) and Membership Rewards liability, require us to make difficult, subjective and complex judgments, and utilize forward-looking information and information provided by third parties over which we have limited oversight or control. If our business decisions, risk management practices or financial estimates and forecasts are based on incorrect or misused models and assumptions or we fail to manage data inputs effectively and to aggregate or analyze data in an accurate and timely manner, our results of operations and financial condition may be materially adversely affected.
The market for qualified, highly motivated individuals with a range of perspectives is highly competitive and we may not be able to attract and retain such individuals. Advances in technology such as AI may increase competition for individuals with expertise in key skills and require our colleagues to adapt to new skills and methods of working. The unexpected loss of key personnel or our inability to effectively execute succession planning for such personnel could disrupt our business and have an adverse impact on our future performance. Changes in immigration and work permit laws and regulations or the administration or enforcement of such laws or regulations or other changes in the legal or regulatory environment can also impair our ability to attract and retain qualified personnel, or to employ colleagues in the location(s) of our choice. Our compensation practices are subject to regulatory review and oversight, which could further affect our ability to attract and retain our executive officers and other key personnel. Our inability to attract, develop and retain highly skilled and motivated personnel with a range of perspectives could materially adversely affect our business and our culture.
Regulation in the areas of privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, AI & ML and information security and cybersecurity could increase our costs and affect or limit our business opportunities and how we collect, use and/or retain personal information.
Legislators and regulators in the United States and other countries in which we operate are increasingly adopting or revising privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, AI & ML and information security and cybersecurity laws, including data localization, authentication and notification laws. As such laws are interpreted and applied (in some cases with significant differences or conflicting requirements across jurisdictions), compliance and technology costs will continue to increase. Additionally, automated decision making and AI & ML technologies, including the adoption of agentic commerce, present novel and complex legal risks, often with limited established guidance and significant uncertainty. New laws and regulations related to these technologies, as well as the application of existing laws and regulations, may restrict or impose burdensome and costly requirements on our ability to use them or impact other aspects of our business, particularly as the legal landscape related to these technologies remains fragmented with potentially inconsistent requirements.
Compliance with current or future laws in the aforementioned areas could significantly impact our business operations, including our collection, use, sharing, retention and safeguarding of consumer, partner and/or colleague information and could restrict our ability to fully maximize our integrated payments platform or provide certain products and services or work with certain service providers, which could materially and adversely affect our profitability. Our failure to comply with such laws, including as a result of process breakdowns, human error or technical issues, or to maintain sufficient governance and control structures could result in potentially significant regulatory and/or governmental investigations and/or actions, litigation, fines, sanctions, ongoing regulatory monitoring, customer attrition, decreases in the use or acceptance of our cards and damage to our reputation and our brand. In recent years, there has been increasing regulatory enforcement and litigation activity in the areas of privacy, data protection, data management, AI & ML and information security and cybersecurity in the United States, the EU and various other countries in which we operate and our data protection and governance programs have become the subject of heightened scrutiny.
For more information on regulatory and legislative activity in this area, see “Supervision and Regulation — Privacy, Data Protection, Data Management, AI, Resiliency, Information Security and Cybersecurity” under “Business.”
We rely on a variety of measures to protect our intellectual property rights and control access to, and distribution of, our trade secrets and other proprietary information. These measures may not prevent infringement of our intellectual property rights or misappropriation of our proprietary information and a resulting loss of competitive advantage. Our ability to detect infringements of our intellectual property, enforce intellectual property rights and prevent disclosure of our trade secrets and other proprietary information may be limited and such efforts may be costly. In addition, competitors or other third parties may allege that our products, systems, processes or technologies infringe on their intellectual property rights. Given the complex, rapidly changing and competitive technological and business environments in which we operate, and the potential risks and uncertainties of intellectual property-related litigation, a future assertion of an infringement or misappropriation claim against us could cause us to lose significant revenues, incur significant defense, license, royalty or technology development expenses, and/or pay significant monetary damages. Furthermore, given intellectual property ownership and license rights surrounding AI, such as generative AI, are currently not fully addressed by courts or regulators, we may not be able to protect our intellectual property rights against infringing use and our use or adoption of AI may result in exposure to claims by third parties.
"Importantly, we continued to strategically invest in areas that strengthen our Membership Model and drive our growth, such as our successful U.S. Platinum Card refresh and technology enhancements like new app and Gen AI-powered experiences. As demonstrated in our results, our investments are paying off – driving increased customer demand, engagement and loyalty, while generating efficiencies across the enterprise and supporting our excellent credit performance.
Fourth-quarter consolidated total revenues net of interest expense were $19.0 billion, up 10 percent year-over-year, or 9 percent on an FX-adjusted basis. The increase was primarily driven by higher Card Member spending, increased net interest income supported by growth in revolving loan balances, and strong card fee growth. Consolidated provisions for credit losses were $1.4 billion, compared with $1.3 billion a year ago. The increase reflected higher net write-offs, partially offset by a lower net reserve build compared to the prior year. The fourth-quarter net write-off rate was 2.1 percent, compared to 1.9 percent a year ago. 4 Consolidated expenses were $14.5 billion, up 10 percent year-over-year. The increase was primarily driven by higher variable customer engagement costs due to increased Card Member spending and the U.S. Platinum Card refresh. The consolidated effective tax rate was 20.3 percent, down from 21.3 percent a year ago, primarily reflecting changes in the geographic mix of income. • American Express signed a multi-year extension of its British Airways Cobrand Card partnership . • The company advanced Gen AI and agentic commerce initiatives , launching Dining Companion and developing standards with partners to enable agent-driven commerce. • The company opened its 31 st Centurion Lounge at the Salt Lake City International Airport . • The company ranked #1 in U.S. Small Business Credit Card Customer Satisfaction by J.D. Power for the fifth consecutive year. 5 • American Express was named #10 on Fortune's 2026 World’s Most Admired Companies™ list .
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Regulators and legislators have heightened their focus on the use of artificial intelligence and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, which are reshaping how we develop, deploy and manage artificial intelligence systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2024 Form 10-K.
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Regulators and legislators have heightened their focus on the use of artificial intelligence and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, which are reshaping how we develop, deploy and manage artificial intelligence systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2024 Form 10-K.
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable laws and requirements, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Regulators and legislators have heightened their focus on the use of artificial intelligence and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, which are reshaping how we develop, deploy and manage artificial intelligence systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2024 Form 10-K.
Another aspect of competition is the dynamic and rapid growth of alternative payment and financing mechanisms, systems and products, which include payment facilitators and aggregators, digital payment, open banking and electronic wallet platforms, point-of-sale lenders and buy now, pay later products, real-time settlement and processing systems, financial technology companies, digital currencies developed by both central banks and the private sector, blockchain and similar distributed ledger technologies, prepaid systems and gift cards, and systems linked to customer accounts or that provide payment solutions. The integration of new or evolving technologies, such as generative artificial intelligence, has the potential to create new or better competitor products, alter the competitive environment and disintermediate our relationship with customers. Additionally, various competitors are integrating more financial services into their product offerings and competitors are seeking to attain the benefits of an integrated payments platform, such as ours.
Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity
Regulatory and legislative activity in the areas of privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain, policies and a governance framework to comply with applicable privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity laws and requirements, meet evolving customer and industry expectations and support and enable business innovation and growth; however, our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny.
Our regulators are increasingly focused on ensuring that our privacy, data protection, data management, artificial intelligence, resiliency and cybersecurity-related policies and practices are adequate to inform customers of our data collection, use, sharing and/or security practices, to provide them with choices, if required, about how we use and share their information, and to appropriately safeguard their personal information and account access. Regulators are also focused on end-to-end management of data, technology infrastructure and architecture, technology operations, resiliency and business continuity, and third-party risk management policies and practices, with regulatory expectations continuing to increase as we grow in size. For example, the EU Digital Operational Resilience Act, which applies as of January 2025, requires EU financial entities to have a comprehensive governance and risk management framework for information and communications technology risk. In addition, regulators and legislators have heightened their focus on the use of artificial intelligence and machine learning through the application of existing laws and regulations as well as by adopting new laws and regulations, such as the EU’s AI Act and state artificial intelligence legislation (e.g., Colorado AI Act). These new and emerging laws and regulations are reshaping how we develop, deploy and manage artificial intelligence systems, including by imposing new obligations related to data use, recordkeeping, transparency and human oversight.
We are also subject to certain privacy, data protection, data management, artificial intelligence, resiliency, information security and cybersecurity laws in other countries in which we operate (including Member States in the EU, Australia, Canada, China, Japan, Hong Kong, India, Indonesia, Mexico, Singapore, Thailand and the United Kingdom), some of which are more stringent and/or expansive than those in the United States and may conflict with each other. Some jurisdictions have instituted or are considering instituting requirements that make it onerous to transfer personal data to other jurisdictions, and certain countries require in-country data processing and/or in-country storage of data. Compliance with such laws results in higher technology, administrative and other costs for us, could limit our ability to optimize the use of our data, and could require use of local technology services. Some of these laws also require us to provide foreign governments and other third parties broader access to our data and intellectual property. Data breach and operational outage notification laws or regulatory activities to encourage such notifications and regulatory activity and laws around resiliency, business continuity and third-party risk management are also becoming more prevalent in jurisdictions outside the United States in which we operate.
referring to the United States, a negative perception of the United States arising from its political or other positions could harm the perception of our company and our brand. These risks to our brand and reputation, as well as other risks described in this Risk Factors section, are heightened by the increasing sophistication and availability of artificial intelligence technology, including by assisting with the creation of deepfakes and increasing the velocity of distribution of disinformation. Although we monitor developments for areas of potential risk to our reputation and brand, negative perceptions or publicity could materially and adversely affect our business volumes, revenues and profitability.
Our industry is subject to rapid and significant technological changes. In order to compete in our industry, we need to continue to invest in technology across all areas of our business, including in transaction processing, data management and analytics, machine learning and artificial intelligence, customer interactions and communications, open banking and alternative payment and financing mechanisms, authentication technologies and digital identification, tokenization, real-time settlement and risk management and compliance systems. Incorporating new technologies into our products and services, including developing the appropriate governance and controls consistent with regulatory expectations, requires substantial expenditures and takes considerable time, and may have unintended consequences or ultimately be unsuccessful. We expect that new technologies in the payments industry will continue to emerge, and these new technologies may be superior to, or render obsolete, our existing technology.
The use of artificial intelligence and machine learning technologies, including generative artificial intelligence, has increased rapidly with the increasing sophistication and applications of the technology. Our and our partners’ use of artificial intelligence and machine learning is subject to various risks including flaws in models or datasets that may result in biased or inaccurate results, unintended or unexpected outcomes, ethical considerations regarding artificial intelligence, infringement of intellectual property rights, exposure of proprietary or personal information, heightened security risks and the ability to safely deploy and implement governance and controls for artificial intelligence systems. The complexity of these technologies can make it difficult to assess proper operation, reduce error, or understand and explain their outputs. Adverse consequences of artificial intelligence and machine learning remain uncertain but could include flaws in the decisions, predictions, outputs or analysis such technologies produce and subjecting us to competitive harm, legal liability, heightened regulatory scrutiny and brand or reputational harm.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems and company accounts. These threats have arisen from external parties, as well as insiders who knowingly or unknowingly engage in or enable malicious cyber activities. There are a number of motivations for cyber threat actors, including criminal activities such as fraud, identity theft and ransom, corporate or nation-state espionage, political agendas, public embarrassment with the intent to cause financial or reputational harm, intent to disrupt information technology systems and supply chains, and to expose and exploit potential security and privacy vulnerabilities in corporate systems and websites. Cyber threat actors, including state-sponsored and nation state actors, have rapidly evolved their techniques and increasingly utilize advanced capabilities, including the integration of advanced forms of artificial intelligence and other new technology, which can increase the efficacy, severity, frequency and ease of execution of cyberattacks.
Despite our efforts and the efforts of third parties that process, transmit or store our data and data of our customers and colleagues or support our operations, such as service providers, merchants and regulators, the possibility of information, operational and cybersecurity incidents, malicious social engineering, password mismanagement, corporate espionage, fraudulent or other malicious activities and human error or malfeasance cannot be eliminated entirely and will evolve as new and emerging technology is deployed by threat actors, including the use of artificial intelligence and quantum computing, and we increasingly use platforms that are outside of our network and control environments. For example, we are aware that certain of our third-party service providers and joint ventures have been the victims of ransomware and other cyberattacks, in some instances that affected our data or services provided to us. In addition, recently introduced products and services, such as checking accounts and non-card lending, may lead to an increase in the number or types of cyberattacks and our exposure to fraud and other malfeasance. Risks associated with such incidents and activities include theft of funds and other monetary loss, disruption of our operations and the unauthorized disclosure, release, gathering, monitoring, misuse, modification, loss or destruction of confidential, proprietary, trade secret or other information (including account data information). An incident may not be detected until well after it occurs and the severity and potential impact may not be fully known for a substantial period of time after it has been discovered. We are subject to varied cybersecurity regulations and incident reporting requirements, which could require us to disclose incidents that may not have been resolved or fully investigated at the time of disclosure, leading to customer confusion, regulatory scrutiny and negative publicity and exacerbating risks related to the incident itself. Our ability to address incidents may also depend on the timing and nature of assistance that may be provided from relevant governmental or law enforcement agencies.
We rely on third-party service providers, cobrand partners, merchants, affiliate marketing firms, processors, aggregators, network partners and other third parties for services that are integral to our operations and are subject to the risk that activities of such third parties may adversely affect our business. As outsourcing, specialization of functions, third-party digital services and technology innovation within the payments industry increase (including with respect to mobile technologies, tokenization, big data, artificial intelligence and cloud-based solutions), more third parties are involved in processing card transactions, handling our data and supporting our operations. For example, we rely on third parties for the timely transmission of accurate information across our global network, card acquisition and provision of services to our customers.
Regulation in the areas of privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity could increase our costs and affect or limit our business opportunities and how we collect and/or use personal information.
Legislators and regulators in the United States and other countries in which we operate are increasingly adopting or revising privacy, data protection, data management, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity laws, including data localization, authentication and notification laws. As such laws are interpreted and applied (in some cases, with significant differences or conflicting requirements across jurisdictions), compliance and technology costs will continue to increase, particularly in the context of ensuring that adequate privacy, data protection, data management, incident management, resiliency, third party management, data transfer, security controls, account access mechanisms and controls related to artificial intelligence and machine learning are in place. Additionally, new laws and regulations related to automated decision making, artificial intelligence and machine learning as well as the application of existing laws and regulations to these technologies may restrict or impose burdensome and costly requirements on our ability to use them or impact other aspects of our business.
Compliance with current or future laws in the aforementioned areas could significantly impact our business operations, including our collection, use, sharing, retention and safeguarding of consumer and/or colleague information and could restrict our ability to fully maximize our integrated payments platform or provide certain products and services or work with certain service providers, which could materially and adversely affect our profitability. Our failure to comply with such laws or to maintain sufficient governance and control structures could result in potentially significant regulatory and/or governmental investigations and/or actions, litigation, fines, sanctions, ongoing regulatory monitoring, customer attrition, decreases in the use or acceptance of our cards and damage to our reputation and our brand. In recent years, there has been increasing regulatory enforcement and litigation activity in the areas of privacy, data protection, data management, artificial intelligence and machine learning and information security and cybersecurity in the United States, the EU and various other countries in which we operate and our data protection and governance programs have become the subject of heightened scrutiny.
For more information on regulatory and legislative activity in this area, see “Supervision and Regulation — Privacy, Data Protection, Data Management, Artificial Intelligence, Resiliency, Information Security and Cybersecurity” under “Business.”
misappropriation claim against us could cause us to lose significant revenues, incur significant defense, license, royalty or technology development expenses, and/or pay significant monetary damages. Furthermore, given intellectual property ownership and license rights surrounding artificial intelligence, such as generative artificial intelligence, are currently not fully addressed by courts or regulators, we may not be able to protect our intellectual property against infringing use and our use or adoption of artificial intelligence may result in exposure to claims by third parties.
We use models and automation throughout our business, including to inform and support decision making, manage risks and estimate financial values. Although we have a governance framework for model development and independent model validation, the modeling methodology or key assumptions could be erroneous or the models could be misused. In addition, issues with the quality or effectiveness of our data aggregation and validation procedures, as well as the quality and integrity of data inputs, could result in ineffective or inaccurate model outputs and reports. For example, models based on historical data sets might not be accurate predictors of future outcomes, such as because of changes in the credit profile of our Card Members, and they may not be able to predict future outcomes. Additionally, we increasingly use models that leverage artificial intelligence, which are subject to additional risks such as biased or inaccurate results or lowered interpretability. Our models also may not be able to function properly in the current geopolitical and macroeconomic environment given the lack of recent precedent. Certain models, such as models for credit loss accounting under Current Expected Credit Loss (CECL) and Membership Rewards liability, require us to make difficult, subjective and complex judgments, and utilize forward-looking information. If our business decisions or financial estimates are based on incorrect or misused models and assumptions or we fail to manage data inputs effectively and to aggregate or analyze data in an accurate and timely manner, our results of operations and financial condition may be materially adversely affected.
The Enterprise-Wide Model Risk Policy establishes the comprehensive framework for governing model risk. This policy is approved by the ERMC. The comprehensive risk management and governance framework includes procedures for model development, independent model validation, model risk reporting and change management capabilities that seek to minimize erroneous model methodology, outputs, and misuse. We also assess model performance and model- related issues on an ongoing basis and seek to address deficiencies in a timely manner. In addition, we utilize artificial intelligence and machine learning (AI/ML) models, including Generative AI tools, for a variety of business use cases. We perform extensive reviews and testing to reduce the risk that these AI/ML techniques result in adverse consequences.
Regulatory and legislative activity in the areas of privacy, data protection, data governance and information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain and enhance, policies and a governance framework to comply with applicable laws, meet evolving customer and industry expectations and support and enable business innovation and growth; however our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Laws and regulations related to automated decision making, artificial intelligence and machine learning are still evolving and there is uncertainty as to new laws and regulations that will be adopted and the application of existing laws and regulations, which may restrict us or impose burdensome and costly requirements, including on our ability to use artificial intelligence and machine learning. Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be subject to increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks, and similar disruptions, such as from the misconfiguration or unauthorized use of or access to computer systems or from service or system outages. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2023 Form 10-K.
Regulatory and legislative activity in the areas of privacy, data protection, data governance and information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain and enhance, policies and a governance framework to comply with applicable laws, meet evolving customer and industry expectations and support and enable business innovation and growth; however our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Laws and regulations related to automated decision making, artificial intelligence and machine learning are still evolving and there is uncertainty as to new laws and regulations that will be adopted and the application of existing laws and regulations, which may restrict us or impose burdensome and costly requirements, including on our ability to use artificial intelligence and machine learning. Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2023 Form 10-K.
Regulatory and legislative activity in the areas of privacy, data protection, data governance and information security and cybersecurity continues to increase worldwide. We have established, and continue to maintain and enhance, policies and a governance framework to comply with applicable laws, meet evolving customer and industry expectations and support and enable business innovation and growth; however our policies and governance framework may be insufficient given the size and complexity of our business and heightened regulatory scrutiny. Laws and regulations related to automated decision making, artificial intelligence and machine learning are still evolving and there is uncertainty as to new laws and regulations that will be adopted and the application of existing laws and regulations, which may restrict us or impose burdensome and costly requirements, including on our ability to use artificial intelligence and machine learning. Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems. For more information on privacy, data protection and information security and cybersecurity regulation and the potential impacts of a major information security or cybersecurity incident on our results of operations and business, please see the “Supervision and Regulation” and “Risk Factors” sections of the 2023 Form 10-K.
Our brand and reputation may also be harmed by actions taken by third parties that are outside our control. For example, any shortcoming of or controversy related to a third-party service provider, business partner, merchant acquirer or network partner may be attributed by Card Members and merchants to us, thus damaging our reputation and brand value. Our brand may also be negatively impacted by acceptance of American Express cards by merchants in certain industries, when American Express cards are used for payment for legal, but controversial, products and services or any government inquiries or legislative scrutiny related to card acceptance or usage. The lack of acceptance, suppression of card usage or surcharging by merchants can also negatively impact perceptions of our brand and our products, lower overall transaction volume and increase the attractiveness of other payment products or systems. Adverse developments with respect to our industry, including the creation and implementation of new merchant categories codes, may also negatively impact our reputation, or result in greater regulatory or legislative scrutiny or litigation against us. Furthermore, as a corporation with headquarters and operations located in the United States and a brand name referring to the United States, a negative perception of the United States arising from its political or other positions could harm the perception of our company and our brand. These risks to our brand and reputation, as well as other risks described in this Risk Factors section, are heightened by the increasing sophistication and availability of artificial intelligence technology that can assist with the creation of deepfakes and increase the velocity of distribution of disinformation. Although we monitor developments for areas of potential risk to our reputation and brand, negative perceptions or publicity could materially and adversely affect our business volumes, revenues and profitability.
Our industry is subject to rapid and significant technological changes. In order to compete in our industry, we need to continue to invest in technology across all areas of our business, including in transaction processing, data management and analytics, machine learning and artificial intelligence, customer interactions and communications, open banking and alternative payment and financing mechanisms, authentication technologies and digital identification, tokenization, real-time settlement and risk management and compliance systems. Incorporating new technologies into our products and services, including developing the appropriate governance and controls consistent with regulatory expectations, requires substantial expenditures and takes considerable time, and ultimately may not be successful. We expect that new technologies in the payments industry will continue to emerge, and these new technologies may be superior to, or render obsolete, our existing technology.
The process of developing new products and services, enhancing existing products and services and adapting to technological changes and evolving industry standards is complex, costly and uncertain, and any failure by us to anticipate customers’ changing needs and emerging technological trends accurately could significantly impede our ability to compete effectively. Adoption by consumers, merchants and other service providers is a key competitive factor and our competitors may develop products, platforms or technologies that become more widely adopted than ours. In addition, we may underestimate the resources needed and overestimate our ability to develop new products and services, particularly beyond our traditional card products and travel-related services. The use of artificial intelligence and machine learning technologies, including generative artificial intelligence, has increased rapidly with increasing complexity and changes in the nature of the technology. Our use of artificial intelligence and machine learning is subject to various risks including the use of personal information, flaws in our models or datasets that may result in biased or inaccurate results, ethical considerations regarding artificial intelligence, and our ability to safely deploy and implement governance and controls for artificial intelligence systems. Additionally, laws and regulations related to automated decision making, artificial intelligence and machine learning are still evolving and there is uncertainty as to new laws and regulations that will be adopted and the application of existing laws and regulations, which may restrict or impose burdensome and costly requirements on our ability to use artificial intelligence and machine learning. Adverse consequences of these risks related to artificial intelligence and machine learning could undermine the decisions, predictions or analysis such technologies produce and subject us to competitive harm, legal liability, heightened regulatory scrutiny and brand or reputational harm.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems. These threats can arise from external parties, as well as insiders who knowingly or unknowingly engage in or enable malicious cyber activities. There are a number of motivations for cyber threat actors, including criminal activities such as fraud, identity theft and ransom, corporate or nation-state espionage, political agendas, public embarrassment with the intent to cause financial or reputational harm, intent to disrupt information technology systems and supply chains, and to expose and exploit potential security and privacy vulnerabilities in corporate systems and websites. Cyber threat actors have increasingly demonstrated advanced capabilities, including the rapid integration of new technology such as advanced forms of artificial intelligence and quantum computing. Cyber threats, including attacks from state sponsored or nation-state actors, can increase during periods of diplomatic or armed conflict, such as the ongoing Russia-Ukraine and Israel-Hamas wars.
We rely on third-party service providers, cobrand partners, merchants, affiliate marketing firms, processors, aggregators, network partners and other third parties for services that are integral to our operations and are subject to the risk that activities of such third parties may adversely affect our business. As outsourcing, specialization of functions, third-party digital services and technology innovation within the payments industry increase (including with respect to mobile technologies, tokenization, big data, artificial intelligence and cloud-based solutions), more third parties are involved in processing card transactions, handling our data and supporting our operations. For example, we rely on third parties for the timely transmission of accurate information across our global network, card acquisition and provision of services to our customers.
Regulation in the areas of privacy, data protection, data governance, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity could increase our costs and affect or limit our business opportunities and how we collect and/or use personal information.
Legislators and regulators in the United States and other countries in which we operate are increasingly adopting or revising privacy, data protection, data governance, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity laws, including data localization, authentication and notification laws. As such laws are interpreted and applied (in some cases, with significant differences or conflicting requirements across
jurisdictions), compliance and technology costs will continue to increase, particularly in the context of ensuring that adequate data governance, data management, data protection, incident management, resiliency, third party management, data transfer, security controls, account access mechanisms and controls related to artificial intelligence and machine learning are in place.
Compliance with current or future privacy, data protection, data governance, resiliency, data transfer, third party oversight, account access, artificial intelligence and machine learning and information security and cybersecurity laws could significantly impact our collection, use, sharing, retention and safeguarding of consumer and/or colleague information and could restrict our ability to fully maximize our closed-loop capability or provide certain products and services or work with certain service providers, which could materially and adversely affect our profitability. Our failure to comply with such laws or to maintain sufficient governance and control structures could result in potentially significant regulatory and/or governmental investigations and/or actions, litigation, fines, sanctions, ongoing regulatory monitoring, customer attrition, decreases in the use or acceptance of our cards and damage to our reputation and our brand. In recent years, there has been increasing regulatory enforcement and litigation activity in the areas of privacy, data protection and information security and cybersecurity in the United States, the EU and various other countries in which we operate and our data protection and governance programs have become the subject of heightened scrutiny.
The Enterprise-Wide Model Risk Policy establishes the comprehensive framework for governing model risk. This policy is approved by the ERMC. The comprehensive risk management and governance framework includes procedures for model development, independent model validation, model risk reporting and change management capabilities that seek to minimize erroneous model methodology, outputs, and misuse. We also assess model performance and model- related issues on an ongoing basis and seek to address deficiencies in a timely manner. In addition, we utilize artificial intelligence and machine learning (AI/ML) models for a variety of business use cases. We perform extensive reviews and testing to reduce the risk that these AI/ML techniques result in adverse consequences.
We rely on third-party service providers, cobrand partners, merchants, affiliate marketing firms, processors, aggregators, network partners and other third parties for services that are integral to our operations and are subject to the risk that activities of such third parties may adversely affect our business. As outsourcing, specialization of functions, third-party digital services and technology innovation within the payments industry increase (including with respect to mobile technologies, tokenization, big data, artificial intelligence and cloud-based solutions), more third parties are involved in processing card transactions, handling our data and supporting our operations. For example, we rely on third parties for the timely transmission of accurate information across our global network, card acquisition and provision of services to our customers.
Our industry is subject to rapid and significant technological changes. In order to compete in our industry, we need to continue to invest in technology across all areas of our business, including in transaction processing, data management and analytics, machine learning and artificial intelligence, customer interactions and communications, open banking and alternative payment and financing mechanisms, authentication technologies and digital identification, tokenization, real-time settlement, and risk management and compliance systems. Incorporating new technologies into our products and services, including developing the appropriate governance and controls consistent with regulatory expectations, requires substantial expenditures and takes considerable time, and ultimately may not be successful. We expect that new technologies in the payments industry will continue to emerge, and these new technologies may be superior to, or render obsolete, our existing technology.
The process of developing new products and services, enhancing existing products and services and adapting to technological changes and evolving industry standards is complex, costly and uncertain, and any failure by us to anticipate customers’ changing needs and emerging technological trends accurately could significantly impede our ability to compete effectively. Consumer and merchant adoption is a key competitive factor and our competitors may develop products, platforms or technologies that become more widely adopted than ours. In addition, we may underestimate the resources needed and our ability to develop new products and services, particularly beyond our traditional card products and travel-related services. Our use of artificial intelligence and machine learning is subject to risks related to flaws in our algorithms and datasets that may be insufficient or contain biased information. These deficiencies could undermine the decisions, predictions or analysis such technologies produce, subjecting us to competitive harm, legal liability, and brand or reputational harm.
The Enterprise-Wide Model Risk Policy establishes the comprehensive framework for governing model risk. This policy is approved by the ERMC. The comprehensive risk management and governance framework includes procedures for model development, independent model validation, model risk reporting and change management capabilities that seek to minimize erroneous model methodology, outputs, and misuse. We also assess model performance and model- related issues on an ongoing basis and seek to address deficiencies in a timely manner. In addition, we utilize artificial intelligence and machine learning (AI/ML) models for a variety of business use cases. We perform extensive reviews and testing to reduce the risk that these AI/ML techniques result in adverse consequences.
•the company’s ability to achieve its 2026 earnings per common share (EPS) guidance and grow EPS in the future consistent with its growth aspiration, which will depend in part on revenue growth, credit performance, credit reserve and expense levels and the effective tax rate remaining consistent with current expectations and the company’s ability to continue investing in growth initiatives (such as its brand, value propositions, coverage, marketing, technology, partnerships and talent), controlling operating expenses, effectively managing risk and executing its share repurchase program, any of which could be impacted by, among other things, the factors identified in the subsequent paragraphs and the Form 8-K Cautionary Note, as well as the following: macroeconomic and geopolitical conditions, including a slowdown in U.S. or global economic growth, changes to consumer and business confidence, higher rates of unemployment and wide-scale layoffs, impacts from the Middle East conflict and other international hostilities, deteriorations in global trade and the effects of announced or future tariffs, changes in interest rates, inflation, supply chain issues, energy costs, market volatility, and fiscal and monetary policies; the effects of technology changes and the adoption of artificial intelligence (AI); the impact of any future contingencies, including, but not limited to, legal costs and settlements, the imposition of fines or monetary penalties, increases in Card Member remediation, investment gains or losses, restructurings, impairments and changes in reserves; issues impacting brand perceptions and the company’s reputation; changes in the competitive environment and an inability to realize benefits from new and extended sponsorships; impacts related to acquisitions, divestitures, cobrand relationships and other partners; and the impact of regulation and litigation, which could affect the profitability of the company’s business activities, limit the company’s ability to pursue business opportunities, require changes to business practices or alter the company’s relationships with Card Members, partners and merchants;
•the actual amount the company spends on growth initiatives in 2026 and beyond and the effectiveness of the investments, which will be based in part on business performance, contingencies and changes in the macroeconomic and competitive environment, including the levels of demand for the company’s products; management’s ability to balance expense control and investments in the business, develop new capabilities, features and value propositions, effectively utilize artificial intelligence, enhance our digital channels and platforms, and drive customer demand; and management’s identification and assessment of attractive investment opportunities and its decisions regarding the timing of investments; and
•our ability to grow earnings per share in the future, which will depend in part on revenue growth, credit performance, credit reserve and expense levels and the effective tax rate remaining consistent with current expectations and our ability to continue investing in growth initiatives (such as our brand, value propositions, coverage, marketing, technology, partnerships and talent), controlling operating expenses, effectively managing risk and executing our share repurchase program, any of which could be impacted by, among other things, the factors identified in the subsequent paragraphs as well as the following: macroeconomic and geopolitical conditions, including a slowdown in U.S. or global economic growth, changes to consumer and business confidence, higher rates of unemployment and wide-scale layoffs, impacts from the Middle East conflict and other international hostilities, deteriorations in global trade and the effects of announced or future tariffs, changes in interest rates, inflation, supply chain issues, energy costs, market volatility, and fiscal and monetary policies; the effects of technology changes and the adoption of AI; the impact of any future contingencies, including, but not limited to, legal costs and settlements, the imposition of fines or monetary penalties, increases in Card Member remediation, investment gains or losses, restructurings, impairments and changes in reserves; issues impacting brand perceptions and our reputation; changes in the competitive environment and an inability to realize benefits from new and extended sponsorships; impacts related to acquisitions, divestitures, cobrand relationships and other partners; and the impact of regulation and litigation, which could affect the profitability of our business activities, limit our ability to pursue business opportunities, require changes to business practices or alter our relationships with Card Members, partners and merchants;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of AI technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and AI initiatives; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation and supply chain issues; increased technology costs, including AI usage and investments in technology innovations and system upgrades; expenses related to enterprise risk management and compliance and consulting, legal and other professional services fees, including as a result of our growth, litigation and internal and regulatory reviews; the impact of changes in foreign currency exchange rates on costs; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; and impairments of goodwill or other assets;
•changes in the substantial and increasing worldwide competition in the payments industry, including competitive pressure and competitor settlements that may materially impact the prices charged to merchants that accept American Express cards; merchant acceptance, surcharging, steering and other differential acceptance practices; the desirability of competitor premium card products and competition for partnerships and premium experiences, services and benefits; competition for new and existing cobrand relationships; the effects of the emergence of agentic commerce on the payments landscape and customer payment experiences; competition from new and non-traditional competitors, such as financial technology companies, and with respect to new products, services and technologies, such as the emergence or increase in popularity of digital payment platforms and currencies and other alternative payment mechanisms; competitor acquisitions and transactions; and the success of marketing, promotion, rewards programs, offers and travel-, lifestyle- and business-related benefits (e.g., lounges, dining, entertainment and business tools);
•our ability to sustain our momentum and leadership in the premium consumer space, including with Millennial and Gen-Z consumers, which will be impacted in part by competition, levels of consumer demand for premium card products, brand perceptions (including perceptions related to merchant coverage) and reputation, and our ability to successfully refresh our products and develop and market new benefits, services, experiences and other value propositions, as well as new AI and digital capabilities, that appeal to Card Members and new customers, grow spending with new and younger age cohort Card Members, offer attractive services and rewards programs and build greater customer loyalty, which will depend in part on identifying and funding investment opportunities, addressing changing customer behaviors, new product innovation and development, Card Member acquisition efforts and enrollment processes, including through digital channels, continuing to realize benefits from strategic partnerships, successfully implementing our dining strategy and evolving our infrastructure to support new products, services and benefits;
•our ability to successfully invest in, benefit from and expand the use of technological developments, generative AI, digital payments, servicing, travel, dining & expense management solutions and other technological capabilities, which will depend in part on our success in advancing our agentic commerce initiatives, including embedding our payment capabilities in emerging AI ecosystems, such as through the Amex Agentic Commerce Experiences™ developer kit and Amex Agent Purchase Protection™, making Membership assets discoverable and actionable on AI platforms and building proprietary AI-powered experiences across our platforms; embedding AI into our business and increasing automation, including to streamline and improve internal processes and decision making, enhance our products, develop new capabilities and address servicing and other business and customer needs; developing new features in our applications and platforms and enhancing our digital channels; supporting the use of our products as a means of payment through online, mobile, agentic and other digital channels; building partnerships and executing programs with other companies; and effectively utilizing data and data & analytics platforms, including successfully migrating to new platforms, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, partner engagement, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully implement our dining strategy and grow our dining platform, which will depend in part on our ability to deliver value to diners, restaurants and other bookable venues; expand and innovate the tools and capabilities offered through the platform, including successfully integrating Tock into the Resy dining platform and developing AI-powered experiences in the Resy app; enable the search and booking of Resy venues through AI platforms; and successfully implement partnerships and compete with other dining platforms and means of booking reservations;
•the company’s ability to achieve its 2026 earnings per common share (EPS) guidance and grow EPS in the future, which will depend in part on revenue growth, credit performance, credit reserve and expense levels and the effective tax rate remaining consistent with current expectations and the company’s ability to continue investing in growth initiatives (such as its brand, value propositions, coverage, marketing, technology, partnerships and talent), controlling operating expenses, effectively managing risk and executing its share repurchase program, any of which could be impacted by, among other things, the factors identified in the subsequent paragraphs and the Form 8-K Cautionary Note, as well as the following: macroeconomic and geopolitical conditions, including a slowdown in U.S. or global economic growth, changes to consumer and business confidence, higher rates of unemployment and wide-scale layoffs, impacts of the Middle East conflict and other international hostilities and deteriorations in global trade, the effects of announced or future tariffs, changes in interest rates, inflation, supply chain issues, energy costs, market volatility, government shutdowns and fiscal and monetary policies; the effects of technology changes and the adoption of artificial intelligence (AI); the impact of any future contingencies, including, but not limited to, legal costs and settlements, the imposition of fines or monetary penalties, increases in Card Member remediation, investment gains or losses, restructurings, impairments and changes in reserves; issues impacting brand perceptions and the company’s reputation; changes in the competitive environment and an inability to realize benefits from new and extended sponsorships; impacts related to acquisitions, cobrand relationships and other partners; and the impact of regulation and litigation, which could affect the profitability of the company’s business activities, limit the company’s ability to pursue business opportunities, require changes to business practices or alter the company’s relationships with Card Members, partners and merchants;
•the company’s ability to successfully invest in, benefit from and expand the use of technological developments, generative AI, digital payments, servicing, travel, dining & expense management solutions and other technological capabilities and the actual amount the company spends on technology in 2026 and beyond, which will depend in part on the company’s success in advancing its agentic commerce initiatives, including embedding its payment capabilities in emerging AI ecosystems, such as through the Amex Agentic Commerce Experiences™ developer kit and Amex Agent Purchase Protection™, making Membership assets discoverable and actionable on AI platforms and building proprietary AI-powered experiences across its platforms; embedding AI into its business and increasing automation, including to streamline and improve internal processes and decision making, enhance the company’s products, develop new capabilities and address servicing and other business and customer needs; developing new features in its applications and platforms and enhancing its digital channels; supporting the use of the company’s products as a means of payment through online, mobile, agentic and other digital channels; building partnerships and executing programs with other companies; and effectively utilizing data and data & analytics platforms, including successfully migrating to new platforms, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, partner engagement, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations.
•our ability to grow earnings per share in the future, which will depend in part on revenue growth, credit performance, credit reserve and expense levels and the effective tax rate remaining consistent with current expectations and our ability to continue investing in growth initiatives (such as our brand, value propositions, coverage, marketing, technology, partnerships and talent), controlling operating expenses, effectively managing risk and executing our share repurchase program, any of which could be impacted by, among other things, the factors identified in the subsequent paragraphs as well as the following: macroeconomic and geopolitical conditions, including a slowdown in U.S. or global economic growth, changes to consumer and business confidence, higher rates of unemployment and wide-scale layoffs, impacts of the Middle East conflict and other international hostilities and deteriorations in global trade, the effects of announced or future tariffs, changes in interest rates, inflation, supply chain issues, energy costs, market volatility, government shutdowns and fiscal and monetary policies; the effects of technology changes and the adoption of AI; the impact of any future contingencies, including, but not limited to, legal costs and settlements, the imposition of fines or monetary penalties, increases in Card Member remediation, investment gains or losses, restructurings, impairments and changes in reserves; issues impacting brand perceptions and our reputation; changes in the competitive environment and an inability to realize benefits from new and extended sponsorships; impacts related to acquisitions, cobrand relationships and other partners; and the impact of regulation and litigation, which could affect the profitability of our business activities, limit our ability to pursue business opportunities, require changes to business practices or alter our relationships with Card Members, partners and merchants;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of AI technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and AI initiatives; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation and supply chain issues; increased technology costs, including investments in technology innovations and system upgrades; expenses related to enterprise risk management and compliance and consulting, legal and other professional services fees, including as a result of our growth, litigation and internal and regulatory reviews; the impact of changes in foreign currency exchange rates on costs; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; and impairments of goodwill or other assets;
•changes in the substantial and increasing worldwide competition in the payments industry, including competitive pressure and competitor settlements that may materially impact the prices charged to merchants that accept American Express cards; merchant acceptance, surcharging, steering and other differential acceptance practices; the desirability of competitor premium card products and competition for partnerships and premium experiences, services and benefits; competition for new and existing cobrand relationships; the effects of the emergence of agentic commerce on the payments landscape and customer payment experiences; competition from new and non-traditional competitors, such as financial technology companies, and with respect to new products, services and technologies, such as the emergence or increase in popularity of digital payment platforms and currencies and other alternative payment mechanisms; competitor acquisitions and transactions; and the success of marketing, promotion, rewards programs, offers and travel-, lifestyle- and business-related benefits (e.g., lounges, dining, entertainment and business tools);
•our ability to sustain our momentum and leadership in the premium consumer space, including with Millennial and Gen-Z consumers, which will be impacted in part by competition, levels of consumer demand for premium card products, brand perceptions (including perceptions related to merchant coverage) and reputation, and our ability to successfully refresh our products and develop and market new benefits, services, experiences and other value propositions, as well as new AI and digital capabilities, that appeal to Card Members and new customers, grow spending with new and younger age cohort Card Members, offer attractive services and rewards programs and build greater customer loyalty, which will depend in part on identifying and funding investment opportunities, addressing changing customer behaviors, new product innovation and development, Card Member acquisition efforts and enrollment processes, including through digital channels, continuing to realize benefits from strategic partnerships, successfully implementing our dining strategy and evolving our infrastructure to support new products, services and benefits;
•our ability to build on our leadership in commercial payments, which will depend in part on competition, including from financial technology companies and as a result of competitor acquisitions and transactions; the willingness and ability of companies to use credit and charge cards for procurement and other business expenditures as well as use our other products and services for financing needs; the acceptance of, and economics related to, B2B payment platforms; our ability to successfully refresh our products and offer attractive value propositions and new products to current and potential customers, including through our new Graphite Business Cash Unlimited Card and upcoming Corporate Cash Back Card, as well as new AI benefits and capabilities; our ability to enhance and expand our payment, lending, cash flow and expense management solutions, including the release of new expense management software in 2026, increase customer engagement, enhance the corporate card onboarding experience and build out a multi-product digital ecosystem to integrate our broad product set, which is dependent on our continued investment in capabilities, features, functionalities, platforms and technologies and the successful introduction of capabilities related to, our Center acquisition; and the success of our initiatives to support businesses, such as Small Business Saturday and other Shop Small campaigns;
•our ability to successfully invest in, benefit from and expand the use of technological developments, generative AI, digital payments, servicing, travel, dining & expense management solutions and other technological capabilities, which will depend in part on our success in advancing our agentic commerce initiatives, including embedding our payment capabilities in emerging AI ecosystems, such as through the Amex Agentic Commerce Experiences™ developer kit and Amex Agent Purchase Protection™, making Membership assets discoverable and actionable on AI platforms and building proprietary AI-powered experiences across our platforms; embedding AI into our business and increasing automation, including to streamline and improve internal processes and decision making, enhance our products, develop new capabilities and address servicing and other business and customer needs; developing new features in our applications and platforms and enhancing our digital channels; supporting the use of our products as a means of payment through online, mobile, agentic and other digital channels; building partnerships and executing programs with other companies; and effectively utilizing data and data & analytics platforms, including successfully migrating to new platforms, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, partner engagement, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully implement our dining strategy and grow our dining platform, which will depend in part on our ability to deliver value to diners, restaurants and other bookable venues; expand and innovate the tools and capabilities offered through the platform, including successfully integrating Tock into the Resy dining platform and developing AI-powered experiences in the Resy app; enable the search and booking of Resy venues through AI platforms; and successfully implement partnerships and compete with other dining platforms and means of booking reservations;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of AI technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and digital capabilities; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation and supply chain issues; increased technology costs, including investments in technology innovations and system upgrades; expenses related to enterprise risk management and compliance and consulting, legal and other professional services fees, including as a result of our growth, litigation and internal and regulatory reviews; the impact of changes in foreign currency exchange rates on costs; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; and impairments of goodwill or other assets;
•changes in the substantial and increasing worldwide competition in the payments industry, including competitive pressure and competitor settlements that may materially impact the prices charged to merchants that accept American Express cards; merchant acceptance, surcharging, steering and other differential acceptance practices; the desirability of competitor premium card products and competition for partnerships and premium experiences, services and benefits; competition for new and existing cobrand relationships; competition from new and non-traditional competitors, such as financial technology companies, and with respect to new products, services and technologies, such as the emergence or increase in popularity of agentic commerce, digital payment platforms and currencies and other alternative payment mechanisms; competitor acquisitions and transactions; and the success of marketing, promotion, rewards programs, offers and travel-, lifestyle- and business-related benefits (e.g., lounges, dining, entertainment and business tools);
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing, travel & dining solutions, generative AI and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment and agentic commerce; developing new features in our applications and platforms and enhancing our digital channels; effectively utilizing AI & ML and increasing automation, including to enhance our products, develop new capabilities and address servicing and other business and customer needs; supporting the use of our products as a means of payment through online, mobile, agentic and other digital channels; building partnerships and executing programs with other companies; and effectively utilizing data and data & analytics platforms, including successfully migrating to new platforms, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of artificial intelligence technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and digital capabilities; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation; supply chain issues and increased technology costs; expenses related to enterprise risk management and compliance and consulting, legal and other professional services fees, including as a result of our growth, litigation and internal and regulatory reviews; the impact of changes in foreign currency exchange rates on costs; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; and impairments of goodwill or other assets;
•changes in the substantial and increasing worldwide competition in the payments industry, including competitive pressure and competitor settlements and transactions that may materially impact the prices charged to merchants that accept American Express cards; merchant acceptance and surcharging, steering and suppression by merchants; the desirability of competitor premium card products and competition for partnerships and premium experiences, services and benefits; competition for new and existing cobrand relationships; competition from new and non-traditional competitors, such as financial technology companies, and with respect to new products, services and technologies, such as the emergence or increase in popularity of agentic commerce, digital payment platforms and currencies and other alternative payment mechanisms; and the success of marketing, promotion, rewards programs, offers and travel-, lifestyle- and business-related benefits (e.g., lounges, dining, entertainment and business tools);
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in our applications and platforms and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation, including to enhance our products and address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online, mobile and other digital channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of artificial intelligence technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and digital capabilities; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation; supply chain issues and increased technology costs; expenses related to enterprise risk management and compliance and consulting, legal and other professional services fees, including as a result of our growth, litigation and internal and regulatory reviews; the impact of changes in foreign currency exchange rates on costs; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; and impairments of goodwill or other assets;
•changes in the substantial and increasing worldwide competition in the payments industry, including competitive pressure and competitor settlements and mergers that may materially impact the prices charged to merchants that accept American Express cards; merchant acceptance and surcharging, steering and suppression by merchants; the desirability of competitor premium card products and competition for partnerships and premium experiences, services and benefits; competition for new and existing cobrand relationships; competition from new and non-traditional competitors, such as financial technology companies, and with respect to new products, services and technologies, such as the emergence or increase in popularity of agentic commerce, digital payment platforms and currencies and other alternative payment mechanisms; and the success of marketing, promotion, rewards programs, offers and travel and lifestyle-related benefits (e.g., lounges, dining and entertainment);
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in our applications and platforms and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation, including to enhance our products and address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online, mobile and other digital channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of artificial intelligence technologies; management’s ability to balance expense control and investments in the business and its decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and digital capabilities; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation; supply chain issues and increased technology costs; expenses related to control management and compliance and consulting, legal and other professional services fees, including as a result of litigation or internal and regulatory reviews; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; impairments of goodwill or other assets; and the impact of changes in foreign currency exchange rates on costs;
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex® app and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation, including to address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to control operating expenses, including relative to revenue growth, and the actual amount we spend on operating expenses in the future, which could be impacted by, among other things, salary and benefit expenses to attract and retain talent; our ability to realize operational efficiencies, including through increased scale and automation and continued adoption of artificial intelligence technologies; management’s decisions regarding spending in such areas as technology, business and product development, sales force, premium servicing and digital capabilities; our ability to innovate efficient channels of customer interactions and the willingness of Card Members to self-service and address issues through digital channels; restructuring activity; fraud costs; inflation; supply chain issues; expenses related to control management and compliance and consulting, legal and other professional services fees, including as a result of litigation or internal and regulatory reviews; regulatory assessments; the level of M&A activity and related expenses; information security or cybersecurity incidents; the payment of fines, penalties, disgorgement, restitution, non-income tax assessments and litigation-related settlements; the performance of Amex Ventures and other of our investments; impairments of goodwill or other assets; and the impact of changes in foreign currency exchange rates on costs;
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex® app and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation, including to address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation to address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully invest in, benefit from and expand the use of technological developments, digital payments, servicing and travel solutions and other technological capabilities, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, effectively utilizing data and data platforms, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation to address servicing and other business and customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, customer and colleague receptiveness and ability to adopt new technologies, new product innovation and development and the platforms and infrastructure to support new products, services, benefits and partner integrations;
•the company’s ability to successfully invest in and compete with respect to technological developments and digital payment and travel solutions, which will depend in part on the company’s success in evolving its products and processes for the digital environment, developing new features in the Amex app and enhancing its digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully invest in and compete with respect to technological developments and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to successfully invest in and compete with respect to technological developments and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and machine learning and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•the company’s ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on the company’s success in evolving its products and processes for the digital environment, developing new features in the Amex app and enhancing digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of the company’s products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of our products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•the company’s ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on the company’s success in evolving its products and processes for the digital environment, developing new features in the Amex app and enhancing digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of the company’s products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;
•our ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on our success in evolving our products and processes for the digital environment, developing new features in the Amex app and enhancing our digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the
•the company’s ability to stay on the leading edge of technology and digital payment and travel solutions, which will depend in part on the company’s success in evolving its products and processes for the digital environment, developing new features in the Amex app and enhancing digital channels, building partnerships and executing programs with other companies, effectively utilizing artificial intelligence and increasing automation to address servicing and other customer needs, and supporting the use of the company’s products as a means of payment through online and mobile channels, all of which will be impacted by investment levels, new product innovation and development and infrastructure to support new products, services, benefits and partner integrations;