
What happened
IBM Research's Brian Belgodere said the two companies co-engineered identity management and workload controls, and that CoreWeave Sandboxes run isolated agent code on dedicated or managed serverless infrastructure.
Why it matters
Agent workloads need isolation from tools, storage and other services, so this work suggests the compute layer, not just the model, is becoming a security boundary.
What to watch
Belgodere warned that poor early architecture decisions are costly to reverse, so the test is whether IBM's benchmarked security tradeoffs hold as reinforcement learning adds task execution.
WHO IT HITSEnterprise infrastructure and platform teams running AI models on external GPU clouds will need to decide where agent code executes and what resources it can reach, per Belgodere's description of IBM's setup.
Summaries like this, in your inbox every morning.
IBM Research's infrastructure needs changed as its model development practices evolved. Reinforcement learning added a task-execution stage: a checkpoint is loaded into inference, the model is asked to do something, and the result is measured. That stage changes what the underlying systems must accommodate, Belgodere said. Earlier, IBM Research built a large H100 cluster itself, acquiring the space and assembling it end to end — a task Belgodere described as huge.
The CoreWeave relationship grew out of that period. Much of the IBM Research cluster is single-tenant, with its own storage inside CoreWeave and additional capacity available within cost and security parameters. The joint engineering around identity management began with IBM supplying requirements for extending its internal identity systems into CoreWeave, then refining the implementation over several iterations. Belgodere framed the broader problem as a supply chain and provenance issue spanning hardware, firmware, kernel levels, code, data provenance, and agent images.
Where this lands may hinge on how well the security-performance tradeoffs Belgodere described hold up. IBM measures the performance impact of security controls against benchmark results, then discusses the tradeoffs with security teams. Belgodere also cautioned that early architecture decisions are expensive to undo — either through overbuying networking infrastructure or having to refit everything — so for teams standing up agent workloads now, the cost of getting the isolation and identity layers right the first time appears to be the practical question.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
CrowdStrike and CoreWeave are partnering to combine CrowdStrike's security data and adversary expertise with C…
NetApp's Sandeep Singh said its hybrid cloud tools with autonomous controls, delivered through NetApp Console…
Volantis raised US$88 million in Series A funding to develop an AI inference architecture that uses photonic i…

Hitachi and Fanuc announced a strategic Physical AI partnership on September 30, 2026, with internal testing s…

Microsoft and LG Electronics unveiled a Speech-to-Speech AI agent at the Microsoft Industry Summit in Seoul, e…

Suno, the AI music generator, launched a feature called Speech that turns typed text into spoken words with ma…
