Skip to content
  • X
  • LinkedIn
Subscribe
Techopia
  • Home
  • News
  • Insights
  • AI
  • Enterprise
  • Growth
  • Impact
  • Security
AI, News, Security

Belfius brings autonomous security testing in-house

Belfius is placing AI-led security testing inside its own data centre.

August 6, 2026
4 minutes

Read Time

Belfius brings autonomous security testing in-house
Summary
  • Belfius will install a dedicated Nvidia-powered security-testing server within its own data centre.
  • More than 200 autonomous agents will search continuously for exploitable weaknesses in the bank’s applications.
  • The on-premises, model-agnostic design reflects the control, auditability, and supplier-risk demands facing regulated banks.

Belfius is installing a dedicated artificial intelligence system inside its own data centre to test applications continuously for security vulnerabilities, bringing autonomous penetration testing within the physical and regulatory boundary of the Belgian bank.

Developed with Ghent cybersecurity company Aikido Security, the system will use Nvidia graphics processors and more than 200 AI agents described by the partners as ethical hackers. Rather than waiting for periodic manual assessments, the agents will search for weaknesses continuously and challenge the bank’s systems as software changes.

Belfius and Aikido intend to refine the system together, adapting it to the controls, operational conditions, and regulatory obligations of a systemically important financial institution. The bank will provide the production complexity and institutional requirements, while Aikido supplies the autonomous testing technology.

Automated security scanning is already established, although the project moves further towards agents that can investigate whether a weakness is genuinely exploitable, combine tools, and pursue testing paths without each step being directed by a human operator. Housing that capability on the bank’s premises gives Belfius tighter control over application data, credentials, model access, and the evidence produced during testing.

Control matters as much as speed

The machine is being designed to work with multiple large language models rather than tying the service to a single supplier. Belfius will be able to use models provided by its technology partners and select different systems for particular tasks, reducing the operational dependence that would come with building the service around one external platform.

That architecture reflects a wider problem facing regulated organisations as they introduce agentic software. A security system may need extensive access to source code, development environments, application interfaces, and internal documentation to test effectively, yet granting an autonomous tool that access creates another category of risk.

Testing agents must remain inside tightly defined boundaries, while their actions, tool use, and findings need to be recorded. Aikido has previously identified scope enforcement and isolation between agents and their tools as leading concerns among security and engineering executives considering autonomous penetration testing.

“Attackers move at machine speed. Companies cannot keep responding at human speed,” Roeland Delrue, co-founder of Aikido, said in the partnership announcement.

The contrast between automated attackers and human defenders is common across the cyber industry, although banks already use automated code analysis, vulnerability scanning, attack simulation, and monitoring. Human specialists remain responsible for how those systems are configured, which risks deserve priority, and whether remediation could disrupt critical services.

The Belfius deployment will therefore be judged by whether autonomous testing improves the quality and speed of those decisions. A large quantity of findings would offer little benefit if teams cannot distinguish exploitable weaknesses from low-risk anomalies, or if the system creates another backlog for developers and security engineers.

Banking rules shape the deployment

European financial institutions have operated under the Digital Operational Resilience Act since January 2025. DORA harmonises requirements covering ICT risk management, incident handling, resilience testing, third-party suppliers, and oversight across banks, insurers, investment businesses, and other financial entities.

Although the regulation does not prescribe autonomous penetration-testing systems, it raises the standard of evidence expected from institutions responsible for critical digital services. Belfius must be able to explain how its testing operates, how access is controlled, how findings are handled, and how the use of external models or technology providers fits within its wider ICT risk framework.

Keeping the hardware on premises may simplify some data-control questions, but physical location does not remove supplier risk. The machine will still depend on software components, AI models, updates, and governance decisions, while a model-agnostic approach introduces the task of evaluating how different models behave when given security-sensitive instructions.

Continuous testing also changes the relationship between security and software delivery. Traditional penetration tests are commonly scheduled around releases or conducted at set intervals, whereas an always-on system can test code as applications evolve, shortening the period between introducing a weakness and discovering it.

That approach will require disciplined integration with development and change-management processes. An agent that finds a flaw must produce evidence engineers can reproduce, assign an appropriate severity, avoid unsafe testing against live services, and support remediation without changing systems beyond its authority.

Europe’s vulnerability-management infrastructure is itself adapting to faster discovery. ENISA has warned that frontier AI models are compressing the period between finding and exploiting weaknesses, while the Cyber Resilience Act will introduce mandatory reporting of actively exploited vulnerabilities for manufacturers from September 2026.

Belfius and Aikido ultimately want to develop the system for other financial institutions and highly regulated industries, although the first deployment remains a joint development project rather than a proven sector standard. Its value will depend on measurable outcomes inside the bank: vulnerabilities found earlier, false positives kept under control, remediation completed faster, and testing conducted without creating new operational exposure.

Latest News

View All

  • Enterprise, News

    FiberCop repurposes exchanges for edge computing

    August 6, 2026
    FiberCop repurposes exchanges for edge computing
  • AI, Enterprise, News

    Metsä folds agentic AI into industrial IT

    August 6, 2026
    Metsä folds agentic AI into industrial IT
  • Enterprise, News, Policy

    Italy fast-tracks €25bn-plus data-centre pipeline

    August 6, 2026
    Italy fast-tracks €25bn-plus data-centre pipeline
  • AI, Enterprise, Insights

    Europe’s AI gains flow to established suppliers

    August 6, 2026
    Europe’s AI gains flow to established suppliers
  • AI, News, Security

    Belfius brings autonomous security testing in-house

    August 6, 2026
    Belfius brings autonomous security testing in-house

You May Have Missed

View All

  • FiberCop repurposes exchanges for edge computing
    Enterprise, News

    FiberCop repurposes exchanges for edge computing

    August 6, 2026
  • Metsä folds agentic AI into industrial IT
    AI, Enterprise, News

    Metsä folds agentic AI into industrial IT

    August 6, 2026
  • Italy fast-tracks €25bn-plus data-centre pipeline
    Enterprise, News, Policy

    Italy fast-tracks €25bn-plus data-centre pipeline

    August 6, 2026
  • Europe’s AI gains flow to established suppliers
    AI, Enterprise, Insights

    Europe’s AI gains flow to established suppliers

    August 6, 2026
  • Belfius brings autonomous security testing in-house
    AI, News, Security

    Belfius brings autonomous security testing in-house

    August 6, 2026

About Techopia

Techopia covers business-facing technology across the UK and Europe, with reporting on AI, cybersecurity, enterprise tech, digital transformation, public interest technology and the policy shaping them.

We focus on what technology means in practice — for businesses, institutions and the wider economy — without the fluff, hype or gadget filler.

Latest News

  • FiberCop repurposes exchanges for edge computing

    FiberCop repurposes exchanges for edge computing
  • Metsä folds agentic AI into industrial IT

    Metsä folds agentic AI into industrial IT
  • Italy fast-tracks €25bn-plus data-centre pipeline

    Italy fast-tracks €25bn-plus data-centre pipeline
  • Europe’s AI gains flow to established suppliers

    Europe’s AI gains flow to established suppliers
  • Belfius brings autonomous security testing in-house

    Belfius brings autonomous security testing in-house

Categories

AI Enterprise Growth Impact Insights News Policy Security

Topics

Search

Copyright © 2026. All rights reserved. | 2b Publishing