Summary
- Belfius will install a dedicated Nvidia-powered security-testing server within its own data centre.
- More than 200 autonomous agents will search continuously for exploitable weaknesses in the bank’s applications.
- The on-premises, model-agnostic design reflects the control, auditability, and supplier-risk demands facing regulated banks.
Belfius is installing a dedicated artificial intelligence system inside its own data centre to test applications continuously for security vulnerabilities, bringing autonomous penetration testing within the physical and regulatory boundary of the Belgian bank.
Developed with Ghent cybersecurity company Aikido Security, the system will use Nvidia graphics processors and more than 200 AI agents described by the partners as ethical hackers. Rather than waiting for periodic manual assessments, the agents will search for weaknesses continuously and challenge the bank’s systems as software changes.
Belfius and Aikido intend to refine the system together, adapting it to the controls, operational conditions, and regulatory obligations of a systemically important financial institution. The bank will provide the production complexity and institutional requirements, while Aikido supplies the autonomous testing technology.
Automated security scanning is already established, although the project moves further towards agents that can investigate whether a weakness is genuinely exploitable, combine tools, and pursue testing paths without each step being directed by a human operator. Housing that capability on the bank’s premises gives Belfius tighter control over application data, credentials, model access, and the evidence produced during testing.
Control matters as much as speed
The machine is being designed to work with multiple large language models rather than tying the service to a single supplier. Belfius will be able to use models provided by its technology partners and select different systems for particular tasks, reducing the operational dependence that would come with building the service around one external platform.
That architecture reflects a wider problem facing regulated organisations as they introduce agentic software. A security system may need extensive access to source code, development environments, application interfaces, and internal documentation to test effectively, yet granting an autonomous tool that access creates another category of risk.
Testing agents must remain inside tightly defined boundaries, while their actions, tool use, and findings need to be recorded. Aikido has previously identified scope enforcement and isolation between agents and their tools as leading concerns among security and engineering executives considering autonomous penetration testing.
“Attackers move at machine speed. Companies cannot keep responding at human speed,” Roeland Delrue, co-founder of Aikido, said in the partnership announcement.
The contrast between automated attackers and human defenders is common across the cyber industry, although banks already use automated code analysis, vulnerability scanning, attack simulation, and monitoring. Human specialists remain responsible for how those systems are configured, which risks deserve priority, and whether remediation could disrupt critical services.
The Belfius deployment will therefore be judged by whether autonomous testing improves the quality and speed of those decisions. A large quantity of findings would offer little benefit if teams cannot distinguish exploitable weaknesses from low-risk anomalies, or if the system creates another backlog for developers and security engineers.
Banking rules shape the deployment
European financial institutions have operated under the Digital Operational Resilience Act since January 2025. DORA harmonises requirements covering ICT risk management, incident handling, resilience testing, third-party suppliers, and oversight across banks, insurers, investment businesses, and other financial entities.
Although the regulation does not prescribe autonomous penetration-testing systems, it raises the standard of evidence expected from institutions responsible for critical digital services. Belfius must be able to explain how its testing operates, how access is controlled, how findings are handled, and how the use of external models or technology providers fits within its wider ICT risk framework.
Keeping the hardware on premises may simplify some data-control questions, but physical location does not remove supplier risk. The machine will still depend on software components, AI models, updates, and governance decisions, while a model-agnostic approach introduces the task of evaluating how different models behave when given security-sensitive instructions.
Continuous testing also changes the relationship between security and software delivery. Traditional penetration tests are commonly scheduled around releases or conducted at set intervals, whereas an always-on system can test code as applications evolve, shortening the period between introducing a weakness and discovering it.
That approach will require disciplined integration with development and change-management processes. An agent that finds a flaw must produce evidence engineers can reproduce, assign an appropriate severity, avoid unsafe testing against live services, and support remediation without changing systems beyond its authority.
Europe’s vulnerability-management infrastructure is itself adapting to faster discovery. ENISA has warned that frontier AI models are compressing the period between finding and exploiting weaknesses, while the Cyber Resilience Act will introduce mandatory reporting of actively exploited vulnerabilities for manufacturers from September 2026.
Belfius and Aikido ultimately want to develop the system for other financial institutions and highly regulated industries, although the first deployment remains a joint development project rather than a proven sector standard. Its value will depend on measurable outcomes inside the bank: vulnerabilities found earlier, false positives kept under control, remediation completed faster, and testing conducted without creating new operational exposure.




