“We govern what we build”: cybersecurity in the age of agentic AI

How to secure the rise of autonomous agents? CIB CISO discusses cybersecurity in the age of agentic AI through governance and architecture. Read more.

4 min
  • Governed innovation: Speed and control are not a trade-off; rigorous, built-in governance frameworks allow for rapid AI deployment without compromising institutional safety.
  • A dual cybersecurity mission: Securing the future requires a two-way approach: leveraging AI to enhance threat detection (AI for Cyber) while implementing strict guardrails to protect the AI itself (Cyber for AI).
  • Strategic autonomy: By utilizing a multi-model approach and on-premises infrastructure, the Bank avoids vendor lock-in and maintains the flexibility to adapt to a changing technological landscape.
  • Resilience through oversight: Human expertise remains at the core of the transformation, ensuring that every autonomous action is traceable, accountable, and subject to human integrity.

The rapid rise of agentic AI is fundamentally redesigning the risk landscape and the very nature of opportunity in financial services. At Vivatech 2026, Bruno Dehem, Chief Information Security Officer (CISO) at BNP Paribas Corporate and Institutional Banking (CIB), discussed cybersecurity in the age of agentic AI and the essential cyber guardrails and technical architecture required to maintain a secure, agent-led banking environment.

The conversation addressed a central challenge for global organisations: the perceived trade-off between the speed of innovation and the necessity of control. For Bruno Dehem, this is a false dilemma. Speed is a vital competitive lever, but it can only be safely harnessed when it is underpinned by rigorous, built-in governance. Read his key insights below.

Building foundations through governance and talent

Rigorous governance provides the framework necessary to accelerate AI deployment while maintaining institutional safety. Through the “Trust for AI” programme, BNP Paribas CIB has implemented a system of traceability and risk-review checkpoints. This approach adapts existing Information and Communication Technology (ICT) risk management protocols for the specific requirements of AI agents, ensuring each agent is assigned a defined identity, a specific purpose, and strict access controls.

“Our goal is to ensure that every agent operates within a structured environment,” explains Bruno Dehem. “By defining an identity, a purpose, and a clear audit trail for every deployment, we can move forward with confidence. Ultimately, we govern what we build.”

This structured approach is already supporting tangible use cases. The internal large language model assistant, “LLM@CIB”, supports 65,000 employees, while the “Dev Assistant” tool helps developers optimize code and automate security remediation. In both instances, human oversight remains central to the process.

Bruno Dehem

Our people are the architects of this transformation. The technology facilitates the task, but our people ensure the integrity of the outcome.

Bruno Dehem
Chief Information Security Officer (CISO), BNP Paribas CIB

Scaling AI capability is a strategic priority for the organisation. To lead this transition, Olivier Osty, CEO of BNP Paribas CIB, appointed Charles Holive as CIB Chief AI Officer in early 2026. Charles leads a cross-functional strategy that integrates data, governance, finance, and human capital to ensure AI is embedded responsibly across the Bank.

The dual responsibility of AI and cybersecurity

In the age of agents, cybersecurity has evolved into a dual mission: leveraging AI to protect the Bank and using cybersecurity to protect the AI infrastructure.

“We are using AI for Cyber to enhance our detection,” Bruno Dehem explains. “Machine learning models can now identify data-leakage patterns more efficiently than manual assessments, while generative AI helps us remediate security vulnerabilities in code instantly.”

Simultaneously, the Bank acts as a guardian for AI deployment through “Cyber for AI.” By restricting uncontrolled access to external tools and integrating security checkpoints into every AI rollout, the Bank prevents the inadvertent exposure of sensitive data. For autonomous agents, this means moving beyond traditional software controls to a multi-layered system: registering agents with specific business objectives, applying role-based permissions, and using real-time observability dashboards to enable rapid rollback if an anomaly is detected.

Preserving strategic autonomy and resilience

Managing dependencies on models and cloud providers is a strategic priority as AI scales. BNP Paribas CIB employs a “best of both worlds” architecture to retain operational freedom. Sensitive workloads are hosted on on-premises cloud infrastructure and internal GPU farms to guarantee data residency.

This internal capability is complemented by strategic partnerships. A three-year extension of the partnership with Mistral AI, alongside collaborations with major cloud vendors, provides a multi-model portfolio. This approach allows the Bank to switch or combine models based on performance, cost, and regulatory requirements.

By prioritising modular, interoperable building blocks – such as standardised identity and policy engines – BNP Paribas ensures continuous access to the most advanced technologies. This architecture enables the Bank to seamlessly integrate external innovation while maintaining the agility to evolve its service landscape without disrupting mission-critical processes

A foundation for long-term resilience

By prioritizing strategic autonomy and rigorous governance, BNP Paribas CIB is building a resilient foundation for the future of banking. For our clients, this means that as we explore the potential of agentic AI, our focus remains steadfast on security and stability. Our commitment to a multi-partner, vendor-agnostic approach ensures that we can adapt to an evolving technological and regulatory landscape while maintaining the continuous protection and accountability that our clients expect.

In the context of AI and automation, “human-in-the-loop” refers to a model where AI systems perform tasks, but humans intervene to review, validate, or approve the results. This ensures that critical decisions – such as credit approvals or security protocols – benefit from AI efficiency while maintaining human accountability and oversight.

Driving innovation at BNP Paribas

Driving innovation at BNP Paribas CIB (38 characters) Content: BNP Paribas CIB is committed to helping clients navigate the complexities of the digital transition. By integrating cutting-edge technologies like agentic AI with rigorous governance and sustainable data strategies, we aim to turn technological change into compelling opportunities for our clients.