Ant Group stresses trusted AI agents as finance and engineering tools launch
On Sept. 10, Ant Group stressed trusted AI-agent infrastructure at the Inclusion·Bund Summit, while Ant Digital, cfo.ai and CoreWeave launched agent products for finance and engineering.
Chen Liang, chief technology officer of Ant Group’s security business, said at a media group interview that security is not a course to be added after AI scales, but a foundation that must be laid before it can scale. “Capability decides what AI can do, and trust decides what society dares to hand to AI,” Chen said, according to Leiphone.com. With agents beginning to call services, operate devices and execute transactions on behalf of users, he said, the industry must answer not only whether AI is smart, but whether it understands users’ real intent, acts within authorized boundaries, remains controllable and leaves a traceable result. Ant’s security capabilities built during the mobile-internet era remain largely applicable, Chen said, but the difference is that an agent layer now sits between users and businesses. The core variables are the user’s absence and broader delegation boundaries. While an abnormal amount can be blocked directly, a mismatch such as a user wanting an Americano but receiving a latte requires the system to check the original intent, the agent’s understanding and the final transaction. Ant therefore treats agent security as an end-to-end chain: from terminals such as phones, glasses and earphones, to the agent’s identity, permissions, behavior and runtime environment, and then to transaction risk control, post-event auditing and accountability.
Wan Xiaofei, head of terminal security at Ant Group, said terminals are changing in two ways at once: hardware is expanding from phones to glasses, earphones and other pervasive devices, while software entrances are shifting from apps to agents. The relatively closed boundary of “app plus cloud service” has been broken, requiring security to enter the design stage of terminal systems, chips and supply chains. Ant upgraded its GPASS brand to Lingying and its GOS to Lingying AOS, moving from individual terminal-security capabilities toward underlying infrastructure for intelligent terminals. Lingying pushes trusted execution, data protection and runtime security into devices and operating systems, working with device makers and supply-chain partners to build security into phones, AI glasses, earphones and other devices. Wan also introduced ASL, or the Agent Secure Trusted Interconnection Protocol. ASL does not replace interaction protocols such as A2A; it adds a trusted connection layer covering identity trust, intent trust and data trust, defining how two agents verify each other, transmit authorization and constrain operations when they conduct business. According to Leiphone.com, ASL began about a year and a half ago as a standards initiative, then became a protocol and product with an open, compatible ecosystem strategy. It has been deployed in cross-platform agent scenarios such as 1688 e-commerce procurement and in Alipay’s internal business, connecting Alipay agents with device makers’ system assistants.
Zhu Chuanqun, head of agent security at Ant Group, said that once agents can plan autonomously, call tools and keep executing, risks extend from model outputs into the real digital world and may later affect the physical world. Agents need independent identities and permission systems, while the tools, skills, MCP services and memory they use could be poisoned, causing actions to deviate from the user’s original intent. Governance therefore needs to cover identity, permissions, supply chain, runtime environment, execution behavior and audit accountability. Controls can be graded by the sensitivity of data an agent can access and the harm of actions it can perform: low-risk, low-sensitivity operations can retain more autonomy, while high-sensitivity data or high-risk actions require human confirmation or should be prohibited. Two group standards launched during the summit correspond to these areas: the Technical Framework for Agent Identity Authentication and Authorization, which emphasizes independent agent identities and regulates identity issuance, terminal binding and authorization management, and the Technical Requirements for Agent Runtime Security, which focuses on sandbox isolation, runtime guardrails and dynamic control of intent and action execution. Chen Luobin, head of risk-control security at Ant Group, said risk control needs two new capabilities for agents: more native identity verification on pervasive terminals such as glasses, earphones and watches, and continuous verification of user intent and authorization before and after transactions. Systems must judge not only whether a single transaction is abnormal, but also identify the agent’s environment, reconstruct multi-level delegation chains and compare the user’s original intent with final business behavior, extending protection to pre-event constraints, in-event judgment and post-event tracing.
At a forum during the same summit, Yu Bin, president of AI business at Ant Digital Technologies, launched Agentar Finance Edition, which provides ready-to-use financial agent expert teams, industry skills, MCP, agent evaluation tools and governance capabilities. The platform is intended to give financial institutions a “super factory” covering agent development, deployment, collaboration, evaluation and management, according to Leiphone.com. The first edition includes 10 financial agent expert teams covering core scenarios such as robo-advisory, wealth management and customer operations. Each digital expert corresponds to a full job role, can understand business goals, break down tasks and coordinate multiple specialized agents to produce a complete business result, the company said. In retail finance, for example, a “digital customer manager” can coordinate agents for customer-group insight, product matching and strategy generation, generating personalized plans and supporting follow-up service. Work that previously required cross-role, multi-step coordination can be compressed into the same day, Ant Digital said. Trial results showed a 10% increase in total assets under management for a pilot customer group, a 15% rise in customer activity and more than a fivefold increase in the number of customers served. Agentar Finance Edition includes a financial large model, financial-grade trusted Harness engineering and more than 2,000 financial evaluation tools covering professionalism, compliance, accuracy and execution quality, along with full-chain security checks on data input, task execution and output. Ant Digital said it has built more than 300 professional agents with partners in financial scenarios and serves all state-owned and joint-stock banks, more than 60% of local commercial banks and hundreds of financial institutions. IDC’s July report on China’s financial large-model, agent application and service market put the 2025 market at more than 2.4 billion yuan, with Ant Digital holding a 13.3% share, the largest.
Runway Financial Inc. said it has pivoted away from accounting software and rebranded as cfo.ai, launching an AI agent called Ari that is designed to act as a chief financial officer for startup founders and independent business owners, SiliconANGLE reported. Founders can integrate Ari with financial and customer-relationship tools such as NetSuite, QuickBooks, Stripe, Salesforce or Snowflake. Ari builds and maintains a model of the business’s financial health, communicates through Slack and can perform tasks such as forecasting cash flow or analyzing the impact of a hiring plan. It monitors recurring revenue, cash flow, churn, profit margins and EBITDA, and can proactively alert founders to a sudden jump in churn or lower-than-expected cash flow, investigate why and suggest remedies. Founder and CEO Siqi Chen said large language models can already handle simpler finance work including accounting and reporting, but struggle with forecasting because spreadsheets were designed around how humans see and work. Ari uses Reambase, a proprietary multidimensional calculation engine that assigns values to cells based on business addresses built from named variables and dimensions such as Region, Month or Customer, so semantic meaning travels with the value. Chen said a chatbot waits for a question, but a CFO keeps track of the business, notices changes and brings them to the founder; Ari works the same way, while giving founders direct access to the model.
CoreWeave Inc. launched a Physical AI Field Engineering service to help enterprise engineering teams implement AI directly into their workflows, SiliconANGLE reported. The service is intended to bridge industrial domain expertise and applied machine learning. CoreWeave has recruited engineers with expertise in automotive, aerospace and mechanical engineering to work with customers’ own engineering teams, train models on customer data and integrate them with workflows and applications. Each engagement begins with a workshop to evaluate engineering workflows, identify the best AI use cases and establish a quantified return on investment. Models are then designed and built using existing and real-time data to predict physical outcomes, a process CoreWeave says can cut testing times by 17% to 35%. The company then helps set up an optimal compute environment, avoiding over- or under-provisioning, before moving to agentic learning in which AI insights are transformed into physical actions. The final step integrates AI into applications, dashboards and optimization tools. The service is underpinned by CoreWeave’s cloud infrastructure, bare-metal servers and integrated tools including Weights & Biases’ Weave and experiment-tracking models, marimo and ARIA. Richard Ahlfeld, senior vice president of physical AI, said engineers adopt new tools after they have held up in their own hands and on their own systems, which is why CoreWeave sends engineers who speak the same language as customer teams and builds on customer data. CoreWeave said it has had more than 100 engagements with early adopters in automotive, aerospace and robotics. Nissan used 90 years of previously untapped archived test data to create predictive models that optimized chassis bolt-joint evaluations and reduced physical testing times by 17%. At an unnamed automaker, CoreWeave engineers completed a key engine calibration step that normally took three months in 24 hours. The service stems from CoreWeave’s acquisition of Monolith AI Ltd. last September.