AI News Feed
Market watch
Companies

IBM and CoreWeave co-design controls for agent workloads

IBM Research and CoreWeave are co-designing identity and workload controls for AI agent workloads, IBM's Brian Belgodere said.

Belgodere said IBM Research’s Granite family of models required substantial computing infrastructure, and the cooling and power demands of a subsequent hardware generation helped drive IBM’s decision to work with CoreWeave Inc. He said the decision led IBM to build out its own infrastructure, including a large H100 cluster. ‘We went out and built a large H100 cluster, and we did it ourselves: got the space, soup to nuts. It was a huge task,’ he said.

The relationship has expanded into joint engineering around identity management and workload controls, according to Belgodere. IBM supplied requirements for extending its internal identity systems into CoreWeave, then refined the implementation through several iterations. Belgodere said CoreWeave often approaches IBM with proposed designs for feedback, and IBM reviews them.

Much of IBM Research’s cluster is single-tenant, with its own storage deployed inside CoreWeave and additional capacity available within cost and security parameters, Belgodere said. IBM’s collaboration with CoreWeave also includes CoreWeave Sandboxes, which support isolated execution on dedicated infrastructure or through a managed serverless runtime. Those options let researchers choose where agent code runs and what resources it can access.

Belgodere said reinforcement learning adds a task-execution stage to model development. ‘The RL process is [that] you are in the middle of training a model,’ he said. ‘At some point, you take that checkpoint and then actually load it into inference, ask it to do something and you’re measuring. That’s your testing phase.’ He described agent workload isolation as a design requirement for systems that now run code and test agents, not only train models.

Belgodere warned that architecture decisions carry high costs. ‘There are a lot of misses, and people tend to underestimate the cost to change some of these decisions,’ he said. ‘If you decide to make a poor architecture decision early on, the cost is either going to be [that] you accidentally bought way too much networking infrastructure, or you have to go buy and refit everything.’

IBM measures the performance impact of security controls against benchmark results, using those findings to discuss tradeoffs with security teams, according to Belgodere. Workload isolation sits alongside enterprise identity integration as part of that broader security architecture.

‘This is a supply chain problem, top to bottom,’ he said. ‘It’s not just the hardware, it’s the firmware, kernel levels, code, your data provenance. Then you get into the whole world of agents, your images. It is an absolute provenance problem.’

TheCUBE is a paid media partner for the Fully Connected event. Neither CoreWeave, the sponsor of theCUBE’s coverage, nor other sponsors have editorial control over the content on theCUBE or SiliconANGLE.

Editor's Summary

IBM Research and CoreWeave are co-designing identity and workload controls for AI agent workloads, with IBM providing requirements for extending internal identity systems into CoreWeave and using CoreWeave Sandboxes for isolated execution. Belgodere said the work is part of a broader security and provenance problem spanning hardware, firmware, kernels, code, data and agent images, while IBM weighs security controls against benchmark performance.