workflow automation

How Brex secures AI agents by observing the network, not the code

"Agents" is a terrible name, and Brex's CEO says so.

4 min readVentureBeat
How Brex secures AI agents by observing the network, not the code

The most provocative idea Brex CEO Pedro Franceschi put forward at VB Transform 2026 isn't about the technology at all. It's the demand that we abandon the word "agent" entirely. His reasoning is sharp: the term has become a Silicon Valley abstraction that obscures more than it reveals. When he reframes the goal as building a "virtual employee," the security conversation changes overnight. You don't hire a human and then let them run wild on the corporate network without oversight. You watch what they do, you set boundaries, and you escalate when they hit a wall. That framing makes the problem tangible, and it's the same reason we've been paying close attention to how Exploring Paragraph Structure: How LLMs Navigate Token Space reveals that even the internal mechanics of these models are less about magic and more about learned structure. If we're going to trust these systems with real work, we need that same level of clarity applied to their behavior.

What Brex built in response to its own security team's refusal is a pragmatic admission that you cannot police the code. The team's instinct to reject OpenClaw's code execution capabilities was correct, and their solution wasn't to lock the model down but to assume it was already compromised. Shifting the security perimeter to the network layer, monitoring outbound traffic with an LLM-as-a-judge, is a fundamentally different philosophy. It accepts that the frontier of risk isn't inside the black box; it's in the actions the box takes. The static rule bypass for routine requests, like checking a LinkedIn profile, and the LLM review for high-stakes actions, like sending an email, is a sensible bifurcation that keeps latency down to a manageable 2% of requests. This is the kind of thinking that separates companies actually deploying this tech from those still running pilots. It also echoes the hard lessons in AI Agents Shared User Images, Highlighting Data Security Concerns, where the risk wasn't a malicious prompt but an ordinary action that had unintended public consequences. The network doesn't care about intent, only about the destination.

But the most instructive part of Franceschi's story isn't the clever proxy. It's his honest assessment that there was a 70% chance Brex would throw CrabTrap away in six months. He built it anyway because the learning curve was the real asset. That is a hard truth for enterprises waiting for the perfect commercial solution. The vendors will catch up, and the tool will become commoditized, but the institutional knowledge of how to safely onboard a virtual employee, how to review its policy violations, and how to run a human-in-the-loop escalation flow, cannot be bought. It's earned through the mess of doing it. For our readers, the takeaway is direct: if you're waiting for the security suite to arrive before you let an AI touch a production workflow, you're not being cautious, you're being left behind. The question to ask isn't "is this agent safe?" but "what is my escalation path when it does something I didn't predict?" Because it will, and the only real defense is a network that's watching the door, not the mind behind it. The specific detail to watch is whether the 2% latency figure holds up as these systems scale to thousands of concurrent requests, because that's where the static rules will start to chafe and the LLM judge will become the bottleneck.

From VentureBeat

Brex CEO Pedro Franceschi offered a blueprint for one of the pressing challenges facing the enterprise today at VB Transform 2026: securely deploying AI agents, like the open-source OpenClaw, into production environments.

Unlocking this enterprise value requires a mindset shift. The industry needs to move past vague terminology and focus on concrete enterprise roles.

Read the original at VentureBeat