⚡ Breaking
The ominous sign that Michael Carrick’s days…  ·  Coleman not included in Republic of Ireland…  ·  Glasner predicts Delap to kick on at…  ·  Klopp names two Germany squads for Nations…  ·  Breaking down the 2026 Red Sox postseason…  ·  ‘Not joking’ – Sophie Cunningham’s ‘chops’ can…
Follow: Facebook Instagram Telegram WhatsApp
Advertisement
Home Business JPMorgan rolls out Claude changes: $2,000 spending limits…

JPMorgan rolls out Claude changes: $2,000 spending limits and extra security

· · 5 min read

JPMorgan has launched $2,000 monthly spending limits for some employees using Claude Code, internal messages seen by Business Insider show.

Advertisement

The cap, along with a new security effort for some Claude users, marks another evolution in how America’s biggest bank is refining its AI use amid ballooning costs and risks, and reshaping expectations for software engineers.

Last month, two Teams messages in a group for some engineers with access to Anthropic’s Claude asked about a new error code: “ExceededBudget” and “Budget=2000.0.” Responses from employees said that there is a monthly spending limit of $2,000 for certain engineers using Claude; two responses said that costs reset monthly.

Other replies said that users can request to increase their spending limit.

Advertisement

As Business Insider previously reported, JPMorgan, which has a nearly $20 billion annual tech budget, has carefully tracked its engineers’ AI usage for months, but this is the first indication of AI spending or token caps.

Token costs have become an increasingly pressing issue across Wall Street.

In June, Zachery Anderson, chief data and analytics officer in payments at JPMorgan, said at a tech event that some employees are “spending more on tokens than their salary,” but that there wasn’t a firmwide effort to scale back usage, Semafor reported.

During the bank’s second-quarter earnings call in July, Chief Financial Officer Jeremy Barnum said that while token expenses were at that point “trivial,” the bank is “forecasting some meaningful acceleration in that number for the second half of the year.” JPMorgan declined to comment on the specifics of token limits or its cost strategy.

A spokesperson said, “We’re approaching AI with discipline, tying costs to measurable business value and consider a range of metrics, including adoption, outcomes, productivity improvements, quality, speed, capacity creation, risk reduction, and business impact.” The $2,000 limit for some coincides with a broader change in how some engineers at the bank use Claude, and was mentioned in a Teams group about a new coding architecture, “Devspace.” Until recently, some developers piloted Claude directly on their desktops.

Devspace, however, is a longer-term plan that restricts Claude’s access to employees’ credentials and its ability to interact with internal systems, the spokesperson said.

This type of restriction is especially useful for running and controlling AI agents, which can make decisions and carry out tasks on their own.

Devspace is described as a “containerised,” sandbox-like server hosted in Amazon Web Services in a blog post on an internal site for technical questions seen by Business Insider.

A coding sandbox, like one on a playground, is an isolated place where software can run without affecting the rest of a computer system.

The spokesperson said that Devspace is relatively new, and the bank is continuing to roll out new features.

The blog post was published two months ago; it’s unclear when the firm began introducing the new coding environment and how many engineers have access to it.

Pat Opet, JPMorgan’s global chief information security officer, talked about sandbox architecture during a fireside chat at a cybersecurity conference in April, before the bank introduced the platform.

He said it can be risky to put powerful AI tools on the same desktops that house employees’ emails, sensitive files, and personal information.

Opet said the firm was “trying to build this in a way that isolates the platform that the AI uses,” and creates distinct employee and AI desktop environments. “Ideally, we would want these agents to run in an ecosystem where they have no entitlements.

They have an identity, but no entitlements,” he said. “When these tools need access to a resource, we want to be in control of understanding the context around that.” Under this type of architecture, JPMorgan can better understand and authorize agents’ activity, Opet said.

If an AI agent figured out how to break out of the environment, it wouldn’t have the credentials to access internal systems or “abuse the enterprise.” With the Devspace rollout, the bank has begun to realize Opet’s vision, though it’s unclear whether or when all engineers who use Claude will begin operating in the new digital environment.

As of now, only a sliver of the bank’s 65,000-person Global Technology division has access to Claude.

In August, an internal dashboard seen by Business Insider showed that around 8,000 people had Claude licenses, and the Teams group for questions about Devspace had about 1,900 members in early September.

It’s not clear whether all of the people in the Teams group have seats in Devspace.

Since Opet’s fireside chat, concern about rogue AI agents has grown, and public security threats have snowballed in severity and frequency.

Agents from Anthropic and OpenAI have escaped closed testing environments over the past few months, sometimes accessing the internet and hijacking websites.

Anthropic has since tightened security in its digital testing environments, and OpenAI has committed to changing how it discloses when its agents go rogue.

Some industry leaders have advocated slowing down technological advancement to save humanity.

Banks hold a tremendous amount of sensitive data, from customers’ identifying information to their credit card numbers.

Firms’ reputations are tied to their level of safety, real and perceived, making the question of cybersecurity in the AI era particularly pressing.

The safety focus isn’t new for JPMorgan — the firm was part of “Project Glasswing,” a cybersecurity group that tested Anthropic’s powerful Mythos model in a controlled environment in April.

When Opet spoke in April, he said that successfully building this architecture would engender enough “trust and confidence” to scale AI coding assistants across the firm, which has prided itself on being a first mover in AI on Wall Street. “This is kind of our best view at the moment on how enterprises can architect for those coding assistants,” he said.

Advertisement
Nairavoice
Contributor at NairaVoice.com.ng