In brief

Marco Argenti says companies should test models, protect the place where they run, limit agent permissions, and control data access. This is a proposed approach, not a public standard.

New to this? Read it in simple words
  • Goldman Sachs CIO Marco Argenti says companies should not ban open-weight models before testing them. He suggested four safety layers in an interview with Axios.
  • The first layer tests and approves the model. The others protect where it runs, limit agent permissions and control data access.
  • His main point is that companies can consider more models without accepting every risk.
  • This is a suggestion, not a public banking rule. Banks and regulators will still need evidence that the controls are enough.
Words to know
CIO
Chief information officer, the leader in charge of a company’s computer systems.
Open weights
The trained model files are public, so anyone can download and run the model.
Regulator
A government body that makes and enforces rules for an industry.

Four layers between a model and the bank

Argenti gave his proposal in an interview with Axios. The first layer is model testing and approval. The second is a protected place to run the model. The third gives AI agents only the permissions they need. The fourth controls access to company data.

The approach uses two computer-security ideas. Zero trust means a company should not trust a model only because of its name or source. Defense in depth means that several different controls should protect the system at the same time.

Goldman already keeps its AI tools away from direct access to the original data systems, Argenti said. Requests go through the bank's data platform, which checks access rights. This can limit what a model sees even if another safety layer fails.

Sources12

SAFETY STACK 06
Four separate controls stand between an open model and important bank systems.

The proposal covers model testing, a secure running area, limited agent permissions, and controlled data access.

Why open models create choice and work

An open-weight model lets a company inspect and change the trained model files. It may run the model on computers that the company controls. This can support privacy, custom work, and a choice between several providers.

Open weights do not make a model safe. A model may contain weak code, hidden behavior, or training problems. It may also follow a harmful instruction from a document. The company must test the model and control every tool it can use.

Argenti says Goldman has tested several US open models and uses some for business work. He says the bank's current open-model use is mostly or only from the United States. The interview does not list the models or the business tasks.

Sources1

A useful proposal still needs clear tests

The four layers are a strong starting map, but each layer needs a clear pass or fail test. Teams must know which model behavior blocks a release. They also need records of permissions, data requests, human approvals, and unusual events.

Separate controls should fail in different ways. If one mistake can turn off every layer, the system does not have true defense in depth. Regular exercises can show whether staff can find a problem, stop the agent, and recover safely.

Argenti's main point is about choice: a company can consider more models without accepting every risk. That is a useful goal. Banks and regulators will still need detailed evidence before they agree that the controls are enough.

Sources12

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Research · September 8, 2026Goldman CIO: Don't rule out open models Axios
  2. 2
    Primary source · August 2020Zero Trust Architecture U.S. National Institute of Standards and Technology
How we checked this story

Axios is the direct source for Argenti's proposal and Goldman's current practice. We used the NIST standard only to explain zero trust. We do not describe the proposal as a Goldman policy, a government rule, or proof that every open model is safe.