Skip to main content
Brex AI agent monitoring network activity, not code, for control and security.

Editorial illustration for Brex's AI Caution: Watching Network, Not Code, to Control Agents

Brex Controls AI Agents by Monitoring Network Traffic

Brex's AI Caution: Watching Network, Not Code, to Control Agents

4 min read

Pedro Franceschi has a name for what most of the industry calls AI agents: a terrible name. Speaking at VB Transform 2026, the Brex CEO laid out how his company approached one of the thorniest problems in enterprise software right now, putting autonomous AI systems into production without losing control of what they touch. Brex's test case was OpenClaw, an open-source agent framework that became viable after coding models hit a new level of maturity in December, then shipped in January. The breakthrough let agents write and maintain their own code instead of running on fixed, pre-built tools, which is exactly what made Brex's security team nervous.

Franceschi's pitch wasn't really about automation. It was about building something closer to a virtual employee, an entity with an email address and a Slack handle that can sit in meetings and take on real work alongside humans. Getting there meant abandoning the usual code-level security assumptions, since an agent that rewrites its own tools can't be locked down the way static software can. Franceschi walked through what happened when he first floated the idea internally, and it didn't go over well.

Franceschi’s presentation detailed how Brex pointed OpenClaw at internal roles, realized traditional security models failed, and built a novel network-level security layer called CrabTrap.

Why this matters

Franceschi's move is a tacit admission that code review can't keep pace with what these agents actually do once deployed. If Brex, a company built on financial infrastructure, can't fully trust an agent's internals and has to fall back on network monitoring instead, that tells us something about where the rest of the industry stands. Founders building on frameworks like OpenClaw should take note: the security model isn't "verify the agent," it's "assume the agent is compromised and watch everything it touches." For developers, that means the interesting engineering problem right now isn't smarter agents, it's smarter perimeters and better observability at the network layer.

For researchers, it's a reminder that "agent" as a category is still fuzzy enough that even the people shipping it in production, like Franceschi, think the term itself is getting in the way of real risk assessment. Expect more enterprises to quietly adopt this same posture: not trusting the code, but instrumenting the network around it. That's a more honest place to start than pretending alignment solves this.

Common Questions Answered

What is CrabTrap and why did Brex develop this network-level security layer?

CrabTrap is a novel network-level security layer that Brex built after discovering that traditional security models failed when applying OpenClaw AI agents to internal roles. Rather than trying to verify the agent's code, CrabTrap monitors network activity to control what autonomous AI systems can access and do once deployed in production.

Why does Pedro Franceschi believe 'AI agents' is a terrible name for autonomous systems?

While the article doesn't explicitly state Franceschi's alternative terminology, his perspective suggests the industry's naming conventions may not accurately capture what these autonomous systems actually are or how they function. His criticism implies the current terminology is misleading about the nature and capabilities of these systems.

What triggered Brex's decision to shift from code review to network monitoring for AI agent security?

Brex realized that traditional code review security models couldn't keep pace with what AI agents actually do once deployed in production. This realization led them to assume agents could potentially be compromised and shift their security approach to network-level monitoring instead of relying on code verification.

When did OpenClaw become viable and what milestone enabled its development?

OpenClaw became viable after coding models reached a new level of maturity in December, with the framework shipping in January. This advancement in coding model capabilities made it possible for Brex to implement and test the open-source agent framework in their production environment.

What does Brex's approach to AI agent security suggest about industry-wide practices?

Brex's shift from code verification to network monitoring suggests that the broader industry may be unable to fully trust autonomous agents' internals and will need to adopt similar defensive security strategies. This indicates that companies building on frameworks like OpenClaw should assume agents could be compromised and implement network-level controls rather than relying solely on code review.

LIVE21:36AI Model GeoPT Simulates Physics With 1.3 Million Particle Interactions