ibl.ai
ibl.ai supplies a self-hosted, model-agnostic agent platform to banks, broker-dealers, asset managers and wealth firms, deployed inside the institution's own virtual private cloud, on-premise, or fully air-gapped with no route to the public internet. Its argument is that model risk guidance places validation, governance and monitoring on the bank rather than the vendor, so the bank must be able to inspect the whole stack: it runs several named model families including self-hosted open-weight options, lets the institution's model risk team pin specific versions and sign off validation packs, treats any model swap as a new validation event rather than a vendor surprise, ships platform code under an open licence with a perpetual platform licence so orchestration logic is inspectable and reproducible, and writes every call to the bank's own security monitoring system with model version, prompt template, input hash, output, decision flag and disposition.
A knowledge graph unifies customer data fragmented across core banking, customer, risk and financial crime systems, connected over open protocol with row and field level security, and ownership is transferred to the institution's team.
Capability Axes
Capability grades
15 of 15 axes rated · 10 graded A or B
The product is an agent platform and nothing else: model serving, orchestration, a knowledge graph for retrieval and agents running compliance, research, advisory and financial crime workflows. It is worth naming the tension that the platform is horizontal, serving education, healthcare and government alongside finance, and it clears the financial services bar on shipped capability rather than positioning, with a sector-specific data ontology spanning core banking, customer, risk and financial crime systems, a supervisory guidance architecture mapping, and a deployment blueprint for regulated firms.
No oversight model, approval threshold, escalation path or human review requirement is described for agents operating across compliance, advisory and financial crime workflows. The platform provides the material oversight depends on, with complete logging including a decision flag and disposition per call, and it does not state who reviews those decisions, when an agent must defer, or what an agent is permitted to act on rather than recommend.
Four mechanisms map directly onto what supervisory model risk guidance asks for. The institution's model risk team pins specific model versions, validates the chosen version against the workload and signs off a validation pack, and crucially a model swap becomes a new validation event rather than a vendor surprise, which is the direct answer to silent provider updates changing behaviour without the bank acting.
Platform code is open licensed and the licence perpetual, so orchestration logic can be inspected, documented in the validation pack and reproduced indefinitely, making development soundness auditable in the guidance's own terms. Every call logs to the bank's existing security monitoring system with six fields including model version, prompt template, input hash, output, decision flag and disposition, and outputs are versioned by default. Logging to the bank's own system rather than the vendor's is what makes it evidence the institution controls.
Scale is stated at more than 400 organisations and 1.6 million users, with partner status at three major cloud providers, and every named customer is a university rather than a financial institution. No bank, broker-dealer or asset manager is identified anywhere, and no deployment count, workload or outcome figure is published for the financial services business specifically. The engineering aimed at this sector is substantial; the evidence that anyone in it has bought is not.
This is the strongest stewardship position in the index because it is structural rather than promised. The platform self-hosts in the institution's own infrastructure, on-premise or fully air-gapped, so the vendor has no path to customer data at all rather than a policy against using it.
The company states the knowledge graph never sits in a vendor index, that the ontology an institution builds is its own to keep, extend and govern rather than data locked inside someone else's product, and that engineers transfer ownership to the institution's team so the firm gains capability rather than a tool. Perpetual licensing and open source platform code mean the arrangement survives the vendor.
Privacy follows from architecture rather than policy, since the knowledge graph and all client data stay inside what the company describes as the institution's own aligned boundary and never enter a vendor index. Source systems connect once with row and field level security, so access control operates at the data element rather than the system. Held at B because no data processing agreement, retention schedule or subprocessor register was located, and the alignment claim is stated rather than attested.
Controls are described concretely, covering alignment to the service organisation control standard and financial privacy requirements, identity bound to the institution's own provider, row and field level data security, and complete audit logging into the institution's monitoring system. Air-gapped deployment removes network exposure entirely. Held at B because the standard is described as aligned rather than certified, and no attestation report, penetration test summary or trust centre was located.
Five regimes are engaged at mechanism level rather than listed: model risk guidance, securities and broker-dealer supervision and recordkeeping, financial reporting controls, financial privacy, and national bank supervisory expectations. The treatment of model risk is the sharpest in the index, correctly identifying that the guidance places validation, governance and monitoring on the bank rather than the vendor, and therefore that an uninspectable model makes every obligation harder.
A concrete 90-day governance sequence accompanies it, running from inventory and risk tiering through policy update and a governance layer in production to a first workload under full governance, with the observation that inventory and tiering is the foundation and nothing else is defensible without it.
No fairness testing, bias monitoring or disparity analysis was located. The platform supplies infrastructure rather than decisioning models, which places bias in the customer's application layer, and agents operating in advisory and financial crime workflows still produce differential outcomes for individuals, with financial crime screening in particular carrying well-documented disparate impact. Governance content addresses control and auditability throughout without reaching fairness.
No guarantee, indemnity or correction process was located, and the architecture arguably makes this the customer's responsibility by design, since the institution owns the deployment, the models and the decisions. That is a coherent position and it leaves the affected individual unaddressed: a customer wrongly flagged by an agent reasoning over the knowledge graph has no described route to correction, and the audit trail exists to satisfy the examiner rather than to give them a remedy.
Five model families are named directly, including two that can be self-hosted so no external provider sits in the path at all, and the institution rather than the vendor chooses among them and pins the version. Platform code ships under a permissive open source licence with a perpetual platform licence, so the orchestration layer is inspectable rather than trusted.
That combination answers the third-party model dependency question completely: a bank can document which model, which version, running where, under whose control, and can change any of it without the vendor's involvement.
The integration thesis is well argued: a customer is fragmented across core banking, customer relationship, risk and financial crime systems, and an agent reasoning over that fragmentation can miss a sanctions flag or quote a stale balance, which in a regulated firm makes a confident wrong answer a compliance event. The response is a unifying ontology with source systems connected once over an open protocol carrying row and field level security and full audit trails. Held at B because no individual core, customer or screening system is named, so a bank cannot confirm its own stack is covered.
The deployment range is the widest in the index and includes an option no other vendor here offers: managed private cloud inside the institution's own account, on-premise installation, and fully air-gapped operation with no route to the public internet at all, intended for trading and private client desks.
Identity binds to the institution's own provider and logs land in its own monitoring system, so the deployment sits inside the perimeter examiners already inspect rather than adjacent to it. Residency is answered by construction rather than by regional selection.
Two structural commitments are published without any price attached: the platform licence is perpetual rather than subscription, and a core component ships under a permissive open source licence. Both materially affect total cost and lock-in, and no rate, unit or implementation cost accompanies them, nor any indication of what forward-deployed engineering costs.
The buyer is defined by function as much as institution, aimed at technology, security and AI leadership at banks, broker-dealers, asset managers and wealth firms, with agent coverage across compliance, research, advisory and financial crime. Deployment tiering is thought through, proposing managed private cloud for lower sensitivity work and air-gapped installation for trading and private client desks. Held at B because the platform serves three other industries and no financial services presence is evidenced by name.
What Changed
Material product, regulatory, evidence and commercial changes at ibl.ai, each verified against a live source and tagged to the capability axis it bears on. Funding rounds and awards are not product changes and are not logged.
ibl.ai added Projects and Workflows for organizing agentic tasks. A Project is a workspace holding its own files, standing instructions and assigned agents, and a Workflow is a multi step agent execution structured as a graph with branches, loops and guardrail checks.
ibl.ai documented supported deployment paths for applications built on its platform, including pushing a Next.js application directly to a platform hosted deployment on ibl.ai infrastructure.
ibl.ai introduced server side spend caps for model usage, configurable at workspace, agent or user and agent level. Caps carry customizable reset periods, near limit alert thresholds, and enforcement modes that either block usage or raise an alert.
Compared With
Most editorial comparisons pair two vendors the index assesses as direct competitors for the same buyer. Some pair vendors that are adjacent rather than rival, where the useful question is where one ends and the other begins. Each carries a verdict, the buyer conditions that favor each vendor, and a graded side by side.
Alternatives to ibl.ai
The closest documented capability profiles to ibl.ai in the same categories, ordered by similarity across the same fifteen axes the index grades every vendor on. Closest documented profile, not a claim that either product does the same job. No vendor pays for placement.
Documents Autonomy and Oversight Model where ibl.ai does not
Documents Autonomy and Oversight Model and AI Governance and Bias Disclosure where ibl.ai does not
Documents Operational and Outcome Evidence and Autonomy and Oversight Model where ibl.ai does not
Documents Autonomy and Oversight Model and AI Governance and Bias Disclosure where ibl.ai does not
Documents Operational and Outcome Evidence and Autonomy and Oversight Model where ibl.ai does not
Documents Autonomy and Oversight Model and AI Governance and Bias Disclosure where ibl.ai does not
Similarity is computed axis by axis from published grades, not from a composite score. The index does not aggregate grades into a total. See the fifteen axes and the methodology.
Pricing
Vendor-published figures are labeled as such. Figures labeled “Estimated” are derived from third-party sources and have not been confirmed by the vendor.
No pricing data has been verified for this vendor. Pricing information will be published here once confirmed through vendor disclosure or third-party estimation.