EXCLUSIVE: "The New Playbook" - Red Hat in 'Discover Sibos'
By Lauren Towner · 1 October 2026

As with any transformative technology, AI creates as many challenges as it solves. Red Hat is a global open-source enterprise solutions provider that has been working on tackling some of the biggest issues surfacing right now – namely, how best to integrate gen AI with existing architectures; how to make sure agents don’t go rogue; and how to reduce the big artificial footprint that AI could leave on the real word.
We assembled a wide-ranging panel of Red Hat experts to get their take on all three
A flexible infrastructure for AI
Open up the technology stack of a typical bank and you’ll find something closer to an archaeological dig than a tidy data centre. Mainframes at the bottom, a layer of virtual machines above, Cloud infrastructure on top and, increasingly, a fresh deposit of containers.
Sitting atop many companies’ stacks, a brand new AI layer is now growing. The challenge isn’t simply where to put it, but how to make it get along with decades of technology sediment underneath.
“The rate of change that’s come, particularly with AI, has exposed some real challenges,” says Ivan Jennings, Automation Platform Lead, UKI & CENE at Red Hat. The mainframes underpinning many UK and Irish financial institutions remain famously dependable, he says. But the journey into Cloud, Kubernetes and now AI has made ‘the speed at which institutions can get change into the market’ a far tougher proposition.
For Dario Molinari, Senior Solutions Architect at Red Hat, the squeeze is tightest for institutions still leaning on ageing kit. Modernisation can mean ‘injecting new technologies like AI into end-of-life systems infrastructure’, he says. “That is the big challenge – just scaling the level of effort with ever-reducing budgets.”
The good news? Modernisation doesn’t have to mean bulldozing the dig site and starting again. Rather than babysitting each generation of technology separately, Red Hat argues for greater standardisation across the estate. Monica Sasso, Digital Transformation Lead, Global Financial Services, at Red Hat, says a common platform can act as a consistent layer across old and new technologies alike, taking the sting out of managing them.
Crucially, standardising doesn’t mean modernising everything in one heroic undertaking. Sasso argues that firms should be able to move at their own pace and within their risk tolerance, without disrupting important business services. The idea is to abstract away some of the underlying complexity, freeing attention for the things that matter: security and innovation. Her prescription fits on a post-it note: standardise, simplify and automate.
Red Hat OpenShift, the company’s Kubernetes-based hybrid Cloud application platform, is one way to put that into practice. It lets virtual machines and containerised applications live side by side on a common platform, while also supporting AI workloads. That combination matters as financial institutions look to bring in AI without abandoning the applications they already rely on.
Ashesh Badani, Senior Vice President and Chief Product Officer at Red Hat, describes the opportunity as getting mission-critical legacy applications and newer Cloud-native ones onto the same platform, then extending that foundation to AI models and agentic workflows. It may be best to think of this as progressive modernisation, rather than rip-and-replace. Existing applications keep running while practice.
It lets virtual machines and containerised applications live side by side on a common platform, while also supporting AI workloads. That combination matters as financial institutions look to bring in AI without abandoning the applications they already rely on.
Ashesh Badani, Senior Vice President and Chief Product Officer at Red Hat, describes the opportunity as getting mission-critical legacy applications and newer Cloud-native ones onto the same platform, then extending that foundation to AI models and agentic workflows. It may be best to think of this as progressive modernisation, rather than rip-and-replace. Existing applications keep running while centres and public Cloud. In financial services, those decisions come with extra homework: regulation, compliance, data restrictions and digital sovereignty requirements.
Red Hat’s answer is what it calls open hybrid Cloud: using open-source technology to create a consistent foundation across public and private Clouds and on-premise infrastructure.
Jennings puts the principle simply: “Open hybrid Cloud is all about being able to move your data, your applications, your tooling from one set of infrastructure to another, whether that’s in your own data centre or in the Cloud.”
For financial institutions, that portability means more say over where different workloads live. It also ties into another pillar of Red Hat’s philosophy: open source. Jennings argues that openness gives organisations more freedom and reduces the risk of becoming beholden to a single vendor. Of course, freedom comes with its own paperwork. Running applications across different technologies and environments multiplies the number of processes institutions need to manage consistently.
Richard Harmon, VP & Global Head of Financial Services at Red Hat, points to patching, architecture modernisation and moving workloads between environments as prime candidates for automation. He describes it as ‘a foundation for any kind of architecture, hybrid in particular’.
Red Hat’s Ansible Automation Platform is designed to automate IT operations across an organisation’s technology estate, including virtualised infrastructure, operating systems and networks spanning data centre, Cloud and edge. In financial services, that can stretch to operational resilience and disaster recovery, too.
For Sasso, part of the value lies in making resilience boringly routine. She describes customers that, every day after trading closes, use automation to wipe their servers, rebuild them and restart them ready for the next trading day. If a failure or attack does strike, recovery isn’t a panicked scramble; institutions need to manage consistently.
Guardian or predator? AI defences
Generative AI is growing up fast. Having mastered producing information, it’s evolving into agentic systems that can size up a situation, make a decision and act on it. For an industry trusted with customers’ money and sensitive data, that creates a double challenge: making sure AI systems behave as intended, and protecting them and the infrastructure around them from outside threats.
Recent AI security headlines, including the Claude Mythos incidents and Hugging Face, have thrown those risks into sharp relief and divided the industry between those who believe agents are best kept corralled behind proprietary walls and those, like open source specialists Red Hat, who argue that transparency and shared responsibility are the only way to keep them in check.
Any organisation seeing the swarms, breakouts and hacks of recent months is forgiven for feeling queasy – especially if it’s a financial institution. How should it keep increasingly capable AI secure, accountable and under control while the technology keeps moving?
For Richard Harmon, VP & Global Head of Financial Services at Red Hat, control starts well before an AI system goes live. Borrowing the software development principle of ‘shift left’, the practice of moving tasks like testing and security earlier in the software development lifecycle, he argues that institutions should set the rules of the road for AI before they start building anything.
They also need to be able to see and question what AI systems are up to. Harmon points to strict controls, auditability and traceability, alongside rising demands for transparency and explainability.
“With AI, as it becomes more autonomous in terms of starting to evaluate systems and making decisions, physical decisions, the guardrails and the transparency and explainability are key," he says.
For agentic AI, that means staying in its lane, or as Julio Guijarro, Chief Technology Officer, EMEA, at Red Hat, puts it, doing the jobs expected of it and not wandering ‘outside of the domains that you are interested in’, which raises the obvious question of who is monitoring the situation. Ivan Jennings, Automation Platform Lead, UKI & CENE at Red Hat, envisages increasingly ‘self-healing infrastructure’, where AI fixes technical problems while a human stays in the loop, keeping an eye on things.
Regulators are thinking along similar lines. The EU AI Act introduces transparency and risk-management requirements for certain AI systems, while the NIST AI Risk Management Framework gives organisations a structure for managing AI risks throughout their lifecycle. For financial institutions, the stakes are especially high: AI innovation has to coexist with regulatory obligations and the duty to protect customers’ money and data.
Governance can’t afford to wait for the technology, or the rulebook, to stop moving. Guardrails are one layer of defence, for Red Hat, open source offers another – toughening up the technology itself through transparency and collective scrutiny. Put simply, open source makes the underlying code available for anyone to inspect, test and contribute to. Red Hat argues that this lets a wider community of developers, researchers and organisations spot vulnerabilities and build safeguards together, rather than relying on a single technology provider to catch everything.
Harmon sees that many-eyes model becoming increasingly important for AI: “The goal here is a global community ensuring everything is secure and safe,” he says. “It’s not one single firm who owns a monopoly on a particular capability.”
Guijarro argues that meaningful openness means understanding how models were built, what data went into them and which tools were used in order to trace how decisions are made. Red Hat is applying that open-source thinking to AI’s emerging security challenges. In July 2026, the company became an inaugural member of NVIDIA's Open Secure AI Alliance, an initiative focussed on developing open tools and techniques to protect the AI stack, from open-weight models all the way through to agent harnesses. Writing principles and regulations down is one thing. Turning them into controls that actually run alongside live AI systems is quite another.
As Steven Huels, VP of AI Engineering at Red Hat, puts it: “As organisations transition from experimental AI pilots to long-running, autonomous agents, establishing clear operational guardrails becomes a critical infrastructure requirement.”
Closing that gap is the focus of asago – AI Safety And Governance Orchestration, a collaborative open-source community project that Red Hat announced in August. Asago aims to translate corporate and regulatory AI governance policies into working operational controls. Importantly, the project is designed to plug into frameworks that institutions may already be wrestling with, including the NIST AI Risk Management Framework, OWASP LLM Top 10 and the EU AI Act. And it isn't a Red Hat solo act: founding participants include Microsoft, NVIDIA, IBM Research, MIT Lincoln Laboratory and The Alan Turing Institute.
Asago is still in its formation phase, but its premise speaks to the need for governance to start moving at something closer to the speed of the technology as AI systems become more autonomous. For financial institutions, the goal isn't to pick between AI innovation and safety. It's to build an environment where the two can advance together. As AI takes on more autonomy, financial institutions will need clear guardrails around what it’s allowed to do.
Red Hat sees open-source transparency and collective scrutiny as one line of defence, alongside governance that can turn policy into practical controls. The technology won’t stand still, and neither can the systems built to keep it honest.
AI’s hidden bill. Counting the cost of resources
Banks have spent years scrutinising the environmental footprint of the companies they finance. As AI adoption grows, they may need to look a little closer to home: at the energy and water consumed by the technology humming away in their own operations. Red Hat argues that seeing where those resources go is the first step to using them more efficiently.
Every model, however clever, has a physical address. AI training and deployment happen mainly in data centres, where servers draw electricity and cooling systems can consume both power and water. The Banks have spent years scrutinising the environmental footprint of the companies they finance. As AI adoption grows, they may need to look a little closer to home: at the energy and water consumed by the technology humming away in their own operations.
Red Hat argues that seeing where those resources go is the first step to using them more efficiently. Every model, however clever, has a physical address. AI training and deployment happen mainly in data centres, whereservers draw electricity and cooling systems can consume both power and water. The of global electricity consumption in 2024 and expects their electricity demand to more than double by 2030, with AI the biggest driver of that growth.
The UK Environment Agency says large data centres can use millions of litres of water a day, and growing AI use is expected to push up demand for data-centre capacity. As financial institutions roll out more AI, understanding the resources behind it matters not just for sustainability, but for efficiency and cost. You can’t cut what you can’t see.
Julio Guijarro, EMEA Field CTO at Red Hat, argues that better data gives organisations visibility into which computing processes are eating energy, and where there’s room to trim.
“For sustainability, and really any green agenda, we need the data,” he says.
One approach Red Hat has worked on is Kepler – Kubernetes-based Efficient Power Level Exporter, an open-source project that estimates and reports the energy consumption of processes, containers and Kubernetes pods. Think of it as a smart meter for your workloads: those metrics can then be used to spot and optimise energy use.
For Guijarro, visibility can also change behaviour. Showing developers and users the energy impact of what they build gives them something to act on when deciding how to design and run it.
“If there is no data, you don’t see what is happening, how the work that you are doing affects the consumption of technology – and then it’s very difficult to change it,” he says.
A dashboard, however, is only useful if someone acts on it. Dario Molinari, Senior Solutions Architect at Red Hat, argues that infrastructure efficiency and sustainability are becoming hard to tell apart. He points to the shift towards leaner, containerised infrastructure as one way financial institutions have slimmed down the physical resources needed to run applications, while better monitoring, metering and telemetry show developers exactly how much an application consumes.
For Molinari, that makes sustainability as much a question of economics as of environmental responsibility. Organisations that don’t prioritise it, he argues, could end up feeling it twice: in their cost base, and in the growing scarcity of energy and other resources.
There’s one more consideration for financial institutions: what they expect from the businesses they finance may increasingly need to show up in their own technology operations. Practising what you preach, in other words. Molinari says the banks he works with take sustainability seriously because they have ‘a duty of sustainability towards their investors’. Many also offer sustainability-focussed products, which gives them another good reason to check how efficiently their own IT runs.
For financial institutions, getting a grip on AI’s growing appetite starts with understanding it. it. Better visibility shows where energy is being consumed, while more efficient infrastructure can cut both resource use and cost. And for institutions asking the businesses they finance to meet sustainability commitments, their own technology estate is increasingly part of that conversation.
As AI scales, how lightly it treads on the planet’s resources may become one of the most important measures of its success.