JPMorgan rolls out Claude changes: $2,000 spending limits and extra security
Internal Teams messages show some engineers at JPMorgan have spending limits for Claude. Bloomberg/Getty Images Internal messages on Teams show some engineers who use Claude have $2,000 monthly spending limits. The cap coincides with a new coding architecture for some engineers using Claude, "Devspace." Devspace restricts Claude's access to employees' credentials and ability to interact with firm systems. JPMorgan has launched $2,000 monthly spending limits for some employees using Claude Code, internal messages seen by Business Insider show. The cap, along with a new security effort for some Claude users, marks another evolution in how America's biggest bank is refining its AI use amid ballooning costs and risks, and reshaping expectations for software engineers. Last month, two Teams messages in a group for some engineers with access to Anthropic's Claude asked about a new error code: "ExceededBudget" and "Budget=2000.0." Responses from employees said that there is a monthly spending limit of $2,000 for certain engineers using Claude; two responses said that costs reset monthly. Other replies said that users can request to increase their spending limit. As Business Insider previously reported, JPMorgan, which has a nearly $20 billion annual tech budget, has carefully tracked its engineers' AI usage for months, but this is the first indication of AI spending or token caps. Token costs have become an increasingly pressing issue across Wall Street. In June, Zachery Anderson, chief data and analytics officer in payments at JPMorgan, said at a tech event that some employees are "spending more on tokens than their salary," but that there wasn't a firmwide effort to scale back usage, Semafor reported. During the bank's second-quarter earnings call in July, Chief Financial Officer Jeremy Barnum said that while token expenses were at that point "trivial," the bank is "forecasting some meaningful acceleration in that number for the second half of the year." JPMorgan declined to comment on the specifics of token limits or its cost strategy. A spokesperson said, "We're approaching AI with discipline, tying costs to measurable business value and consider a range of metrics, including adoption, outcomes, productivity improvements, quality, speed, capacity creation, risk reduction, and business impact." New architecture for Claude The $2,000 limit for some coincides with a broader change in how some engineers at the bank use Claude, and was mentioned in a Teams group about a new coding architecture, "Devspace." Until recently, some developers piloted Claude directly on their desktops. Devspace, however, is a longer-term plan that restricts Claude's access to employees' credentials and its ability to interact with internal systems, the spokesperson said. This type of restriction is especially useful for running and controlling AI agents, which can make decisions and carry out tasks on their own. Devspace is described as a "containerised," sandbox-like server hosted in Amazon Web Services in a blog post on an internal site for technical questions seen by Business Insider. A coding sandbox, like one on a playground, is an isolated place where software can run without affecting the rest of a computer system. The spokesperson said that Devspace is relatively new, and the bank is continuing to roll out new features. The blog post was published two months ago; it's unclear when the firm began introducing the new coding environment and how many engineers have access to it. Pat Opet, JPMorgan's global chief information security officer, talked about sandbox architecture during a fireside chat at a cybersecurity conference in April, before the bank introduced the platform. He said it can be risky to put powerful AI tools on the same desktops that house employees' emails, sensitive files, and personal information. Opet said the firm was "trying to build this in a way that isolates the platform that the AI uses," and creates distinct employee and AI desktop environments. "Ideally, we would want these agents to run in an ecosystem where they have no entitlements. They have an identity, but no entitlements," he said. "When these tools need access to a resource, we want to be in control of understanding the context around that." Under this type of architecture, JPMorgan can better understand and authorize agents' activity, Opet said. If an AI agent figured out how to break out of the environment, it wouldn't have the credentials to access internal systems or "abuse the enterprise." With the Devspace rollout, the bank has begun to realize Opet's vision, though it's unclear whether or when all engineers who use Claude will begin operating in the new digital environment. As of now, only a sliver of the bank's 65,000-person Global Technology division has access to Claude. In August, an internal dashboard seen by Business Insider showed that around 8,000 people had Claude licenses, and the Teams group for questions about Devspace had abo
READ ORIGINAL REPORT ↗





