In an interview published September 30, 2026 in MIT Technology Review, OpenAI’s chief research officer, Mark Chen, described how his lab now watches its own models after a security lapse during training this summer. Specialized language models monitor other models’ reasoning and flag what looks wrong. “Now every single thing is put through monitors,” he said. Human reviewers assess the flagged cases: “It’s all triage.” Chen said OpenAI has shifted between 5 and 10 percent of its computing resources from training new models to safety work, chiefly monitoring. At the frontier of the field, the human component of systems development has taken on a new spirit. The humans no longer write every line; they decide what the machine may claim and rule on what the monitors catch.
In 1981, Tracy Kidder’s The Soul of a New Machine found that spirit in the engineers who built Data General’s Eagle: the compromises they accepted, the problems they refused to ignore, the judgment they exercised under pressure, infused into a general-purpose minicomputer. The new machine of 2026 is not general purpose. It is an AI workstation connected to licensed market data through the Model Context Protocol and purpose-built for one specialized, complex use case. Ours is corporate actions in securities finance. The human is still its soul. This post describes what that human had to do, and what a firm will have to do, to build one.
The door is now open
In June 2026, EquiLend said it was building MCP connectivity across its product suites, and on September 9 it launched its Data and Insights MCP connector, bringing securities finance data into compatible AI assistants for licensed clients across Spire, DataLend and Orbisa. LSEG has offered an MCP server for its licensed data and analytics since November 2025 and extended it in May 2026. On September 29, Bloomberg announced Enterprise MCP, for its clients’ AI agents. Tony McManus, Bloomberg’s global head of enterprise data and indices, said the bottleneck facing financial institutions “has shifted from model capability to data readiness.” For a desk that lends or borrows, the screen that displayed rates, utilization and balances for decades can now be asked a question, and the agent can pursue the evidence behind the answer.
Access settles who can reach the data. It leaves open who governs what the agent reads and what it may conclude. Oaktree Capital’s Howard Marks put the second half plainly in his February 26 memo, AI Hurtles Ahead: “Before investors take action on the basis of AI’s hypotheses, then, I think they’ll have to be checked for reasonableness.” Marks was writing about an AI’s conclusions. On the event, we found the same test had to be applied to the evidence the agent was permitted to use.
We built the workstation this use case requires
We tested it on the SpaceX (SPCX) lockup releases. The market expected the staggered releases to deliver a wave of newly lendable shares that would ease borrowing conditions. The shares had priced only in June, so the quantitative models arrived with considerable machinery but a shortage of observations.

The deep ensemble never cleared its validation gate and its forecasts entered no distributed edition. The reasoning agents carried the analysis, reviewing live lending conditions against our instructions and the IPO precedents of Klarna Group (KLAR) and CoreWeave (CRWV), with senior practitioners approving the evidence on the way in and the reports on the way out.

The approval ran to the admissibility of the evidence, not to a recommendation to lend or to borrow. The scored record, with its conditions attached, is in the after-action report and our companion post at CSFME. This post concerns the steps.
If this domain matters to your organization, this is what you will do
First, engage your own experts or retain specialist consultants, and settle the intellectual property before the work begins. In this machine the expertise is the product. The rulings a practitioner makes about admissible evidence and market conventions become the instruction set the agents run on, so the firm needs to own that instruction set outright. An employee’s work product ordinarily belongs to the employer; a consultant’s does not unless the engagement says so, so the engagement should be written as work for hire or carry an assignment of the resulting instructions, prompts and reference files to the firm. The expertise is needed because a database queried through MCP returns what was asked and nothing more. It will not warn an agent that a negative rebate on cash collateral corresponds to a positive intrinsic loan rate for the lender and a higher cost to borrow, or that an apparent large new loan on the real-time blotter may be an internal transfer. Someone with desk experience must rule on which records are admissible and specify the conventions the agent must follow.
The same record of transactions is read by both lenders and borrowers, but they are each asking for inferences about the future state of the market to guide their actions. The lender is asking whether a fee hike will result in the loan being terminated and the shares being returned; the borrower is asking whether a new locate will be needed from a cheaper lender because the short leg of the existing trade can’t support the new fee. The AI/MCP workstation states the evidence for the inference and the observation that would overturn the reading. Serving both seats from one record is possible only because the practitioner, not the agent, has already ruled on what the record may be taken to mean. That ruling is the expensive part.
In our early editions those rulings took hours. Some midday reports reached testers two to three and a half hours after their data cutoffs. One arrived after the close. The humans were in the loop, and the clock had noticed.
Second, build a reservoir of corporate action precedents and a way to relate them to the situation at hand. CoreWeave supplied the mechanics of lockup expiries for an exciting IPO. In August 2025, AI data centers were at the height of their excitement phase and benefited from a persistent narrative that produced institutional buying of most of the newly unlocked shares. The expiry produced a squeeze, not the expected deluge of supply and sales that would have driven the price slide the early short sellers needed. Our Klarna record showed a lockup expiry that produced constrained borrowable supply rather than the expected deluge, because eligibility to sell did not mean immediate selling or availability to lend. A precedent is useful to an agent only when its mechanism can be tested against the live data, so each one needs instructions stating which observations would confirm the analogy and which would overturn it. Our Corporate Actions Taxonomy does that work: it classifies each event by its significance for the stock loan desk and connects it to the filings, lending variables and conditions worth monitoring.
Third, optimize the reasoning agent’s instructions and conditional inferences so the market intelligence reaches traders while it is still useful. Every ruling we made was captured. The rebate convention, the treatment of vendor gaps and contaminated options rows, and the internal-transfer check each began as an intervention and now sits in the instruction set. A separate agentic auditor tests provenance, stale data, calculation consistency and compliance with those instructions before a human sees the report. As the recorded checks moved earlier in the process, delivery improved, and the human checkpoint became shorter because the system arrived better prepared. What the trader does with the intelligence remains the trader’s decision, whether the book lends or borrows; the workstation describes the market state, its evidence and what would change the reading.
Or lease what we have built. We will maintain the machinery for you
A firm can undertake all three steps itself. It will need experienced people to answer the same classes of questions and to test whether its rules still hold in the next event. Those hours belong to some of its most valuable practitioners. The alternative is to lease the work already done: ASC’s Securities Finance Reasoning and Evaluation Toolkit, with its proven taxonomy, data dictionary, Regime Change project instructions, task-specific prompts, reference files, precedent reservoir and separate agentic analyst and agentic auditor mandates, runs inside the client’s own environment on its own enterprise language models and licensed data. ASC maintains the precedents and the instruction set as each new event adds to them. The data partner need not host our models or receive client forecasts. Client tickets and internal forecasts stay inside the client’s walls.
A forecasting system delivers a number whose quality depends on the history behind it. On SPCX the most elaborate forecasting machinery we had did not earn admission, and a desk relying on it alone would have had nothing to read. The captured interventions kept producing intelligence when the forecasts could not, and they carry forward to the next lockup, tender or spinoff, where a forecast trained on one name has little to offer. With the major data providers opening their databases to agents, the next workstation should begin with more experience than an empty prompt box.
Sources and further reading
Will Douglas Heaven, interview with Mark Chen, MIT Technology Review, September 30, 2026
Howard Marks, AI Hurtles Ahead, Oaktree Capital memo, February 26, 2026
EquiLend, AI in Securities Finance: A Practical Approach, June 18, 2026
EquiLend Data and Insights MCP connector announcement, September 9, 2026
LSEG launches MCP Server in Databricks Marketplace, November 7, 2025
LSEG extends MCP connectivity to Amazon Quick, May 6, 2026
Bloomberg Launches Enterprise MCP, September 29, 2026
ASC KLAR, The Squeeze the Market Missed
The Chen interview and the Marks memo are quoted from their publications. EquiLend, Bloomberg and LSEG offerings are described from their own announcements. ASC examples draw on contemporaneous event-window records and the published after-action report. The toolkit and lease describe proposed services, subject to agreed data permissions and implementation. Nothing here is legal advice or a trading instruction; the workstation describes market state and evidence, and the participant decides what that means for its own book, long or short.

