TLDRocket
Sign in

How MRH Trowe enabled secure self-service AI agents in financial services

Amazon Web Services Marouane El Bostahi

MRH Trowe gave about 400 staff secure self-service AI agents in its first month. It keeps client data in Frankfurt and cuts chaos from shadow AI tools.

Based on reporting by Amazon Web Services, Marouane El Bostahi — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

MRH Trowe didn’t start with a flashy chatbot. It started with a problem that regulated firms know well: people want AI, and if you don’t give them a safe way to use it, they’ll improvise anyway. The German insurance broker rolled out secure self-service AI agents to roughly 400 employees in the first month of production, using a setup built for governance, not just convenience.

The draw here is not raw chat. It’s that the agents can reach internal systems, work with sensitive client data, and stay inside a centrally managed environment. MRH Trowe wanted employees to build and use agents without deep technical skills, but also without every team spawning its own little AI side project. That tension shaped the whole design.

The stack combines Strands Agents, Amazon Bedrock AgentCore, and LibreChat. Strands gives builders an open source SDK for creating agents quickly. AgentCore handles production runtime, session isolation, and the consumption-based model MRH Trowe wanted for cost visibility. LibreChat provides the front end: user management, token budgets, multi-model support, and a familiar chat interface that employees can actually adopt.

The first live agent is practical rather than flashy. An employee can ask, in German, for a recent Microsoft Teams meeting with a given participant, and the agent pulls the calendar entry, retrieves the transcript, and drafts meeting minutes with date, participants, agenda, topics, and action items. The request runs as the signed-in employee through Microsoft Entra ID, so the agent only reaches that person’s own calendar and transcript. The whole flow stays in the AWS Europe (Frankfurt) Region.

The architecture is built like something a compliance team would approve on a good day. Employees connect over private networking, the app runs on Amazon ECS with AWS Fargate, and data is split across Amazon DocumentDB, Amazon ElastiCache, Amazon RDS for PostgreSQL, Amazon OpenSearch Service, Amazon EFS, and Amazon S3 depending on the job. MRH Trowe says the setup cost about $14 per seat in the first month, with a path to cut infrastructure costs by about 40 percent through right-sizing and scheduled scaling. The bigger point is that the company now has a governed way to let employees experiment without turning the place into a shrine to unmanaged AI sprawl.

My take — AI-written commentary, not fact-checked reporting

This is the sane version of enterprise AI: boring controls, private networking, and no heroics. The industry keeps pretending “self-service” means chaos by default, when the real trick is making the secure path easier than the shadow path. MRH Trowe gets that, which puts it ahead of a lot of firms still acting surprised by their own employees.

Read more about this at: Amazon Web Services

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.