2021. What an interesting year. With the world turned upside down by a pandemic that seemingly had its sights set on...
AI and HPE Nonstop: What Controlled Access Has to Look Like
Infrasoft
AI and HPE Nonstop: What Controlled Access Has to Look Like
Pulling an ongoing series together into a single picture, ahead of TBC 26.

For the past few months, we have been working through a single question in these pages and in The Connection: how do you let AI work with the systems running on HPE Nonstop, safely, and without pretending those systems are something they are not? We took it one layer at a time. With TBC 26 coming up, it is worth stepping back and putting the whole picture together.
The hard part was never the model
Most of the noise around enterprise AI is about models. The harder problem, and the one that decides whether any of it is useful, is the connection between the model and the data and processes that actually run the business. On Nonstop that data sits under payments, core banking and other workloads where the cost of getting it wrong is high and the appetite for disruption is close to zero. Which is exactly why it is worth reaching, and exactly why you cannot reach it carelessly. The efforts that work augment these systems. They do not try to replace them.
A standard way in
For a long time, the obstacle was integration. Every model, every agent framework, every new tool wanted its own bespoke connection, and on a mission-critical platform that is a lot of custom code to trust. Model Context Protocol changed the economics. MCP has settled in as the common language between AI clients and the systems they need to reach, and building on it means one standards-based interface rather than a growing pile of one-offs. We provide that interface for Nonstop through uLinga Nexus, so an AI client can get at existing applications, files and processes without new plumbing each time the ecosystem shifts.
What you actually do with it
Connection is the easy half. The interesting half is what you build once it exists. In practice the use cases cluster: AI-assisted operational support, real-time fraud and anomaly detection, conversational interfaces sitting over existing business workflows, and knowledge tools that help people find their way around environments that have grown complex over decades. Take the conversational case. An analyst asks a question in plain language and gets an answer drawn from the live system, but the answer only ever contains what that analyst is already authorised to see. The conversational layer does not go around security. It runs inside it.
Control is the whole point
This is the part demonstrations tend to skip, and the part a Nonstop shop cares about most. Wiring AI into a mission-critical system makes for a good demo and a poor night’s sleep unless the access is governed. Nexus is built around that. Requests are authenticated with OAuth2 bearer tokens validated against a published identity provider. File retrieval is fenced by URI templates, so a client reaches what it is meant to and nothing beyond that. The management interface is role-based, down to a read-only role for people who should look but not touch. Every tool invocation is traced and tied back to its session. And where something would change state, a person stands in the loop: the AI observes, works through the problem and recommends, but the tool does not run until someone approves it.
Expose capabilities, not systems
If there is one line to take away, it is that. You are not handing an AI client the keys to a Nonstop. You are exposing a defined, scoped, observable set of things it is permitted to do, through a layer that enforces the rules and keeps a record of what happened. That is the whole distance between a proof of concept that gets a round of applause and something you would run in production against a live payments switch. Whether AI can connect to a Nonstop is not really the interesting question. The interesting one is whether the connection can be trusted, and trust is an architecture problem, not a demo.
See it at TBC 26
If any of this maps onto what you are working on, come and find us at TBC 26 in Orlando. We are happy to walk through the architecture, show Nexus mediating real access to a Nonstop, and talk through where it might sit in your environment. Stop by the Infrasoft booth, or get in touch beforehand at info@infrasoft.com.au.
This piece draws together an ongoing series in The Connection on AI, Model Context Protocol and controlled access to HPE Nonstop systems. The earlier articles are available on connect2nonstop.com.
Andrew Price has worked on the Nonstop for his entire career, including years as a BASE24 developer, and roles at Insession, ACI, XYPRO and NuWave Technologies. He has been with Infrasoft since January 2020, where he is Director of Business Operations.

