Rocket Software is expanding its Rocket EVA platform with a stronger focus on governed agentic artificial intelligence for the mainframe systems that quietly keep banks, insurers, retailers, and other large enterprises running. Announced on September 23, 2026, the updated platform is designed to let AI investigate operational problems and propose or perform tightly controlled actions while preserving established security policies, human oversight, and detailed audit records.
Why Agentic AI Is Moving Into the Mainframe
For many people, a mainframe is almost invisible. There is no familiar consumer interface and no flashy application window announcing that it is working. Yet behind the scenes, these systems can process enormous volumes of transactions, customer records, payments, account activity, and other critical workloads every hour.
That makes the prospect of autonomous AI particularly sensitive. An AI assistant that makes a mistake in an ordinary productivity application may create an inconvenience. An inappropriate action inside a banking mainframe could affect financial transactions, customer accounts, regulatory records, or essential business services.
Rocket Software is therefore positioning EVA around a different model. Rather than giving an AI agent unrestricted authority, the platform is designed to connect agentic capabilities with the controls already expected in mission critical computing environments.
Rocket describes EVA as an AI powered agentic platform capable of operational diagnostics across core systems. The company says it can connect information from mainframe and enterprise environments, analyze system behavior, and provide recommendations through natural language. Rocket Software’s EVA platform also supports a broader modernization strategy that includes mainframe, distributed, and cloud environments.
What Is New About Rocket EVA
The latest expansion moves EVA further from conversational assistance toward controlled agentic operations. Rocket Software says its approach is intended to allow organizations to introduce AI gradually while retaining people and existing security infrastructure at the center of important decisions.
One of the key additions is a security layer called PlanGuard. The technology is designed to evaluate an AI agent’s proposed action before that action is executed. Rather than relying only on permissions assigned when a user or service account is created, the system can consider the specific request, user, tool, session, environment, and applicable organizational policies.
That distinction becomes especially important when AI agents begin moving beyond analysis. An AI system can be useful when it identifies a problem, but the potential value becomes much greater when it can help coordinate the response. At the same time, the consequences of an incorrect response also become more serious.
Rocket Software says PlanGuard can permit an action, deny it, or require additional approval. When authorization is granted, the system can create a temporary execution identity associated with the approved task and revoke that identity after the operation is completed.
Keeping Humans in Control
The central idea behind governed agentic AI is not simply to make an AI system more autonomous. It is to make autonomy accountable.
For an enterprise security team, knowing that an AI agent performed an action is not enough. Security professionals may need to determine who initiated the request, what the agent attempted to do, which policy applied, whether someone approved the action, what identity was used, and what happened afterward.
Rocket says EVA records these stages as part of an auditable activity trail. The company describes the system as producing a tamper evident record that connects the request, proposed action, policy decision, authorization, execution identity, and resulting activity.
That type of traceability can be particularly relevant for financial institutions, where technology operations often exist alongside strict internal controls and regulatory obligations. A bank cannot simply tell an auditor that an AI system made a decision. It needs evidence showing how the decision was handled within the organization’s control framework.
Existing Mainframe Security Does Not Disappear
Another important element of Rocket’s approach is its relationship with established mainframe security systems. Rocket says PlanGuard works with security managers such as RACF, ACF2, and Top Secret rather than attempting to replace them.
This is significant because large organizations have spent decades building identity, access, and authorization structures around their core systems. Replacing those controls simply to introduce AI would create a substantial operational and security challenge.
Instead, the newer model places an AI governance layer around existing controls. The result is intended to give enterprises a way to experiment with agentic workflows without abandoning the security architecture already responsible for protecting critical workloads.
From Natural Language Questions to Multi Step Investigations
EVA’s earlier capabilities already focused on natural language interaction with mainframe operational information. Instead of manually navigating multiple consoles, dashboards, logs, and reports, an operator can ask a question about system behavior and allow the platform to gather relevant information.
Rocket says EVA can select connected tools and data sources, collect operational context, correlate evidence, and return findings with recommendations. This approach can be useful when a problem crosses several parts of a complex environment.
Imagine a financial institution experiencing an unusual slowdown in a transaction processing system. An operator may traditionally need to examine several sources of information before identifying the underlying cause. The investigation could involve system status, application behavior, transaction activity, dependencies, and performance information.
An agentic platform can bring those steps together. Instead of treating each source as a separate investigation, EVA is designed to connect the evidence and present a more unified explanation of what is happening.
The Mainframe Skills Challenge
There is also a human reason behind the push toward AI assisted mainframe operations. Experienced mainframe specialists possess knowledge that can take years to develop, while organizations increasingly need to support complex systems with teams that may have less exposure to older computing technologies.
Rocket’s approach is intended to make specialized system knowledge more accessible through conversational interaction. The company says developers, operators, and support teams can use natural language to investigate system conditions without requiring the same depth of platform expertise traditionally needed for every diagnostic task.
This does not mean that experienced engineers suddenly become unnecessary. In a mission critical environment, their judgment remains valuable precisely because they understand business context, operational history, unusual system behavior, and the consequences of changing production systems.
The more practical possibility is that AI can help experienced specialists spend less time gathering information and more time making important decisions. It can also give newer employees a clearer starting point when they encounter a complicated incident.
Why Financial Institutions Are Watching Closely
Financial institutions have a particularly strong reason to examine governed AI. Banks and other financial organizations operate some of the most demanding transaction environments in the world, with reliability and security requirements that leave little room for uncontrolled experimentation.
At the same time, these organizations face pressure to modernize their technology operations while continuing to support systems that have served customers for decades. Completely replacing those systems is often expensive, disruptive, and technically complicated.
That creates an opening for technologies that can add modern intelligence around existing infrastructure without requiring immediate replacement of the core system itself.
Rocket Software’s January 2026 launch of EVA described the platform as a way to connect conversational AI with core systems through the Model Context Protocol, allowing teams to query system information, diagnose issues, and receive recommendations without interrupting production workloads. The company’s original EVA announcement positioned the technology as part of a broader effort to modernize critical systems without disruptive migration.
Why Governance Could Determine Enterprise AI Adoption
The biggest question for enterprise AI is increasingly not whether an AI model can generate an answer. It is whether an organization can safely allow that system to interact with real infrastructure.
That requires several layers of protection. Identity controls must determine who is requesting an action. Policies must establish what the agent is allowed to do. Approval mechanisms must handle sensitive operations. Audit records must document activity. And organizations must retain the ability to stop or restrict automated behavior when conditions change.
Rocket EVA’s expanded architecture addresses these concerns by placing governance directly into the path between an AI agent and an operational action.
What Comes Next for AI and Mainframe Operations
The move toward agentic AI in mainframe environments is likely to develop gradually. Enterprises have strong incentives to begin with tasks where the potential benefit is clear and the consequences of an error can be tightly controlled.
Early use cases can include diagnostics, performance analysis, anomaly investigation, operational recommendations, and assistance with repetitive support work. More sensitive actions can remain behind human approval until organizations gain confidence in the technology and establish appropriate policies.
Rocket Software’s current direction reflects that gradual model. Its platform is designed to allow enterprises to begin with AI assisted investigation and then expand toward controlled actions while maintaining visibility into what the agent is doing.
For banks and other organizations that depend on mainframes, that distinction may matter more than the novelty of agentic AI itself. The central question is not whether an AI agent can act. It is whether the organization can clearly determine when it may act, what it may do, who authorized it, and what evidence remains afterward.
That is where Rocket EVA’s latest expansion becomes relevant. The mainframe may be one of the oldest foundations of enterprise computing, but the way organizations operate it is changing rapidly. By combining conversational intelligence, agentic workflows, existing security controls, human approval, and auditable activity records, Rocket Software is attempting to bring modern AI capabilities into that environment without treating reliability and governance as optional features.

