GBHackers

NVIDIA Launches In-Silicon Security Platform to Monitor and Control Autonomous AI Agents


NVIDIA has launched its Open Agent Safety Platform, a security architecture designed for out-of-band monitoring, runtime policy enforcement, and hardware-backed control for autonomous AI agents.

This platform combines the open-source NVIDIA OpenShell runtime with NVIDIA Sentry protections on BlueField-4 data processing units (DPUs), aiming to prevent agents from exceeding their authorized access or operating limits.

NVIDIA In-Silicon Security Platform

The announcement addresses a growing concern regarding long-running agentic AI systems that can write code, call APIs, use credentials, access enterprise data, and delegate tasks to sub-agents.

NVIDIA argues that agents cannot be expected to reliably govern their own behavior, especially when tasks are ambiguous, tools fail, policies conflict, or models operate for extended periods.

The company describes this unintended deviation as agent “drift,” which occurs when an AI system strays from its assigned objectives or operating constraints.

Drift may result from unclear instructions, policy blocks, software bugs, missing tools, or repeated unsuccessful attempts to complete complex tasks. NVIDIA’s approach is to implement security controls outside the agent’s reach, rather than relying solely on the model or application to enforce safe behavior.

. NVIDIA Open Agent Safety Platform Reference Design (Source: Nvidia)

At the runtime layer, NVIDIA OpenShell provides sandboxed environments with kernel-level isolation. Operators can define the files, processes, services, APIs, credentials, and network destinations that an agent may use.

OpenShell then applies those restrictions during execution, including when the agent launches shell commands, generates code, creates child processes, or spawns sub-agents.

OpenShell’s architecture includes a Gateway for managing sandbox lifecycles and policies, a Supervisor that evaluates outbound requests, and an isolated Sandbox where the agent executes.

Network traffic is routed through policy enforcement points, enabling organizations to permit narrowly defined actions, such as read-only API queries, while blocking write operations to the same service.

Additionally, the runtime can keep credentials outside the agent environment, injecting them only into authorized requests directed to approved destinations.

A central feature is formal policy verification. Before applying any permission changes, OpenShell can analyze whether the new rule allows access beyond an operator-defined boundary.

This analysis aims to prevent risky policy expansions, such as granting an agent the ability to use a credential against a new host or API method. Policy changes may also require human review, ensuring that agents cannot independently approve their own access requests.

NVIDIA Sentry enhances this security architecture by providing an infrastructure-level control plane through BlueField-4 DPUs.

In NVIDIA Vera Rubin POD deployments, the BlueField-4 sits on the node’s path to the model, enabling continuous observability and enforcement independent of the host system.

This placement is designed to maintain monitoring even in untrusted host environments or with untrusted agent workloads.

The platform follows a three-layer model: application, runtime, and infrastructure. Applications encompass models, tools, data, and agent frameworks; OpenShell projects these workloads onto controlled compute environments; and NVIDIA Sentry, along with BlueField DPUs and NVIDIA DOCA, provides infrastructure-based enforcement, identity governance, and contextual activity records.

NVIDIA reports that OpenShell supports various agent frameworks, including Codex, Claude Code, Pi, and Hermes. The company has highlighted early adoption across fields such as chip design, enterprise automation, and physical robotics, naming organizations like Cadence, Slack, and Gecko Robotics as users of OpenShell-related controls.

The launch signals a shift towards treating autonomous AI agents as untrusted workloads rather than as trusted automation tools. By enforcing policies independently of the agent and adding optional hardware controls, NVIDIA aims to mitigate risks such as unauthorized data access, credential misuse, policy bypasses, unsafe API actions, and agent-to-agent privilege escalation.

For security teams, the core advantage lies in independent enforcement: while an agent may propose actions, it cannot directly alter the controls that determine what it can access or execute.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link