With controversy swirling around rogue AI agents breaking into places they shouldn't be, Nvidia has stepped in to propose a solution.
On Monday, the company announced its Open Agent Safety Platform , a reference design that combines software safeguards with optional hardware-based monitoring and enforcement.
Speaking on CNBC's "Squawk Box" Monday, Nvidia CEO Jensen Huang described the new platform as "a browser for agents," a containment system that lets agents access only what they need to do their jobs.
Nvidia's OpenShell software limits an agent's access to files, networks, tools, and credentials. An optional layer, Nvidia Sentry, monitors and enforces those limits from separate BlueField hardware beyond the agent's reach.
"Jensen Huang and I share the same conviction: AI changes what the computing stack must provide for its behavior to be trustworthy," SentinelOne CEO Tomer Weingarten said in a statement. SentinelOne collaborated with Nvidia on the Open Agent Safety Platform.
"Today, you can't responsibly hand consequential work to an AI agent without knowing three things: what it's doing, whose authority it's acting on, and whether the limits on that authority actually hold," he maintained.
"Those guarantees can't rest on assuming a model following instructions," he continued. "We've watched that fail too many times. The safeguards have to be built into infrastructure itself."
For the last two months, AI agents have escaped sandboxes, discovered zero-day vulnerabilities, and coordinated multi-day intrusions against production systems without anyone telling them to, explained Denis Calderone, principal and CTO of Suzu Labs , a provider of AI-powered cybersecurity services in Las Vegas.
"Every one of those containment failures had the same root cause," he told TechNewsWorld. "Enforcement lived in software the agent could reach."
"Nvidia just said that out loud and shipped the alternative," he said.
He contended that the platform product isn't the significant part of Nvidia's announcement, but the concession embedded in it.
"The infrastructure company that powers most of AI compute is publicly acknowledging that software guardrails are not sufficient and that the industry needs a physical choke point between the agent and its own brain," he observed.
Lee Rossey, CTO and co-founder of SimSpace , operator of a high-fidelity cybersecurity simulation platform in Orlando, Fla., maintained that the most important thing about Nvidia's announcement is the recognition that this is a familiar problem in a new environment.
In its announcement, Nvidia explained that the internet brought endless opportunity, but also a lot of risk. A website could run code on your machine, steal your sensitive information, or infect your computer with a virus.
The internet was not made secure by requiring that web developers promise to be good, it continued. It became safe because the browser stopped trusting the code in the web pages explicitly.
We need to build this trust layer for agents, it added.
"We've learned that lesson with networks, cloud infrastructure, and identity; that trust has to be enforced through independent controls and continuous verification," Rossey told TechNewsWorld. "We're seeing a similar move to zero trust for AI agents."
"This is important as agents become autonomous," he emphasized. "Once an agent can call tools, access systems, and make independent decisions, model-level guardrails are just one layer of the safety ar…
