NVIDIA Launches Agent Security Platform: To Ensure That AI Acts Within Defined Boundaries Before Taking Action
CoinMeta
1h ago
Ai Focus
As AI intelligents move from answering questions to operating files, invoking tools, and accessing enterprise systems, security issues have also shifted from "saying the wrong thing" to "doing the wrong thing." On September 28th, NVIDIA announced Open Agent Safety Platform, aiming to isolate, monitor, and handle the operations of these intelligents within the same open architecture. The announcement includes an open-source runtime OpenShell, as well as a reference design for Sentry geared towards independent monitoring. The focus of the product is not to ensure that every answer given by the model is correct, but rather to limit the actions that the model can take even if it is misled.
Helpful
No.Help

As AI intelligents move from answering questions to operating files, invoking tools, and accessing enterprise systems, security issues also shift from "saying the wrong thing" to "doing the wrong thing." On September 28th, NVIDIA announced Open Agent Safety Platform, aiming to isolate, monitor, and handle the operations of these intelligents within the same open architecture. The announcement included an open-source runtime OpenShell, as well as a reference design Sentry for independent monitoring. The focus of the product is not to ensure that every answer given by the model is correct, but rather to limit the actions that the model can take even if it is misled.

This difference is not abstract. An agent with permission to read emails and create external links may interpret instructions in malicious emails as user requests; a development assistant capable of executing commands might bring untrusted scripts into the local environment when installing dependencies. Past security tools were mostly designed around human accounts and deterministic programs, but agents can plan their steps autonomously and dynamically select tools on their own. Simply reminding users at the input stage to “not follow malicious instructions” is insufficient to replace the hard constraints in the execution environment.

OpenShell Put control into runtime.

NVIDIA describes OpenShell as an open-source runtime available for developers to use, which is used to manage the resources that agents can access and the actions they can perform. The approach is to provide agents with a restricted workspace and continuously apply policies when interacting with external systems. Checking permissions as files, network requests, and tool calls occur, rather than only after reviewing chat records, is closer to the existing principle of least privilege in enterprises.

The value of runtime constraints lies in their independence from whether the model “understands” a security prompt. Suppose a sales assistant is authorized to access a list of customers but does not have the right to send that complete list externally; even if it generates an upload request, the execution layer should still prevent unauthorized connections. The closer security controls are to the actual actions, the greater the chances of defending against prompt injection, misplanned operations, or abnormal returns from tools. However, errors in policy design can still leave vulnerabilities; what the platform provides is the capability for execution control, not the automatic creation of permission rules for each company.

The announcement states that OpenShell can be controlled on NVIDIA Vera CPU and can also be extended to Arm and Intel platforms. It is important to distinguish between "can be extended" and "all chip combinations have been verified by customers." Open source provides developers with the space to review and modify it, but it also means that companies need to check the versions, dependencies, patches, and operating environments themselves. Installing a set of open-source components in a test environment is different from running them stably in multi-departmental operations; these are two separate stages.

NVIDIA also proposed a reference design using BlueField-4 and DPU to act as gatekeepers outside of the main operating environment for the agents. The idea of independent channels is to retain the ability to observe and isolate in case the main environment is compromised or exhibits abnormal behavior. The announcement mentions a millisecond-level isolation goal, but the reference design cannot be equated with large-scale customer systems having already achieved the same effect; actual latency will still be affected by network conditions, the number of policies, application architecture, and load. Enterprises should request repeatable test data when making purchases, rather than treating the design goals as a commitment.

The security boundaries should be designed together with the business boundaries.

It is difficult to set the permissions for an agent all at once. If too few permissions are granted, it won't be able to complete even normal tasks; if too many are granted, a single misjudgment could lead to data leakage or incorrect transactions. In practice, tasks can be divided into four layers: reading, providing recommendations, preparing for execution, and final submission. The first two layers allow for more automation, while the latter two, which involve funds, sensitive data, or irreversible modifications, should retain approval and logging processes. For runtime systems like OpenShell, to truly be effective, they must work in conjunction with the organization's identity management system, data classification, and approval procedures.

Monitoring should not merely record the model's inputs and outputs. An agent may sequentially invoke search, database, and email tools; each individual request may seem reasonable on its own, but when combined, they can lead to unauthorized outcomes. Security teams need to see the complete call chain, the identity used at each step, the actions that were blocked, and whether retries were attempted after exceptions occurred. Otherwise, incident reviews will still get stuck at the question of "why did the model think that way," without a clear understanding of what the model actually did.

NVIDIA's business motivations in this area are clear: the more agent applications there are, the more enterprises need stable, isolated, and secure infrastructure. However, the effectiveness of security cannot be proven solely by vendor press releases. Customers should measure false positive rates, false negative rates, recovery times, and operational costs under real permissions, with real tools, and using adversarial samples. It is especially important to test scenarios where the security measures themselves fail. Open source and hardware isolation can increase options, but they do not replace these validation processes.

This release marks the beginning of a shift in infrastructure competition for AI, where "what is allowed to be done" is now considered as important as "how fast it can be done." OpenShell has been made available as an open component, while Sentry remains a reference design; their levels of maturity differ. For companies preparing to deploy agents, the most useful conclusion is not to claim that risks have been resolved, but rather to define clear permission boundaries within a system that is executable, testable, and accountable, before deciding how far the agents can go.

The deployment pace should also match the level of risk. Enterprises can first allow agents to process public information in an isolated environment, record their reactions when encountering malicious websites, phishing emails, and feedback from faulty tools, and then gradually integrate them into internal systems. With each additional permission granted, it is necessary to confirm the authorized person, the method for revoking that permission, and the recovery process in the event of an incident. Security platforms can provide control points, but whether these control points are effectively utilized depends on the operating procedures jointly established by business leaders and the security team.

Tip
$0
Like
0
Save
0
Views 18
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
CNBC Daily Market Opening: Potential Diesel Export Ban, Pentagon's War Preparation Plans, and Google's Latest AI Model
U.S. President Trump said he is still "considering" a ban on diesel exports, raising concerns that energy prices may rise further; meanwhile, the market continues to focus on the Middle East situation, the Pentagon's efforts to build the capabilities needed for future wars, and Google has released its latest AI model Gemini 4 Argon.
CNBC
·2026-10-01 10:46:21
17
feedback on Google Android Auto malfunction: Unable to make calls when the small foldable phone is in closed state
Tech media Android Headline reported that Android Auto has recently experienced Bug, causing small foldable phones to be unable to make calls when closed. Google and Motorola have already intervened in the investigation, but no fix has been announced yet.
The Block
·2026-10-01 10:24:15
19
Federal Realty Investment Trust Announces the Release Time of Financial Reports for the Third Quarter of 2026 and Information on the Teleconference
Federal Realty Investment Trust indicates that the third-quarter results for 2026 will be announced before the U.S. stock market opens on Friday, October 30, 2026, and a conference call will be held at 9 a.m. Eastern Time on the same day.
PR Newswire
·2026-10-01 10:24:14
17
Google launches the Gemini 4 Argon flagship AI model, but its practical performance is questioned by employees, according to reports.
According to Bloomberg, Google has begun to gradually roll out Gemini 4 Argon, but some internal employees and informed sources have raised doubts about its actual performance on core tasks such as coding. Google, however, asserts that these claims are inaccurate and states that the model is designed for complex tasks in software engineering, finance, law, and cybersecurity.
The Block
·2026-10-01 10:14:37
25
Tesla Model Model 3 Configuration Upgrade: 16-inch Central Control Screen, Light Gray Premium Interior, New External Power Supply Function Added
Tesla officially announces that all current models of the Model series are now upgraded with 16-inch high-definition touchscreens, and customers can also opt for a light gray premium interior; all models of the Model 3/Y series now come with an additional AC external power supply function, with a maximum power of 2200W. Orders placed before October 31 for the Model 3 will also enjoy a immediate discount of 5000 yuan on the final payment, among other car purchase benefits.
The Block
·2026-10-01 10:14:34
21
View More