{"id":9605,"date":"2026-09-29T01:06:28","date_gmt":"2026-09-29T01:06:28","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9605"},"modified":"2026-09-29T01:06:28","modified_gmt":"2026-09-29T01:06:28","slug":"nvidia-releases-open-agent-safety-platform-to-monitor-and-govern-agentic-ai","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9605","title":{"rendered":"Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will secure agents \u201cfrom testing to deployment.\u201d <\/p>\n<p class=\"wp-block-paragraph\">But while the Nvidia design\u2019s silicon-based component provides some cybersecurity advantages, analysts argued that it cannot help with the vast majority of agentic problems.<\/p>\n<p class=\"wp-block-paragraph\">Nvidia\u2019s offering leverages its OpenShell software and promises \u201cfull-stack governance and control across the software and the hardware, compute, and robotics systems that run agents,\u201d the company said <a href=\"https:\/\/nvidianews.nvidia.com\/news\/open-agent-safety-platform\" target=\"_blank\" rel=\"noopener\">in a news release<\/a>. \u201cOpenShell software provides a secure runtime boundary that traces all actions and enforces policy as agents run on Nvidia Vera CPUs. As open source software, OpenShell can be extended to work with third-party compute platforms, including those from Arm and Intel.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The Open Agent Safety Platform reference system design features <a href=\"https:\/\/developer.nvidia.com\/blog\/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring\/\" target=\"_blank\" rel=\"noopener\">NVIDIA Sentry<\/a>, an out-of-band watchdog that runs on <a href=\"https:\/\/www.nvidia.com\/en-us\/networking\/products\/data-processing-unit\/\" target=\"_blank\" rel=\"noopener\">NVIDIA BlueField-4<\/a> DPUs to continuously monitor agent behavior. \u201cSentry provides in-silicon security enforcement, meaning that if an AI agent attempts to move outside its software boundary, Sentry quarantines and stops it in milliseconds,\u201d the release stated.<\/p>\n<p class=\"wp-block-paragraph\">In a <a href=\"https:\/\/developer.nvidia.com\/blog\/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring\/\" target=\"_blank\" rel=\"noopener\">developer blog post<\/a> focusing on the details of its \u201csafety platform,\u201d Nvidia described its approach as a \u201csecure runtime that executes autonomous AI agents in sandboxed environments with kernel-level isolation\u201d and argued that \u201can advantage of open models is that the entire reasoning space and activations are all visible.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Components of the platform are being rolled out by an extensive list of partners, including Citi Group, JPMorganChase, Citi, Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI.<\/p>\n<h2 class=\"wp-block-heading\">A step in the right direction<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.gartner.com\/en\/experts\/lauren-kornutick\" target=\"_blank\" rel=\"noopener\">Lauren Kornutick<\/a>, a senior director analyst at Gartner, mostly applauded the Nvidia effort, saying that it is \u201csolving a problem from an interesting perspective, at the hardware level. It\u2019s a great step in the right direction.\u201d<\/p>\n<p class=\"wp-block-paragraph\">But Kornutick said that she was less impressed with the published list of supporters, observing, \u201csome major players are notably missing,\u201d including OpenAI, Amazon, and Google.<\/p>\n<p class=\"wp-block-paragraph\">Other analysts and consultants said that the technical implementation is impressive and offers distinct benefits, but they stressed that it also misses the big picture in terms of what enterprise CISOs are truly struggling with when trying to manage and secure autonomous agents.\u00a0<\/p>\n<h2 class=\"wp-block-heading\">Limitations<\/h2>\n<p class=\"wp-block-paragraph\">The biggest challenge is that enterprise environments are flooded with agents that have not been approved by either IT or cybersecurity teams. Typically, <a href=\"https:\/\/www.csoonline.com\/article\/4215449\/zero-trust-has-a-big-ai-agent-problem-ahead.html\" target=\"_blank\" rel=\"noopener\">those teams are not even aware of the credentialed agents<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe limit is coverage,\u201d said <a href=\"https:\/\/www.controlrisks.com\/who-we-are\/our-experts\/expert-bio\/brian-levine\" target=\"_blank\" rel=\"noopener\">Brian Levine<\/a>, a partner with consulting firm Control Risks. \u201cThese controls govern agents you deploy on infrastructure you control. They do nothing for the agent a business unit spun up on a SaaS platform, the one embedded in a vendor\u2019s product, or the one an attacker brings with them. You can\u2019t hold an agent to a policy if you don\u2019t know it exists. Discovery and inventory come first and that is a governance challenge as much as a technical one.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/akm76\/\" target=\"_blank\" rel=\"noopener\">Aman Mahapatra<\/a>, chief strategy officer for Tribeca Softech, a New York City-based technology consulting firm, agreed about the limitations of the Nvidia offering.<\/p>\n<p class=\"wp-block-paragraph\">\u201cEnforcement only applies to agents running inside the governed runtime,\u201d he said. \u201cRuntime governance protects the agents you already know about, which is the population that needed it least.\u201d<\/p>\n<p class=\"wp-block-paragraph\">However, Mahapatra said, that doesn\u2019t mean that the effort is futile.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThis has a meaningful chance of making things materially better for one specific reason: Sentry runs out-of-band on BlueField-4 DPUs, in an isolated trust domain Nvidia describes as invisible to agents and attackers,\u201d he said. \u201cYou cannot reason your way around a control you cannot perceive, and you cannot talk a DPU out of enforcing a policy. Probabilistic reasoning has to be sandwiched between deterministic layers the model cannot influence, with an oversight function that reads everything and writes nothing. Sentry is that principle pushed down into silicon and silicon is the right place for it.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/my.idc.com\/getdoc.jsp?containerId=PRF006018\" target=\"_blank\" rel=\"noopener\">Brent Ellis<\/a>, VP, AI Infrastructure at IDC, agreed. He estimated that it addresses \u201cprobably less than 25%\u201d of enterprise agentic cybersecurity problems.<\/p>\n<h2 class=\"wp-block-heading\">Lock-in risk<\/h2>\n<p class=\"wp-block-paragraph\">He added that there is a vendor lock-in element to the offering as well. Although Nvidia today controls a massive, almost monopolistic market share for AI hardware among enterprises, Ellis said that he expects those numbers to drop, because \u201ccompetitors are starting to emerge as viable,\u201d especially hyperscalers who have invested in designing their own silicon.<\/p>\n<p class=\"wp-block-paragraph\">But for enterprises that are overwhelmingly Nvidia shops, the hardware approach could make a lot of sense, Ellis said.\u00a0But will the Nvidia platform have a good chance at making enterprise agentic cybersecurity materially better?<\/p>\n<p class=\"wp-block-paragraph\">\u201cYes, for the agents that run inside it,\u201d he said. \u201cThat is a big \u2018if,\u2019 though. There is a lot of agent infrastructure that is not Nvidia, and architectures in place prior to Vera and Bluefield are limited in which elements of the platform they can adopt.\u201d<\/p>\n<p class=\"wp-block-paragraph\">With that caveat, Ellis said the news starts to look good. \u201cIn environments where you can adopt all the elements, then you can move enforcement out of the model and the application layer, where agents have repeatedly talked or coded their way around controls. And you can then move enforcement into the runtime and the silicon, which is a harder barrier. Sentry specifically makes the DPU a traffic cop that is harder to bypass.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Then again, he noted, some attacks can still leverage governance weaknesses.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cLook at how the recent OpenAI incidents unfolded,\u201d he pointed out. \u201cThe agents didn\u2019t break the sandbox wall. They walked through a Swiss cheese of environment security: Shared package repositories used as message boards, services that fetched internet content on the agent\u2019s behalf, and unpatched flaws in adjacent systems.\u201d<\/p>\n<h2 class=\"wp-block-heading\">Avoids strategic mistakes<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/frankdickson\/\" target=\"_blank\" rel=\"noopener\">Frank Dickson<\/a>, principal analyst at Dickson Research, said he likes Nvidia\u2019s platform because it avoids some of the strategic mistakes made by those trying to secure agentic systems in the past.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cFor two years, this industry has tried to secure agents by asking them to behave, with guardrails bolted into the prompt, the model, and the harness. That approach was always going to lose,\u201d he said. \u201cNvidia finally puts enforcement where it belongs: outside the agent, in the kernel, in a proxy that inspects every outbound request and in silicon the agent cannot see or touch. You don\u2019t ask the prisoner to lock his own cell. Every serious agent platform will have to match this design.\u201d<\/p>\n<p class=\"wp-block-paragraph\">Dickson said Nvidia\u2019s approach does not try to stop a misbehaving agent after it is caught, but instead tries to prevent the problem from occurring.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cOpenShell checks each outbound request against policy before it leaves the sandbox, and its policy prover checks the permissions before the agent runs at all,\u201d Dickson said. \u201cNvidia claims Sentry quarantines a misbehaving agent in milliseconds.\u201d<\/p>\n<p class=\"wp-block-paragraph\">That contrasts with the time it took to address the <a href=\"https:\/\/www.csoonline.com\/article\/4227777\/openai-pauses-ai-model-training-after-another-agent-bypasses-network-restrictions.html\" target=\"_blank\" rel=\"noopener\">latest agentic problems reported by OpenAI<\/a>, in which an OpenAI agent bypassed network restrictions to communicate with an external chatbot.\u00a0\u201cIt took a human reviewer just three minutes to acknowledge the DNS alert the system did generate, but it was another two-and-a-half hours before the training run was stopped,\u201d OpenAI reported.\u00a0<\/p>\n<h2 class=\"wp-block-heading\">Not a panacea<\/h2>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/acceligence.com\/talent\/profiles\/justin-greis\/\" target=\"_blank\" rel=\"noopener\">Justin Greis<\/a>, CEO of consulting firm Acceligence, also agreed that the Nvidia approach is solid, but he stressed that AI agents have a well-earned reputation for figuring out ways around such restrictions.\u00a0\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe should assume increasingly capable agents will probe boundaries, discover unintended pathways and exploit ambiguity. Security cannot depend upon the agent deciding not to do that,\u201d he said. \u201cBut even hardware-enforced controls are only as good as the boundary and policy we give them.\u201d<\/p>\n<p class=\"wp-block-paragraph\">He pointed out that an agent does not necessarily need to evade a security control if the user accidentally authorizes a legitimate path that produces a dangerous outcome. \u201cMisconfigured permissions, excessive authority, combinations of individually harmless capabilities, compromised third parties and activity occurring outside the governed environment remain very real problems,\u201d he said.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Nvidia on Monday rolled out an agentic governance system called the Open Agent Safety Platform that combines software with out-of-band DPU-based silicon in a reference system design that it says will secure agents \u201cfrom testing to deployment.\u201d But while the Nvidia design\u2019s silicon-based component provides some cybersecurity advantages, analysts argued that it cannot help with [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9606,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9605","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9605"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9605"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9605\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9606"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9605"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9605"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9605"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}