Skip to main content
Security

Nvidia Builds a Security Layer for AI Agents

As enterprises race to deploy autonomous AI agents, Nvidia is pushing security deeper into the AI stack, arguing that agents cannot be trusted to police

2 min read0 views
Nvidia Builds a Security Layer for AI Agents
Share

As enterprises race to deploy autonomous AI agents, Nvidia is pushing security deeper into the AI stack, arguing that agents cannot be trusted to police their own behaviour. Its new Open Agent Safety Platform brings together more than 100 technology, research and public-sector organisations around a layered approach to agent security.

AI agents represent a different security challenge from traditional applications. They can reason, execute code, access databases, call APIs, use credentials and communicate with other systems—sometimes operating independently for extended periods. That combination dramatically increases the potential impact of compromised, manipulated or misbehaving agents.

Nvidia's architecture separates agent intelligence from security enforcement. The company describes three fundamental layers: application, runtime and infrastructure. While the application contains models, tools and data, the runtime determines what an agent is permitted to access, and infrastructure provides an additional enforcement boundary.

At the centre is NVIDIA OpenShell, an open-source secure runtime. Each agent operates inside an isolated sandbox, with access to files, networks, processes, tools and credentials governed by policy. Access is denied by default and permissions are granted according to predefined rules.

The second component, NVIDIA Sentry, moves monitoring further down into infrastructure. Running separately on BlueField-4 DPUs, Sentry can observe agent behaviour independently of the host environment and enforce security policies even when the agent or host itself cannot be fully trusted.

This separation is significant. Prompt-level instructions and model guardrails can influence what an agent should do, but infrastructure controls determine what it actually can do. Nvidia's model therefore applies traditional Zero Trust principles—least privilege, isolation, explicit authorization and auditability—to autonomous AI.

The platform can also correlate agent interactions, policy decisions, tool usage and data access, creating contextual activity records. If an agent begins drifting beyond its intended task, organizations can potentially identify the behaviour, investigate it and intervene before greater damage occurs.

The ecosystem is substantial. Nvidia says organizations working with the technologies include Microsoft, Cisco, CrowdStrike, Palo Alto Networks, IBM, SAP, ServiceNow, Deloitte, Accenture, Hugging Face, Scale AI and others. SAP is integrating OpenShell with Joule Studio, while Salesforce and Nvidia have integrated it with Slack to support visibility and human approval of additional agent permissions.

For cybersecurity vendors, this signals the emergence of a new product category: AI Agent Security and Runtime Governance. Traditional IAM, DLP, SIEM, SOAR and application security will increasingly need to understand not only human and machine identities, but also what autonomous agents are authorized to read, generate, transmit and execute.