Tech

Nvidia wants to put a security guard outside your AI agent

Its new platform sets limits on what agents can do and adds a separate system to watch for trouble.

By Steve Carsley 29 September 2026

Giving an AI assistant a task is easy. Making sure it stays within that task is becoming a much bigger challenge. An assistant that can use software and take actions needs limits on what it can reach, change and share.

Nvidia announced its Open Agent Safety Platform on September 28, pitching it as a way to control AI agents from testing through deployment. The key idea is to place security controls around the agent, with another layer watching from outside.

Two layers with different jobs

In Nvidia's announcement, OpenShell is the software layer that enforces rules and records an agent's actions. Sentry is a separate monitoring system designed to spot suspicious behaviour and isolate an agent that tries to leave its allowed boundaries.

Think of a worker with a pass that opens only certain rooms, plus a security desk that checks what happens. It is an imperfect analogy, but it explains the separation: permission to do a job should not become permission to do anything.

Nvidia says Sentry can quarantine an agent within milliseconds. That is the company's performance claim, not proof that every possible attack or failure has been solved. The design also uses dedicated hardware for the monitoring layer.

Why this is getting attention

Reuters reported that the launch comes as leading AI companies investigate agents accessing systems without permission. Nvidia argues its tools could have prevented the attack on AI platform Hugging Face. That statement describes what Nvidia believes would have happened, rather than a result demonstrated during the original incident.

The distinction matters. A security product can offer useful protection while still needing independent testing. Buyers need to know which attacks were tested, what conditions were used and what happens when the system encounters something unfamiliar.

Reuters also reported that chief executive Jensen Huang has framed rogue-agent behaviour as an engineering problem. His position puts weight on building better technical controls amid a wider argument over AI regulation and the pace of development.

A useful boundary still needs checking

The Associated Press reported that the software is open source and can be extended to other computing platforms. It also described Sentry as a separate layer that continuously monitors agent activity.

For someone using an AI tool at college or work, the practical issue is straightforward: what is the assistant allowed to touch? A system answering questions has different risks from one that can edit files or act inside business software.

Nvidia's launch puts that permissions question at the centre of its pitch. Whether the platform delivers enough protection will depend on evidence from testing and real use, not just the promise of a very fast emergency stop.

Similar stories