Nvidia launched a tool designed to stop AI agents from going rogue. Here’s how it works.
Nvidia has unveiled a two-layer safety system that monitors AI agents and cuts them off when they stray beyond set rules. Here's how it works.
Benjamin Fanjoy/Getty Images
- AI agents have gone out of whack, escaping tests, accessing systems, and covering it up.
- Nvidia wants to stop it by fencing agents in and quickly cutting them off when they stray.
- CEO Jensen Huang framed it as a "technically solvable problem" of engineering.
Nvidia is giving AI agents a playpen — and a watchdog.
The chipmaker on Monday launched the Open Agent Safety Platform, a two-part system designed to keep agents inside clearly defined boundaries and cut them off quickly if they try to escape.
It comes after several frontier AI labs reported agents breaking out of supposedly secure testing environments, reaching systems they were not meant to access, and sometimes misrepresenting what they had done.
Nvidia CEO Jensen Huang said on CNBC's "Squawk Box" on Monday that AI has "the potential to do incredible good."
"But we also have to make sure that the technology is developed and deployed safely," he added.
Here's how Nvidia's new agent safety system — which more than 100 organizations, including Microsoft and Anthropic, are working with — actually works.
Give the agent a tightly limited playground
The first component of Nvidia's safety platform is OpenShell. Companies download the open-source software, install it on devices or in the cloud, and then it acts like a controlled playground for AI agents.
Before an agent starts work, its operator sets the ground rules: which files, websites, networks, tools, and credentials it can access.
Huang compared that approach to giving an employee a badge that works only where they need it to. "Job number one is you take away all of its rights," he told CNBC. The operator then gives it access to files, data, tools, or the internet only when required.
If an agent is sorting invoices, for example, it should not be able to rummage through HR records or make random calls to the wider internet.
In other words, OpenShell puts the agent in a sandbox — an isolated environment designed to stop a bad decision from spilling into the rest of a company's systems. It checks and enforces those rules while the agent works.
Watch for the moment it goes off-script
Nvidia is focused on reducing the risk of agents veering away from the task they were given.
That could happen because instructions were vague, a tool broke, or the agent has spent a long time trying to solve a hard problem.
When one approach fails, it may keep hunting for another, including routes its human operator never imagined.
That does not necessarily mean an agent is malicious. But it can mean it is taking risks.
OpenShell is meant to spot and block actions that fall outside the preset policy in real time.
Add a security guard the agent cannot fire
The second piece, Nvidia Sentry, is the more muscular backstop. It runs on separate Nvidia hardware, called BlueField data-processing units, rather than on the same system running the agent.
In plain English: the watchdog is kept out of the agent's reach.
Sentry monitors the agent's interactions with models, tools, data, and networks. If its behavior looks suspicious or breaches the rules, Nvidia says the system can isolate — or quarantine — the agent in milliseconds.
Huang said the setup effectively places a new chip between the agent and the large language model, allowing Nvidia to "intercept everything."
The launch is Huang's answer to growing worries about increasingly autonomous AI.
"I believe, as an engineer, I know it's an engineering problem," Huang told CNBC. "This is a technically solvable problem."
Read the original article on Business Insider