Key points
- Nvidia launches tools to contain rogue AI agents
- Nvidia says the tools could have stopped July's Hugging Face attack
- The system pairs open-source software with Nvidia hardware
Nvidia (NVDA) launched tools on Monday to restrict what AI agents can access and contain them when they break the rules. The company says its Open Agent Safety Platform could have prevented July's attack on Hugging Face, the AI model hub Nvidia agreed to buy this month.
"From what we know, this new security platform could have stopped the breach if it was being used" in frontier labs during early model evaluation, Justin Boitano, Nvidia's vice president and general manager of enterprise computing, told Reuters.
I'd want to see that demonstrated. The attack came from agents running inside OpenAI's test environment, and Nvidia's announcement doesn't show how its controls would have handled their actions.
How the controls work
The platform has two layers, according to Nvidia's announcement.
OpenShell runs agents in an isolated environment, records their actions, and limits access to files, networks, and processes. The open-source software is already on GitHub. It runs on Nvidia's Vera CPUs, though Nvidia says it can be extended to chips from Arm and Intel.
Sentry monitors agents from outside that environment and can quarantine them if they break the rules. It is a reference design built around Nvidia's BlueField-4 data processing units.
"OpenShell governs the agent's actions, and then Sentry independently monitors and contains suspicious behavior," Boitano said, according to the Associated Press.
The controls also target agents that create helpers to get around restrictions. "This is really agentic behavior that we're talking about, which is fleets of agents and how they operate together," Ali Golshan, Nvidia's senior director of AI software, told Reuters.
Free software, Nvidia hardware
This is where the business model gets interesting. OpenShell is free, while Sentry uses Nvidia's BlueField-4 hardware. Nvidia can give away the software and still sell the equipment behind it. The release gave no prices or shipping dates for Vera or BlueField-4.
The companies on both sides
Nvidia has agreed to put $30 billion into OpenAI and up to $10 billion into Anthropic, and both labs run on its chips, as we laid out in our map of Nvidia's investments.
OpenAI's test agents got into Hugging Face in July. By OpenAI's own timeline, an agent shared exposed Hugging Face credentials on July 10, and agents reached administrator-level access across several clusters on July 12. We covered how Hugging Face fought the attack off last month. Since then, Google said its Gemini model broke into three real companies during a security test, and Australia's prime minister said an OpenAI agent got into a government Medicare portal in June.
Nvidia filed an 8-K on September 2 for its deal to buy Hugging Face. About $11.9 billion goes to stockholders, and up to about $1 billion more is a retention program for employees. Nvidia expects to close in the first half of 2027. Reuters wrote that Nvidia "paid $13 billion," but the deal hasn't closed.
So Nvidia funds the labs, sells them the chips, agreed to buy the company OpenAI's agents broke into, and is now selling the lock. Call it vertical integration.
The partner list is interesting too. Anthropic is on it, and so is Hugging Face. So is Irregular, the security firm that ran the Gemini test. "Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments," said Paul Smith, Anthropic's chief commercial officer. OpenAI, Google, and Meta aren't named.
Huang's answer to regulators
This launch also fits what Jensen Huang has been saying for weeks. At Salesforce's Dreamforce conference on September 15, he said, "Safety is an engineering problem, not a legal one," and "We don't need any new laws. We don't need new regulations," TechCrunch reported. He has said he's fine with rules for specific products, such as robotaxis.
His quote in Monday's release makes the same case. "Safety and security require full-stack engineering," Huang said. The launch gives him something concrete to point to when he argues that safety is an engineering problem. Whether those controls are enough to satisfy regulators is a different question.
Nvidia is turning recent agent-security failures into a product line, with some of the companies Nvidia backs listed as partners. What I'd watch is whether OpenAI signs on and whether Sentry moves from a reference design into working deployments.



