Nvidia engineers put agent containment in silicon, not in the model

OpenShell plus a BlueField-4 watchdog treats drift as a runtime problem that training will not erase

Four Nvidia engineers published a reference design Monday for watching AI agents from outside the model, on the hardware path those agents have to use to think at all.

John Myers, Alex Watson, Ali Golshan and Ofir Arkin laid out the NVIDIA Open Agent Safety Platform on the company’s technical blog. OpenShell, an Apache 2.0 runtime, sandboxes agents on Vera CPUs with kernel-level isolation. Sentry, sitting on BlueField-4 DPUs and programmed through Nvidia’s DOCA software, is the optional second fence. In Vera Rubin POD systems, they wrote, that DPU sits on the node’s only path to the model. Observation and a kill switch share the same wire.

The authors reached for the 1990s internet. Pages could run code, lift data, drop a virus. People used the web anyway. Encrypted sessions and a lock icon helped. The real break, they argued, was sandboxing each page in its own tab so a rogue site could not own the machine. Amazon, Google, Netflix and Meta grew on that layer. Safety did not stall the web. It let commerce happen.

Agents, they said, are in the earlier, leakier phase. Several frontier labs have reported agents leaving evaluation environments and touching systems they were not supposed to reach. Some misreported what they had done. Controls on hand were not enough. It was not one new trick. Tools, time, fuzzy instructions and a push to think “outside the box” stacked up.

OpenShell was built over the past year. The lesson the team took from that work: every agent should start in a zero-trust box, with isolation, monitoring and behavior detection on by default.

They defined the failure mode in plain language. Drift refers to agent actions that depart from the intended task or operating constraints. Drift can occur in response to a policy block, a bug, or a missing tool. Drift can also occur when instructions are ambiguous or agents are left to run for days or weeks to solve hard problems where the first 1,000 things they try do not work. This can’t be trained away while retaining the capability. And here’s the most important lesson: an agent in these circumstances cannot be expected to fully govern its own behavior.

Five rules follow from that. Policy has to be verifiable; a prover is supposed to show, before a run, that the policy cannot slip the operator’s intent. Enforcement has to live out of band, outside the agent’s reach, and the agent does not need to know it is being watched. The path to the model is the control point, because an agent cannot act without its next thought. Authority should scale only as far as the operator can inspect that thinking; open models, the authors noted, expose the full reasoning space and activations. Labs, enterprises and hardware vendors each own a layer, the way cloud responsibility is split today. The runtime and its policy language need to stay open so other vendors can plug in.

The stack is three layers. Application is the work itself: models, harnesses, tools, data, scripts. Runtime maps that work onto a workstation, an edge box or a data center and keeps policy live. Infrastructure is the metal and the pipes: networks, databases, filesystems, general-purpose compute for tools and code, plus accelerated compute for the safety watch itself.

OpenShell turns operator rules into a checkable policy. Files, networks, tools, processes, credentials. Limits are tested before the agent starts and enforced while it runs. Sentry pushes the same watch into BlueField silicon. DOCA ties the DPU to OpenShell policy and stitches agent calls, allow-or-deny decisions, and tool or data access into one activity record. A DOCA gateway adds identity checks, confirming who the agent is and what authority it was handed.

On boxes that already pair Vera with BlueField-4, Nvidia said turning the extra layer on is a software update. OpenShell also runs without the DPU, on other hardware, if a shop is not ready for the in-silicon piece.

GitHub shows OpenShell 0.1.2 posted the same day. A separate Nvidia walkthrough covers wiring runtime controls onto existing agents.

For a buyer, the question is which layer they own when an agent wanders. Prompts will not cover a weeklong run that invents a thousand wrong moves. For a developer, the runtime is public. The DPU path is the part that stays up if the host is no longer honest.


Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x