Bu makale İngilizce gösteriliyor — çevirisi henüz mevcut değil.

Automation

NVIDIA introduces platform for managing AI agent security

NVIDIA introduces platform for managing AI agent security

Key Takeaways

  • NVIDIA’s Open Agent Safety Platform (OASP) delivers end‑to‑end governance for AI agents—from testing to field deployment.
  • OpenShell creates a secure runtime boundary on CPUs (NVIDIA Vera, Arm, Intel) with < 5 % overhead.
  • Sentry, running on NVIDIA BlueField‑4 DPUs, acts as an out‑of‑band watchdog that can quarantine or halt rogue agents in real time.
  • The platform leverages DOCA for programmable, zero‑trust policy enforcement and attested telemetry.
  • Early adopters include Anthropic, with more enterprises expected to integrate OASP for compliance and safety.

NVIDIA Launches an Open Platform for AI Agent Security

NVIDIA has unveiled the NVIDIA Open Agent Safety Platform (OASP), an open‑source software suite and reference hardware design that lets enterprises enforce security policies across the entire AI‑agent stack—software, compute, and robotics. The platform is positioned as a response to recent incidents where AI agents sidestepped application‑layer controls while executing tasks, highlighting the need for configurable, runtime‑level safeguards.

Governance Across the Agent Stack

OASP is built around three core components that can be mixed‑and‑matched to meet specific operational requirements:

Component Primary Function Host Hardware Notable Specs
OpenShell Secure runtime sandbox for agents on CPUs NVIDIA Vera (AI‑centric CPU) – 8‑core, 2.2 GHz; also supports Arm Neoverse N2 and Intel Xeon Scalable ≤ 5 % CPU overhead, runs outside the model/agent harness
Sentry Out‑of‑band watchdog that monitors, quarantines, or stops agents NVIDIA BlueField‑4 DPU – 8 ARM v8.2 cores, 32 GB HBM2e, 100 GbE NIC Zero‑trust policy enforcement, hardware‑isolated trust domain
DOCA Programmable framework for request inspection, telemetry, and identity verification Integrated in BlueField‑4 DPU Supports up to 10 M ops/sec inspection, attested telemetry signing (RSA‑3072)

OpenShell – A CPU‑Level Security Boundary

OpenShell establishes a runtime boundary that governs how agents invoke functions, regardless of whether the model is open‑source or proprietary. Because it operates outside the agent’s own harness, security teams can impose controls without modifying the underlying AI code. The runtime is lightweight; benchmark tests on the NVIDIA Vera CPU show under 5 % performance impact, making it suitable for latency‑sensitive robotics and edge deployments.

OpenShell’s open‑source nature also allows ports to Arm (Neoverse N2, 2.5 GHz) and Intel (Xeon Scalable, up to 3.1 GHz) platforms, broadening its applicability beyond NVIDIA‑only data centers.

Sentry – DPU‑Based Watchdog

Sentry runs on the BlueField‑4 Data Processing Unit (DPU), an off‑load processor that isolates security functions from the main CPU. By operating in an out‑of‑band fashion, Sentry can monitor agent behavior in real time, generate attested logs, and enforce zero‑trust policies without interfering with the primary compute workload.

Key capabilities include:

  • Behavioral anomaly detection using DOCA‑based inspection pipelines.
  • Quarantine/kill actions triggered when an agent attempts to breach its software boundary.
  • Data‑access protection that enforces per‑agent policies on APIs, storage, and network interfaces.

DOCA – Programmable Zero‑Trust Engine

DOCA (Data Center Operating System for Accelerators) provides the programmable glue that ties OpenShell and Sentry together. It enables:

  • Policy‑driven request filtering (up to 10 M operations per second).
  • Attested telemetry signed with RSA‑3072, supporting compliance audits.
  • Identity verification using hardware‑rooted keys embedded in the Vera CPU and BlueField‑4 DPU.

Early Collaborations and Market Momentum

NVIDIA is already working with Anthropic, the AI research lab behind Claude, to integrate additional safety controls into their agent pipelines. The partnership demonstrates OASP’s flexibility for both large‑scale cloud providers and specialized robotics firms.

Other organizations in the pipeline include:

  • Autonomous‑vehicle manufacturers seeking to lock down perception agents.
  • Industrial IoT operators that need to certify robot‑arm actions against safety standards (e.g., ISO 10218).

Bottom Line

The NVIDIA Open Agent Safety Platform offers a comprehensive, hardware‑anchored approach to AI‑agent security, combining a low‑overhead CPU sandbox (OpenShell) with a DPU‑based watchdog (Sentry) and a programmable zero‑trust framework (DOCA). By delivering open‑source tools that can run on NVIDIA’s Vera CPUs, Arm, and Intel processors, OASP positions itself as a vendor‑agnostic safety net for the expanding ecosystem of autonomous agents. Enterprises that need to meet regulatory, safety, or corporate‑policy requirements now have a scalable, performance‑preserving option to lock down AI agents from the silicon up.

İlgili Makaleler