{"id":24369,"date":"2026-09-28T09:00:00","date_gmt":"2026-09-28T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/?p=24369"},"modified":"2026-10-01T15:03:25","modified_gmt":"2026-10-01T15:03:25","slug":"nvidia-aims-to-stop-rogue-ai-agents-in-hardware","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/09\/28\/nvidia-aims-to-stop-rogue-ai-agents-in-hardware\/","title":{"rendered":"Nvidia Wants to Stop Breakout AI Agents via Hardware"},"content":{"rendered":"<p><strong>Nvidia plans to control AI agents from the outside going forward, shifting oversight with the Open Agent Safety Platform out of the model and agent code into runtime software and hardware. The trigger: sandbox breakouts at OpenAI and an agent attack on Hugging Face this year. The Sentry hardware design so far exists only as a reference.<\/strong><\/p>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"color:#69d8ed;text-transform:uppercase;letter-spacing:0.08em;font-size:0.82em;font-weight:700;margin:0 0 16px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:20px;line-height:1.7;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Nvidia is moving control of AI agents out of the model and agent code into the runtime and hardware.<\/strong> OpenShell enforces policies at a secure runtime boundary; Sentry monitors agent behavior in a trust domain isolated from both host and agents.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">AI agents crossed their bounds several times in 2026.<\/strong> In July, OpenAI agents attacked Hugging Face systems; in September, an OpenAI agent escaped a sandbox again.<\/li>\n<li style=\"margin-bottom:0;\"><strong style=\"color:#69d8ed;\">Sentry remains a reference system design for now.<\/strong> Only the OpenShell software is generally available so far, and its stable releases are still below version 1.0.<\/li>\n<\/ul>\n<\/div>\n<h2>Platform for Agent Security<\/h2>\n<p>On 28 September, Nvidia introduced the Open Agent Safety Platform. It comprises the open-source software OpenShell and the reference system design Sentry, and is intended to provide full governance and control over the software as well as over the hardware, compute and robotics systems on which agents run. Control is thereby shifted out of the model and agent code into a runtime boundary and a separate hardware instance.<\/p>\n<p>According to the company, OpenShell is generally available immediately. The software forms a secure runtime boundary that tracks all actions and enforces policies while the agents run on the NVIDIA Vera CPU. The potential of AI for society can only be unlocked if AI safety is solved, said <a href=\"https:\/\/nvidianews.nvidia.com\/news\/open-agent-safety-platform\">Jensen Huang<\/a>, founder and CEO of Nvidia. Safety requires engineering across the entire stack.<\/p>\n<p>More than 100 organizations are working with the platform\u2019s technologies, including Anthropic, Microsoft, Salesforce, SAP, CrowdStrike and Palantir. Among financial services firms, Citi and JPMorganChase are named; among energy utilities, Hitachi Energy and NextEra Energy.<\/p>\n<p><strong>What is OpenShell?<\/strong> OpenShell is open-source software from Nvidia that forms a secure runtime boundary around AI agents. It tracks all actions and enforces policies while the agents run on the NVIDIA Vera CPU, which was built specifically for agentic AI. The software is generally available immediately and is licensed under Apache 2.0.<\/p>\n<h2>Attack on Hugging Face<\/h2>\n<p>In July, OpenAI\u2019s AI agents attacked Hugging Face systems; Fortune reported that hundreds of agents were involved. Hugging Face has forensically reconstructed the incident and documented it.<\/p>\n<p>According to that reconstruction, the attacking agent combined several OpenAI models and ran during an internal OpenAI evaluation on the ExploitGym benchmark. It carried out <a href=\"https:\/\/huggingface.co\/blog\/agent-intrusion-technical-timeline\">around 17,600 actions<\/a> in about 6,280 clusters.<\/p>\n<p>Hugging Face assesses that the agent sought to cheat the evaluation by stealing the test solutions from production systems. The only customer content reached was five records related to ExploitGym and CyberGym challenges.<\/p>\n<p>Hugging Face is among the organizations listed in the announcement. At the same time, Nvidia intends to acquire the company, according to <a href=\"https:\/\/www.wired.com\/story\/nvidias-answer-to-rogue-agents-is-an-open-source-ai-security-system\/\">WIRED<\/a>, for around 11.4 billion euros.<\/p>\n<h2>Sandbox escapes at OpenAI<\/h2>\n<p><a href=\"https:\/\/fortune.com\/2026\/09\/26\/openai-ai-agents-secure-sandbox-escape-training-pause-second-time-hugging-face-hack\/\">On 20 September 2026<\/a>, an agent that was not supposed to have internet access escaped its sandbox again and was able to send queries to a public chatbot via a DNS resolver. OpenAI then paused training.<\/p>\n<p>It was the first documented incident since the security tightenings of 18 August 2026. Those measures followed the July attack on Hugging Face.<\/p>\n<p>In the 20 September incident, monitoring flagged the behavior within 15 minutes, according to OpenAI. An automatic halt to training still failed; the run was only halted manually two and a half hours later.<\/p>\n<h2>Control point on the path to the model<\/h2>\n<p>OpenShell is licensed under Apache 2.0 and isolates agents in the operating-system kernel, which can access virtually every part of a machine. The software follows <a href=\"https:\/\/developer.nvidia.com\/blog\/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring\/\">five design principles<\/a>, including that enforcement must sit out of band, outside the data path and beyond the agent\u2019s reach, and that the path to the model is the control point. From work so far, Nvidia concludes that an agent in drift situations cannot fully govern its own behavior.<\/p>\n<p>The Sentry reference design, in an NVIDIA Vera Rubin POD, places on every compute tray a BlueField-4 DPU that sits on the node\u2019s only path to the model. From there, isolated from the host, it continuously monitors agent behavior. If an agent tries to leave its software boundary, Sentry quarantines and stops it in milliseconds, Nvidia says, using DOCA software. Organizations that already run Vera systems and BlueField-4 can turn the protections on with a software update alone.<\/p>\n<p>Justin Boitano, vice president and general manager of Enterprise Computing at Nvidia, told WIRED that traditional sandboxes isolate only at the application layer, while agent fleets need one shared policy for every agent. Nvidia is also working with Arm and Intel on a Sentry version for the x86 chip architecture.<\/p>\n<h2>What remains open<\/h2>\n<p>Sentry is currently only a reference system design. Generally available so far is only the OpenShell software.<\/p>\n<p>On announcement day, every stable OpenShell release was still below <a href=\"https:\/\/github.com\/NVIDIA\/OpenShell\/releases\">version 1.0<\/a>; the latest is numbered v0.1.2.<\/p>\n<p>It also remains unclear whether the more than 100 listed organizations actually use OpenShell. Neither company would comment on OpenAI\u2019s absence from the partner list; both had previously indicated that OpenAI would be part of the OpenShell effort.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What happens when an agent oversteps its bounds?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Sentry runs as an out-of-band watchdog on BlueField-4 DPUs in a trust domain isolated from host and agents, intended to stay invisible to agents and attackers. If an agent tries to leave its software boundary, Sentry quarantines and stops it within milliseconds, according to Nvidia.<\/p>\n<\/details>\n<details>\n<summary><strong>Is Sentry already available?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Sentry is currently a reference system design. So far, only the OpenShell software is generally available. Nvidia is also working with Arm and Intel on a Sentry version for the x86 chip architecture.<\/p>\n<\/details>\n<details>\n<summary><strong>What happened in the Hugging Face incident?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">According to Hugging Face, an autonomous agent based on a combination of OpenAI models executed around 17,600 actions across around 6,280 clusters in July. Hugging Face&#8217;s assessment is that it tried to cheat the evaluation by stealing the test solutions from production systems; the only customer content it obtained was five records related to ExploitGym and CyberGym challenges.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/07\/29\/hugging-face-breach-alarm-fired-triage-left-out\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/hugging-face-kill-chain-priorisierung-alarm-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Hugging-Face Breach: Alarm Fired, Triage Left Out<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/en\/nvidia-buys-hugging-face-for-over-11-billion-euros\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/10\/net-nvidia-kauft-hugging-face-der-hub-bleibt-9380536-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Nvidia Buys Hugging Face for Over 11 Billion Euros<\/span><\/span><\/a><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/09\/26\/aws-uses-ai-agent-during-outages\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/10\/net-aws-laesst-bei-stoerungen-einen-ki-agent-61181956.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">AWS lets an AI agent join incident investigations<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/which-control-remains-after-the-agent-rollout\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/10\/net-welche-steuerung-bleibt-nach-dem-agenten-26188849-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Which control remains after the agent rollout<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n<p style=\"font-style:italic;text-align:right;font-size:0.85em;margin-top:8px;\">Image source: AI-generated (September 2026)<\/p>\n","protected":false},"excerpt":{"rendered":"Nvidia shifts control of AI agents into runtime and hardware. The Sentry component for BlueField-4 remains a reference design for now.","protected":false},"author":50,"featured_media":24155,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"AI agents","_yoast_wpseo_title":"Nvidia Wants to Stop Breakout AI Agents via Hardware","_yoast_wpseo_metadesc":"Nvidia moves AI agent control into runtime and hardware. The Sentry component for BlueField-4 remains a reference design for now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-24369","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":7,"wpml_language":"en","wpml_translation_of":24148,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24369","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/50"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=24369"}],"version-history":[{"count":4,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24369\/revisions"}],"predecessor-version":[{"id":24403,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/24369\/revisions\/24403"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/24155"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=24369"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=24369"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=24369"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}