THE CRUNCH
NVIDIA says AI security is an engineering problem that needs enforceable controls, clear ownership and evidence that protections work, rather than relying on the model itself. The company argues that security depends on the full agent stack, from models and harnesses to runtime environments, and that each layer carries specific responsibilities. NVIDIA emphasises that agents must operate within defined boundaries, so
NVIDIA emphasises that agents must operate within defined boundaries, so even if an agent makes a wrong decision, the environment should still block unauthorised actions like exporting customer data. The company also highlights the need for traceable identities and credentials limited to an agent’s assigned task, as well as protected logs that capture attempted tool calls and outcomes for investigation.
To enforce these controls, NVIDIA points to its open source OpenShell runtime, which sits outside the agent’s reach to sandbox execution and govern access to data, network and system resources. Partners like Cisco and JFrog are building on OpenShell to add governance layers and scan agent skills. NVIDIA also stresses that teams need evidence of security before deployment, such as testing that controls block attempts to obtain credentials beyond an agent’s scope or send sensitive data to unauthorised destinations. Tools like CrowdStrike’s SafeMind and Palo Alto Networks’ Prisma AIRS are cited as examples of continuous red teaming that can verify fixes and uncover vulnerabilities.
Finally, NVIDIA argues that defenders need the right tools at the right time, including both open and closed models, to investigate failures and reproduce attacks. The company advocates for open work sharing, where evidence of what failed and how fixes were verified helps the broader security community strengthen their own systems. NVIDIA’s security research and the Open Secure AI Alliance are presented as ways to bring research, practical tools and expertise into the community, shifting the advantage toward defenders.
Why It Matters: The shift from treating AI security as a model problem to an engineering problem could change how organisations build and deploy AI agents. By emphasising enforceable boundaries and shared evidence, NVIDIA is pushing for a more practical, defensive approach that prioritises containment and investigation over relying on the model’s inherent safety.


