Lifestyle

NVIDIA Says AI Agent Security Is an Engineering Problem: Controls at Every Layer, from the Model to Where Actions Run

On September 21, 2026, NVIDIA's official blog argued that securing AI agents (AI programs that can use tools and take actions on someone's behalf) takes engineering, not good intentions: limits enforced at every layer, minimal permissions, human approval, continuous testing and open tools. Here is what NVIDIA proposes and what it means for organisations using agents and the people whose data they handle.

About 7 min read

NVIDIA Says AI Agent Security Is an Engineering Problem: Controls at Every Layer, from the Model to Where Actions Run
Image: Mokaair (Original editorial artwork)

What happened: NVIDIA proposes an engineering framework for AI agent security

On September 21, 2026, NVIDIA's official blog published "AI Security Is an Engineering Problem," written by Saša Zdjelar. The post opens by stating that "AI security is an engineering problem" and makes this concrete with four elements: clear security requirements, enforceable controls, named owners, and evidence that the protections are effective. NVIDIA argues that as AI capabilities grow, the industry must speed up security engineering, broaden access to defensive tools, and share what works more quickly.

According to NVIDIA, the internet and the cloud changed how software runs, but the core security responsibilities did not change: establishing identity, controlling access, limiting exposure, and verifying that protections work. What is new about AI agents is that they can reason, use tools, and adjust their actions based on the data they encounter. The post also acknowledges that organizations want the productivity gains of AI, while practices for governing and protecting such systems are still developing.

NVIDIA Says AI Agent Security Is an Engineering Problem: Controls at Every Layer, from the Model to Where Actions Run
Mokaair editorial verification flow · Image: Mokaair (Original editorial artwork)
Read the full description

Sources are collected, independently checked, then reviewed by Jev.

NVIDIA's three-layer agent stack and key principles

The post divides agent systems into three layers, which together it calls the agent stack: the model provides capability; the harness organizes context, tools and workflows; and the runtime provides the infrastructure where actions actually execute. NVIDIA says every layer carries security responsibilities, and controls are needed across layers as data, instructions and actions flow through the system.

The post illustrates this with a scenario: while updating a customer record, an agent encounters malicious instructions in an attached document and then attempts to export customer data to an unauthorized destination. In NVIDIA's view, network policy should block the transfer, and protected logs should record the attempted tool call, the authorization decision and the outcome so the security team can trace what happened. Permission to update records should also not automatically include permission to export data; the agent may request additional access but cannot approve it itself.

  • Boundaries independent of the agent's judgment: the runtime should enforce its own limits on files, network destinations and processes, so they hold even when the agent makes a wrong decision.
  • Identity and least privilege (giving only the permissions a task needs): every agent should have a traceable identity, with credentials (the keys and logins it uses) limited to its assigned task.
  • Human checkpoints: significant actions and permission changes still require human approval.
  • Supply chain checks: verify the origin and integrity of the tools, skills and dependencies an agent uses.
  • Retain evidence: keep protected records of tool calls, authorization decisions and outcomes, and have procedures ready to revoke access and contain incidents.

Tools mentioned in the post

In the post, NVIDIA introduces its own open-source OpenShell, describing it as a secure runtime that enforces policy outside the agent's reach and provides sandboxed execution, meaning the agent's actions run in an isolated, fenced-off environment. The post also lists tools from several vendors as examples. The table below is compiled from NVIDIA's descriptions; neither the features nor their effectiveness have been verified by this site or any third party, and nothing here is a purchasing recommendation.

Source: examples listed in NVIDIA's official blog post; reflects NVIDIA's descriptions only
ToolVendorPurpose as described in NVIDIA's post
OpenShellNVIDIAOpen-source secure runtime that enforces policy outside the agent's reach and provides sandboxed execution
DefenseClawCiscoBuilt on OpenShell, adding a governance layer
(Integration with OpenShell)JFrogScans and verifies agent skills, and controls which skills agents can use
SafeMindCrowdStrikeTests and strengthens defenses through repeated attack simulations
Prisma AIRSPalo Alto NetworksContinuous red teaming (simulated attacks to find weaknesses) as models and applications change
VulnHunterCapital OneAI-assisted code security
Spectra AssureReversingLabsUses AI to analyze software packages and detect malware and tampering

Testing and open tools: NVIDIA's position

NVIDIA argues that before deployment there must be evidence that controls can stop an agent from obtaining credentials beyond its task or sending sensitive data to unauthorized destinations. Testing should also cover attempts to change permissions or interfere with monitoring, and should be repeated after significant changes to models, tools or workflows. The post says a named owner must decide on release based on test results, failed tests must lead to fixes, and every finding can be turned into a repeatable test.

On tool choice, the post says closed models offer managed capabilities and services, while open models let defenders inspect components, adapt strategies and run on infrastructure they control. NVIDIA notes that when an incident occurs, this control helps teams reproduce the problem on their own systems and test fixes while keeping sensitive evidence in-house.

What it means for everyday readers

More and more services are letting AI agents look up information, edit records and call other systems on people's behalf. The points NVIDIA raises apply to ordinary users too: what an agent "can do" should be determined by system boundaries, not just its own judgment; key actions should be confirmed by a person; and when something goes wrong, it should be traceable. As you start using AI agents at work or in your personal life, look at whether the service lets you set permissions, whether it asks for your confirmation before important operations, and whether it keeps an operation log you can review.

Frequently asked questions

Is this a new product announcement?

Mostly not. This NVIDIA blog post focuses on explaining views and principles, while also introducing NVIDIA's open-source runtime OpenShell and listing partner tools as examples.

What is the "agent stack"?

According to NVIDIA, it has three layers: the model provides capability; the harness organizes context, tools and workflows; and the runtime provides the infrastructure where actions actually execute. The post argues each layer needs security controls.

Why can't instructions alone keep an AI agent in line?

NVIDIA argues that instructions and safeguards can guide behavior, but security also requires enforceable boundaries. Even if the agent makes a wrong decision, for example after being influenced by malicious instructions in a document, the runtime should independently limit the files, network destinations and processes it can touch.

What is OpenShell?

According to NVIDIA, OpenShell is an open-source secure runtime that enforces policy outside the agent's reach and runs the agent's actions in an isolated sandbox. Its real-world effectiveness is so far supported only by NVIDIA's own claims, with no independent verification.

What do everyday users need to do?

You don't need to buy anything. When using AI agent services, check whether they obtain only the permissions needed for the task, whether they ask for your confirmation before important operations, and whether they keep an operation log. These are all principles NVIDIA's post emphasizes.

Browse the latest news in this topic

Latest travel guides

Sources

Lifestyle