Lifestyle
NVIDIA Says AI Agent Security Is an Engineering Problem: Controls at Every Layer, from the Model to Where Actions Run
On September 21, 2026, NVIDIA's official blog argued that securing AI agents (AI programs that can use tools and take actions on someone's behalf) takes engineering, not good intentions: limits enforced at every layer, minimal permissions, human approval, continuous testing and open tools. Here is what NVIDIA proposes and what it means for organisations using agents and the people whose data they handle.
About 7 min read

What happened: NVIDIA proposes an engineering framework for AI agent security
On September 21, 2026, NVIDIA's official blog published "AI Security Is an Engineering Problem," written by Saša Zdjelar. The post opens by stating that "AI security is an engineering problem" and makes this concrete with four elements: clear security requirements, enforceable controls, named owners, and evidence that the protections are effective. NVIDIA argues that as AI capabilities grow, the industry must speed up security engineering, broaden access to defensive tools, and share what works more quickly.
According to NVIDIA, the internet and the cloud changed how software runs, but the core security responsibilities did not change: establishing identity, controlling access, limiting exposure, and verifying that protections work. What is new about AI agents is that they can reason, use tools, and adjust their actions based on the data they encounter. The post also acknowledges that organizations want the productivity gains of AI, while practices for governing and protecting such systems are still developing.
Read the full description
Sources are collected, independently checked, then reviewed by Jev.
NVIDIA's three-layer agent stack and key principles
The post divides agent systems into three layers, which together it calls the agent stack: the model provides capability; the harness organizes context, tools and workflows; and the runtime provides the infrastructure where actions actually execute. NVIDIA says every layer carries security responsibilities, and controls are needed across layers as data, instructions and actions flow through the system.
The post illustrates this with a scenario: while updating a customer record, an agent encounters malicious instructions in an attached document and then attempts to export customer data to an unauthorized destination. In NVIDIA's view, network policy should block the transfer, and protected logs should record the attempted tool call, the authorization decision and the outcome so the security team can trace what happened. Permission to update records should also not automatically include permission to export data; the agent may request additional access but cannot approve it itself.
- Boundaries independent of the agent's judgment: the runtime should enforce its own limits on files, network destinations and processes, so they hold even when the agent makes a wrong decision.
- Identity and least privilege (giving only the permissions a task needs): every agent should have a traceable identity, with credentials (the keys and logins it uses) limited to its assigned task.
- Human checkpoints: significant actions and permission changes still require human approval.
- Supply chain checks: verify the origin and integrity of the tools, skills and dependencies an agent uses.
- Retain evidence: keep protected records of tool calls, authorization decisions and outcomes, and have procedures ready to revoke access and contain incidents.
Tools mentioned in the post
In the post, NVIDIA introduces its own open-source OpenShell, describing it as a secure runtime that enforces policy outside the agent's reach and provides sandboxed execution, meaning the agent's actions run in an isolated, fenced-off environment. The post also lists tools from several vendors as examples. The table below is compiled from NVIDIA's descriptions; neither the features nor their effectiveness have been verified by this site or any third party, and nothing here is a purchasing recommendation.
| Tool | Vendor | Purpose as described in NVIDIA's post |
|---|---|---|
| OpenShell | NVIDIA | Open-source secure runtime that enforces policy outside the agent's reach and provides sandboxed execution |
| DefenseClaw | Cisco | Built on OpenShell, adding a governance layer |
| (Integration with OpenShell) | JFrog | Scans and verifies agent skills, and controls which skills agents can use |
| SafeMind | CrowdStrike | Tests and strengthens defenses through repeated attack simulations |
| Prisma AIRS | Palo Alto Networks | Continuous red teaming (simulated attacks to find weaknesses) as models and applications change |
| VulnHunter | Capital One | AI-assisted code security |
| Spectra Assure | ReversingLabs | Uses AI to analyze software packages and detect malware and tampering |
Testing and open tools: NVIDIA's position
NVIDIA argues that before deployment there must be evidence that controls can stop an agent from obtaining credentials beyond its task or sending sensitive data to unauthorized destinations. Testing should also cover attempts to change permissions or interfere with monitoring, and should be repeated after significant changes to models, tools or workflows. The post says a named owner must decide on release based on test results, failed tests must lead to fixes, and every finding can be turned into a repeatable test.
On tool choice, the post says closed models offer managed capabilities and services, while open models let defenders inspect components, adapt strategies and run on infrastructure they control. NVIDIA notes that when an incident occurs, this control helps teams reproduce the problem on their own systems and test fixes while keeping sensitive evidence in-house.
What it means for everyday readers
More and more services are letting AI agents look up information, edit records and call other systems on people's behalf. The points NVIDIA raises apply to ordinary users too: what an agent "can do" should be determined by system boundaries, not just its own judgment; key actions should be confirmed by a person; and when something goes wrong, it should be traceable. As you start using AI agents at work or in your personal life, look at whether the service lets you set permissions, whether it asks for your confirmation before important operations, and whether it keeps an operation log you can review.
Frequently asked questions
Is this a new product announcement?
Mostly not. This NVIDIA blog post focuses on explaining views and principles, while also introducing NVIDIA's open-source runtime OpenShell and listing partner tools as examples.
What is the "agent stack"?
According to NVIDIA, it has three layers: the model provides capability; the harness organizes context, tools and workflows; and the runtime provides the infrastructure where actions actually execute. The post argues each layer needs security controls.
Why can't instructions alone keep an AI agent in line?
NVIDIA argues that instructions and safeguards can guide behavior, but security also requires enforceable boundaries. Even if the agent makes a wrong decision, for example after being influenced by malicious instructions in a document, the runtime should independently limit the files, network destinations and processes it can touch.
What is OpenShell?
According to NVIDIA, OpenShell is an open-source secure runtime that enforces policy outside the agent's reach and runs the agent's actions in an isolated sandbox. Its real-world effectiveness is so far supported only by NVIDIA's own claims, with no independent verification.
What do everyday users need to do?
You don't need to buy anything. When using AI agent services, check whether they obtain only the permissions needed for the task, whether they ask for your confirmation before important operations, and whether they keep an operation log. These are all principles NVIDIA's post emphasizes.
Browse the latest news in this topic
Lifestyle
Cloudflare launches Traces in public beta: site operators can follow every step a request takes through the platform on one timeline
On October 2, 2026, Cloudflare announced the public beta of Cloudflare Traces. Website operators and developers using Cloudflare can see a request pass through security rules, caching, routing and the origin server on a single timeline, making it easier to find why a request was blocked or slowed. New pricing takes effect on December 1, 2026. Information comes from the official Cloudflare blog.
Lifestyle
Cloudflare launches Web Search API via AI Gateway, requiring search partners to follow its crawler rules
On October 2, 2026, Cloudflare announced a Web Search API that lets AI agents query live web information through AI Gateway. The first partners are Ceramic.ai, Exa and Linkup. Cloudflare says these partners' crawlers must meet its Verified bots requirements and cite sources. This matters both to developers building AI applications and to website owners whose content may be crawled.
Lifestyle
Cloudflare open-sources Streamline: a demo of using its cloud services to add graphics to live streams and burn subtitles into videos
On October 2, 2026, Cloudflare launched and open-sourced Streamline, a developer playground showing how developers can combine Stream, Workers, Containers and Durable Objects to build their own video processing pipelines, such as adding graphics to live streams in real time or adding subtitles to videos. This article explains what it is, how it works, its limitations, and what it means for viewers and developers.
Lifestyle
Google unveils Gemini 4 Argon: cyber defenders get it first, everyone else still has to wait
On September 30, 2026, Google announced Gemini 4 Argon, which it calls its new frontier (most advanced) AI model. For now it is available only to trusted cyber defenders through the Fairwind Program. Here is what Google says the model can do, what it will cost developers, how Google says it is managing the risks, and what it means for everyday users. All figures come from Google itself.
Latest travel guides

GuideTokyo
Where to Stay in Tokyo: Comparing Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza, Plus Airport Access, Accommodation Tax, and Luggage Delivery
Where should you stay in Tokyo? Compare Shinjuku, Ueno, Tokyo Station, Shibuya, Asakusa, Ikebukuro, and Ginza by the same criteria: access from Narita and Haneda, transit routes, nearby attractions, neighborhood character, and who each area suits. Includes a comparison table, a Yamanote Line diagram, Tokyo’s accommodation tax as verified in 2026/9 (changing to 3% in 2027/4), and Airport TA-Q-BIN luggage shipping rules.
- Budget
- Hotels

GuideTokyo
How to Choose Tokyo Transit Passes: Are Suica, Welcome Suica, the Tokyo Subway Ticket, and the JR Pass Worth It?
On a first Tokyo trip, start with an IC card and pay per ride (Welcome Suica has no deposit and is valid for 28 days). If you take four or more subway rides in a day, add a 72-hour Tokyo Subway Ticket for 2,000 yen; a JR Pass is never worthwhile if you stay in Tokyo and do not go to Kansai. See what TOURIST PASMO, Suica on iPhone, and the Tokyo Metro day pass do and do not cover, with a decision chart. Prices verified in September 2026.
- Transport
- Budget

GuideTokyo
Tokyo Disneyland and DisneySea Guide: Ticket Prices, Fantasy Springs, Disney Premier Access (DPA), Standby Pass, and Which Park to Choose for Your First Visit
Tokyo Disney one-day Passport prices vary: most weekdays in 9/2026 cost ¥9,900 and weekends ¥10,900. At 14:00 daily, tickets go on sale for the same date two months later. Free Priority Pass is no longer on the official service list; only paid Disney Premier Access (¥1,000–3,500 per person per use) shortens waits. Covers hours, the 25th anniversary, Standby Pass, Entry Request, Fantasy Springs access and first-visit park choice; checked on the official site in 9/2026.
- Itineraries
- Family
Sources
- AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack | NVIDIA Blog · Checked:
- Saša Zdjelar Author Page | NVIDIA Blog · Checked:
- AI Security Is an Engineering Problem — How to Solve It at Every Layer of the Agent Stack | NVIDIA Blog · Checked:
- - Archives Page 1 | NVIDIA Blog · Checked:
- NVIDIA and Partners Showcase AI Advancements Across Southeast Asia | NVIDIA Blog · Checked: