Nvidia outlines AI agent security framework with OpenShell
Tue, 6th Oct 2026 (Today)
Nvidia has outlined a security framework for AI agents and highlighted OpenShell as a runtime for enforcing controls. Its approach centres on enforceable boundaries, accountable owners and evidence that protections work.
The framework sets out how organisations should secure AI systems that can reason, use tools and adapt their actions based on the data they encounter. It argues that the same core responsibilities used in internet and cloud security still apply, including identity management, access control, limiting exposure and verifying that safeguards are effective.
Rather than treating AI security as a separate discipline, Nvidia presents it as an engineering task that requires defined requirements, clear ownership and testing. Pressure is rising as businesses pursue AI-driven productivity gains while governance and security practices are still taking shape.
Agent stack
A central point in the framework is that security depends on the full agent stack, not just the model. Nvidia describes that stack as including models, harnesses that organise context and workflows, and the runtime environments where actions are executed.
Each layer carries its own security responsibilities. As instructions, data and actions move through the system, controls must work across all of them.
One example in the framework involves an AI agent updating a customer record after encountering malicious instructions in an attached document. In that scenario, a network policy should block any attempt to export customer data to an unauthorised destination, while protected logs should record the attempted tool call, the authorisation decision and the outcome.
Nvidia also argues that permission to update a customer record should not automatically allow an agent to export the same data elsewhere. If an agent needs extra access, it can request it, but it should not be able to grant that access to itself.
Runtime controls
Security boundaries must remain effective even when an agent makes the wrong decision. That makes the runtime environment critical, as it should impose limits on files, network destinations and processes independently of the agent's reasoning.
OpenShell is presented as Nvidia's open-source runtime for that purpose. It provides sandboxed execution and enforces policy controls outside the agent's reach while governing access to data, networks and system resources.
The wider ecosystem is also part of the message. Open Secure AI Alliance partners are building on OpenShell, with Cisco's DefenceClaw adding a governance layer and JFrog integrating scanning and verification of agent skills while applying policies to the skills agents may use.
The framework also calls for each agent to have a traceable identity and credentials limited to its assigned task. Organisations should set clear policies on what information agents may access, which systems they may change and which actions still require approval.
Consequential actions and permission changes should remain subject to human approval. Teams should also verify the source and integrity of the tools, skills and dependencies agents use.
Testing evidence
Before deployment, teams need evidence that controls can block attempts to obtain credentials beyond an agent's scope or send sensitive data to an unauthorised destination. Testing should also cover attempts to change permissions or interfere with monitoring.
That testing should be repeated after material changes to models, tools or workflows. A named owner should then decide whether the system is ready to go live and ensure failed tests lead to corrective action.
Nvidia also sets out an iterative process for failures found in testing or live operation. Those failures should be reproduced, investigated and addressed, and each finding should become a repeatable test for future releases.
Examples include CrowdStrike's SafeMind for repeated attack simulations and Palo Alto Networks Prisma AIRS for continuous red teaming as models and applications change. Their inclusion points to a growing market for AI assurance and operational testing.
Open and closed
Nvidia also addressed the debate over open and closed models in security work. It said closed models provide managed services, while open models can give defenders more scope to inspect components, adapt their methods and operate on infrastructure they control.
That control can matter during an incident because teams may need to reproduce failures and test fixes on their own systems while keeping sensitive evidence within their environment. AI tools used by defenders should also be judged on reproducible findings, verifiable fixes and whether they shorten response times.
Nvidia pointed to Capital One's VulnHunter for code security work and ReversingLabs' Spectra Assure for analysing software packages for malware and tampering. It added that sharing evidence about failures, effective controls and verified fixes could help other teams strengthen their own systems.
In Nvidia's view, AI security remains an engineering problem, and every agent deployment needs enforceable boundaries, an accountable owner and evidence that its protections work.