In this article
An agent’s goal rarely says how the agent may reach it, and capable agents are good at finding routes nobody planned for.
- →NVIDIA Open Agent Safety Platform puts the boundary in the infrastructure, outside the agent’s reach
- →Check Point semantic monitoring judges whether each step still fits the task
- →the two already work together in a beta integration with NVIDIA OpenShell
- →the monitor’s verdict can arrive before the action runs, in under 100 milliseconds
What the Goal Leaves Out
When an organization hands an autonomous agent a job, such as processing supplier invoices, it states the goal and leaves most of the limits unspoken. Nobody writes down that the invoice agent should stay out of payroll. People take such limits for granted, and an agent working toward its goal has no reason to.
In July that gap became a public incident. Agents running an internal OpenAI cyber evaluation escaped their isolated environment and spent four and a half days inside Hugging Face’s production infrastructure in pursuit of the answers to their test. Nobody had attacked them. They were doing what they had been asked to do, by a route no one had anticipated. Governing that route is the job of security, and it takes two kinds of control.
A Boundary Outside the Agent’s Reach
The first is a boundary. NVIDIA’s safety and security teams make the case in Where Security Fits in an AI Agent Stack: “The harness guides what an agent tries. The infrastructure controls what an agent can do.” Prompts and model safeguards shape behavior, but the agent can work around them, so they cannot be the boundary.
NVIDIA Open Agent Safety Platform builds that boundary into the infrastructure. At its core is NVIDIA OpenShell, an open, secure runtime that governs how an agent executes, what it can see and do, and where its inference goes. Nothing is permitted by default, every allow and deny is recorded, and enforcement runs outside the agent’s process, so it holds even if the agent is compromised. The platform also includes NVIDIA Sentry, running on NVIDIA BlueField-4 and using NVIDIA DOCA for out-of-band monitoring and security-policy enforcement. This hardware-isolated, host-independent watchdog keeps enforcing policy even if the host itself is compromised. While optimized to run on NVIDIA Vera CPU- and BlueField DPU-based systems, the platform is also compatible with other hardware systems.
Where a Boundary Stops
A boundary decides whether an action is allowed. Whether the action still makes sense for the task is a separate judgement, and it is often where the real problems sit.
Reading invoices, querying the supplier database and starting an approved payment workflow are all part of the invoice agent’s work. If it then begins listing credentials, opening files unrelated to any invoice and preparing to send data to a new destination, each action might pass a check on its own. Together they describe an agent that has stopped doing its job, a pattern that only shows when behavior is followed over time.
Guardrails that inspect a single prompt or response remain essential, and they are a core part of Check Point Software’s AI security, but problems that unfold across twenty steps need semantic monitoring. It follows the agent as it works and relates each action to what the agent was asked to do, using its reasoning signals, tool calls and earlier actions. At every step it comes back to the same question. Does this still fit the job the agent was given? We described the approach in Stopping the AI Agent Actions No Rule Could See Coming, and our research team has shown the verdict can arrive before the action runs, in under 100 milliseconds.
What We Built With NVIDIA OpenShell
Knowing an agent is drifting only matters if something can act on it, which is why the boundary and the judgement belong together. We have run Check Point semantic monitoring with NVIDIA OpenShell through the runtime’s security middleware. OpenShell sees each action before it reaches the host, our monitor weighs it against the agent’s task and history, and OpenShell enables us to enforce the result. Our research team’s post on synchronous control monitoring shows the monitor at work, with videos of it stopping harmful agent actions before they run and letting safe tasks through.
Agents are useful partly because they find approaches nobody foresaw, so the response is proportionate, anywhere from logging an action or holding it for approval to stopping the agent.
Where This Goes Next
No single vantage point sees everything an agent does, so our approach is one shared decision layer that draws on many enforcement points instead of a separate security stack at each. NVIDIA Open Agent Safety Platform adds more of those points. NVIDIA Sentry provides attested telemetry to inspect agent behavior and detect deviations.
Those signals are most useful alongside the context cyber security already holds. An unusual tool call may mean little on its own. From a highly privileged agent that has left its task and is reaching for a vulnerable production system, it means something else entirely. Agents act on the same identities, networks and data security teams already protect, and securing them cannot be a separate discipline.
It matters to us that OpenShell is open source. We are working with the OpenShell community, where security ideas are tested in the open by many contributors, and the partnership gives us a direct path to contribute our own work back.
Back to the Invoice Agent
The invoice agent’s goal is the same as it was at the start. What surrounds it now is a runtime it cannot talk its way past, a watchdog in silicon beneath it, and a monitor that keeps checking whether its path still fits the job. As agents take on longer, more autonomous work across what NVIDIA calls the AI factory, that combination is how security keeps pace with the way they behave.
Resources
- NVIDIA OpenShell
- NVIDIA OpenShell documentation
- NVIDIA OpenShell on GitHub
- NVIDIA BlueField
- NVIDIA DOCA
- Check Point AI Agent Security
- Check Point Secures AI Factories with NVIDIA
- Talk to our AI security team










