Blog

Safe AI Agents Start With Trusted AI Infrastructure

Trusted and Safe AI with Eclypsium AI Infrastructure Assurance and NVIDIA Open Agent Safety Platform

AI agents are moving from answering questions to taking action. They can read sensitive data, call APIs, write and execute code, use external tools, and coordinate with other agents. In some environments, their decisions may affect physical systems.

That creates a security requirement that prompts and model guardrails cannot address on their own. Organizations need controls over what an agent can access and do. They also need to verify the infrastructure enforcing those controls.

NVIDIA’s Open Agent Safety Platform addresses agent execution by placing security boundaries in the runtime and infrastructure. Eclypsium is verifying the integrity and security posture of the hardware and firmware infrastructure supporting those boundaries.

Together, NVIDIA Open Agent Safety Platform  and Eclypsium Infrastructure Assurance Platform address agent safety and security from the underlying infrastructure to the actions AI agents are permitted to take.

NVIDIA provides safe agent execution

An agent’s instructions can guide its behavior, but instructions are not an independent security boundary. An agent with tool access may encounter malicious inputs, make an unexpected decision, or attempt an action its operators did not intend. Security controls need to evaluate and enforce those actions independently of the agent.

The NVIDIA Open Agent Safety Platform is an open reference design built around two complementary elements. NVIDIA OpenShell provides a secure runtime that governs how an agent executes, what it can access, and where inference occurs. Its sandboxes, policy engine, and gateway control interactions with files, processes, networks, tools, and services.

NVIDIA Sentry runs on NVIDIA BlueField-4 Data Processing Unit (DPU), using NVIDIA DOCA capabilities to monitor activity and enforce policies from a hardware-isolated domain outside the agent and host software. This provides a separate enforcement point for identity, data access, and communications.

This separation matters as agents receive access to production systems. Operators need controls that an agent cannot simply reason its way around. 

That leads to the next challenge: How do operators verify the integrity and security of the infrastructure enforcing safe agent execution?

Eclypsium verifies the infrastructure for safe agent execution

A DPU has its own firmware, software, configuration, and supply chain. The server around it includes UEFI and BIOS firmware, a baseboard management controller (BMC), network interfaces, GPUs, and other components with privileged access. These components operate outside the application and operating system layers where many traditional security controls focus. Some can also persist through a host reboot or reimage.

Consider a security architecture that relies on a DPU to enforce access policy while the DPU firmware has been modified or the host BMC has been compromised. The independent control plane still provides isolation, but the integrity of that control plane becomes part of the security model.

A compromise at the hardware or firmware layer could affect components, telemetry, or the assumptions on which runtime enforcement depends. The exact impact depends on the affected component and type of compromise. Isolation by itself does not verify that an isolated component remains in a known-good state.

This is familiar territory for our team. Eclypsium provides infrastructure assurance for AI environments by inventorying hardware and firmware, verifying device integrity, identifying vulnerabilities and insecure configurations, and detecting unauthorized modifications and persistent threats.

Coverage includes AI servers, DPUs, GPUs, BMCs, firmware code, and connected network infrastructure. These checks provide evidence about device and firmware posture before agent workloads are deployed and as the underlying infrastructure changes.

End-to-end chain of trust for safe AI deployment and execution

A practical security model for autonomous agents has three parts:

  1. Verify the infrastructure. Establish and continuously validate trust in the hardware and firmware foundation supporting and enforcing safe AI agent execution. Maintain known-good baselines, verify the integrity and security posture of critical components, and ensure the infrastructure remains resilient against vulnerabilities, unauthorized changes, supply-chain risk, and compromise.
  2. Enforce from an independent boundary. Use NVIDIA OpenShell to govern agent execution and, on BlueField-4 systems, NVIDIA Sentry to monitor and enforce policies from a domain isolated from the host and GPU domains.
  3. Govern agent access and actions. Apply explicit permissions to data, tools, APIs, network destinations, and execution paths. Record decisions and activity so security teams can investigate and validate what occurred.

Each layer answers a different operational question. Is the infrastructure in an expected state? Is the security boundary enforcing policy? What actions did the agent take?

Runtime policy determines which requests are permitted. Hardware-isolated enforcement can apply those decisions independently of the agent process. Infrastructure assurance ensures that the hardware and firmware enforcing those controls cannot be bypassed, match an expected, known-good state, and have not been tampered with.

That verification cannot be a one-time check. AI infrastructure changes and threat actors constantly look for ways to exploit it. Infrastructure needs to be monitored continuously throughout its lifecycle.

Make AI infrastructure assurance operational

For an enterprise deploying AI agents, infrastructure assurance starts with an accurate inventory of components those agents depend on: GPUs, DPUs, CPUs, TPUs, BMCs, NICs, UEFI, HBM, SSDs, TPMs, accelerators, Operating System and firmware code in all of them, and the infrastructure connecting agents to data and tools.

Without that inventory, security teams cannot reliably identify which components require investigation when a vulnerability is disclosed, firmware changes, or a device deviates from its approved state.

The next step is to establish known-good firmware and configuration baselines and compare production devices against them. Eclypsium identifies vulnerable or unexpected firmware, detects integrity drift and signs of persistent compromise, and provides component-level context for findings.

That evidence can inform deployment decisions, incident response, maintenance, and the conditions under which agent workloads are permitted to run.

Verify the foundation of autonomous systems

Consider a platform team preparing to give an agent access to a sensitive data service. The team needs to know whether the OpenShell policy permits the connection. It should also be able to verify the posture of the host and the infrastructure enforcing that policy. If code integrity changes or an exploitable vulnerability is identified in a critical component, the team needs evidence it can use to investigate the affected component and restore it to an approved state.

NVIDIA OpenShell and Sentry address agent runtime governance and independent enforcement. Eclypsium addresses the integrity and risk of the infrastructure components those controls depend on. Together, these layers give security and infrastructure teams evidence about both agent activity and the infrastructure supporting it.

As AI agents get access to more sensitive data, tools, and infrastructure, security teams need enforceable limits on what those agents can do. They also need to verify the infrastructure enforcing those limits.

The NVIDIA Open Agent Safety Platform provides an architecture for governing and enforcing safe agent execution. The Eclypsium Infrastructure Assurance Platform ensures that organizations can verify the infrastructure supporting safe and secure deployment and execution of AI models and agents.