返回首页

对比阅读

对比阅读:Nvidia's 100-Partner Agent Safety Push — Real Gatekeeper Is Its Hardware Stack 与 英伟达拉 100 家伙伴做 Agent 安全平台 — 真正门槛是它的硬件栈

AEN
NvidiaJensen HuangOpen Agent Safety Platform·

Nvidia's 100-Partner Agent Safety Push — Real Gatekeeper Is Its Hardware Stack

On September 28, Jensen Huang announced on X: Nvidia, together with 100+ industry partners, is launching an Agent (an AI program that can autonomously read/write files and invoke tools) safety platform. On the surface it looks like a product launch; in our view it's more of an ecosystem positioning play—the technical details still have room to iterate, and the real headline is 100 partners showing up. Whether you can route around it depends on whose hardware stack you're running.

What this is

The platform has two layers.

Top layer: OpenShell—the policy layer. It was already open-source; this time it's formally folded into the safety platform architecture. Its job is to enforce rules at Agent runtime—file access, network connections, tool invocations, credential use—violations are rejected. The practical implication for engineering teams: you can add constraints without modifying the Agent itself, wrapping the layer directly around existing Agents like Claude Code or Codex.

Bottom layer: Sentry—the hardware isolation layer. This is the genuinely new piece. It sinks monitoring and isolation down into Nvidia's BlueField-4 DPU (data processing unit), running independently of the Agent for continuous threat detection. The cost: you must be on Nvidia hardware.

The umbrella for both tracks is the Open Security AI Alliance (OSAA), founded July 2026, with members including Adobe, CrowdStrike, IBM, Microsoft, and Red Hat. The platform is one of OSAA's engineering deliverables.

Industry view

Supporters argue Agent runaways are a real engineering pain point. When Agents reason and call tools within authorized permissions, systems typically lack runtime blocking capability—by the time out-of-scope access or credential leaks are detected, actual damage has often already occurred. Layered defense (software for policy, hardware for isolation) is the standard path, and Nvidia has packaged it into a deliverable so every team doesn't have to reinvent the wheel.

There are two lines of objection. First, OpenShell's policy granularity is hard to calibrate—too coarse and it's decorative, too fine and false-positive rates spike, with business units complaining that workflows get blocked. Second, Sentry's requirement for BlueField-4 puts a hardware floor that shuts out edge and endpoint scenarios; companies not running Nvidia's hardware stack only get "half the package." Look one level deeper: this binds the "standard answer" for Agent safety to Nvidia's ecosystem, which competitors will struggle to replicate—the impact on the vendor landscape is worth watching more than the technical details themselves.

Impact on regular people

For enterprise IT: Teams running Agents in production—especially in high-sensitivity sectors like finance, healthcare, and infrastructure—need to reassess "whether Agents might be misused beyond authorized scope" and inventory OpenShell integration costs and BlueField-4 hardware readiness.

For individual careers: Ordinary employees won't notice anything for now, but IT, ops, and security roles need to pick up a new skill—Agent runtime policy configuration—which may become a resume differentiator down the line.

For the consumer market: In the short term, AI features inside consumer apps won't change because of this; in the long run, Agent-type applications will be more willing to ship—only when someone's backing the safety liability will enterprises dare let an Agent order your takeout, edit your contracts, or check your bank account.

来源: juejin.cn
BZH
英伟达黄仁勋Open Agent Safety Platform·

英伟达拉 100 家伙伴做 Agent 安全平台 — 真正门槛是它的硬件栈

9 月 28 日,黄仁勋在 X 平台宣布:英伟达联合 100 多家行业伙伴,推出 Agent(能自主读写文件、调用工具的 AI 程序)安全平台。表面看是产品发布,在我们看来更像一次生态卡位——技术细节还有迭代空间,100 家伙伴的站台才是重头戏。绕不绕过它,取决于你跑在谁的硬件栈上。

这是什么

平台分两层。

上层是 OpenShell:策略层。它早已开源,这次正式被纳入安全平台架构。职责是在 Agent 运行时强制执行规则——文件访问、网络连接、工具调用、凭证使用,越界就拒。对工程团队的意义是,无需改造 Agent 本身就能加约束,可以直接套在 Claude Code、Codex 这类存量 Agent 外面。

下层是 Sentry:硬件隔离层。这是真正的新东西。它把监控和隔离下沉到英伟达 BlueField-4 数据处理芯片上,独立于 Agent 运行,持续做威胁检测。代价是必须依赖英伟达自家硬件。

两条线的承接方是 2026 年 7 月成立的开放安全 AI 联盟(OSAA),成员覆盖 Adobe、CrowdStrike、IBM、Microsoft、Red Hat 等。平台是 OSAA 成果的工程化落地之一。

行业怎么看

支持方认为,Agent 失控是真实工程痛点。Agent 在权限内做推理、调用工具时,系统通常缺乏运行时阻断能力,等发现越界访问或凭证泄露,往往已造成实际损害。分层防御(软件层管策略,硬件层管隔离)是标准路径,英伟达把它做成可交付件,省得每个团队重新造轮子。

反对意见也有两条。一是 OpenShell 的策略颗粒度难拿捏——太粗等于摆设,太细则误杀率高,业务部门会抱怨流程被拦;二是 Sentry 必须依赖 BlueField-4,硬件门槛把边缘和端侧场景挡在门外,没用英伟达硬件栈的企业只能用「半套」。更深一层看,这是把 Agent 安全的「标准答案」绑定到英伟达生态,对手难复制——供应商格局的影响,会比技术细节本身更值得留意。

对普通人的影响

对企业 IT:已在生产环境跑 Agent 的团队,尤其是金融、医疗、基础设施等高敏领域,需要重新评估「Agent 是否可能被越界使用」,并盘一盘 OpenShell 接入成本和 BlueField-4 硬件就位情况。

对个人职场:普通员工暂时无感,但 IT、运维、安全岗的人需要补一门「Agent 运行时策略配置」的新功课,未来可能变成简历加分项。

对消费市场:短期内消费类 App 里的 AI 功能不会因此变化;长期看,Agent 类应用会更敢放出来——有人兜底安全责任,企业才敢让 Agent 替你点外卖、改合同、查银行账户。

来源: juejin.cn