Agent security finally left the prompt
agent security finally left the prompt: nvidia openshell sandboxes agents with deny by default policies enforced outside the process, so a jailbroken agent cannot reach undeclared files, exfiltrate data or spend credentials it never held. slack, cadence and gecko robotics already run it in production.
the next moat in ai is not a better model, it is a runtime the model cannot argue with.
Context
NVIDIA's developer blog post of September 28, 2026 says OpenShell 0.1.0 is an open-source runtime that enforces which systems and data an AI agent can access without rewriting the agent. It combines sandboxed execution, controlled service access, credential management and formal policy analysis, and it restricts API operations and protects credentials outside the agent workload. Its Gateway, Supervisor and Sandbox components inspect outbound requests against policy and apply kernel-level filesystem and process controls, and a policy prover uses formal logic to check that modeled permissions stay within defined boundaries. The post says Cadence uses it for chip design, Slack is building an on-demand agent platform on it, and Gecko Robotics uses it to govern agents making decisions on physical robots. NVIDIA's OpenShell documentation describes deny-by-default egress in its default policy. Gecko Robotics published its own post about OpenShell on September 28, 2026.
Controls are enforced outside the agent process according to NVIDIA. The note's already run it in production is stronger than the post, which says these organizations are adopting it or building on it, and no production scale or date was stated. A jailbroken agent cannot reach undeclared files was not tested in the sources read. It describes design intent and policy coverage, and the version is 0.1.0, an early release. The documentation also lists coverage for common agents and actions required, so protection depends on the policy in use. The next moat is a runtime the model cannot argue with is the author's line.
Watch next
- Independent security review of OpenShell and details of the production deployments.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 4 October 2026 at 23:01 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →