AI/ML, AI benefits/risks

NVIDIA can stop a rogue agent. Can it revoke its access?

Futuristic digital security concept with robotic hand reaching for file icon and login credentials over network connections in a modern city backdrop. Sentient.

COMMENTARY: NVIDIA's new Open Agent Safety Platform is one of the more credible attempts yet to keep AI agents from going off the rails.

It pairs OpenShell, an open-source runtime that traces agent activity and enforces policy, with Sentry, an out-of-band watchdog running on BlueField-4 data processing units (DPUs). Think of a DPU as a separate computer living on the network card that the host can't tamper with. Because Sentry sits outside the host, an agent can't simply disable the control watching it. If the agent crosses a defined boundary, Sentry can quarantine it within milliseconds. That's sound architecture.

My concern is how it's going to be used. The security industry has a habit of taking reasonable control, leaning on it harder than it was designed for, and calling the problem solved. We did it with password rotation, which mostly taught users to go from Summer2023! to Fall2023!, and again with SMS MFA and malware sandboxes. Each addressed a real risk and eventually fell short on its own.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

Sandboxes are the closest parallel, since malware learned to behave whenever it was being watched. Frontier labs have published research on models that appear to recognize when they're being evaluated, and in NVIDIA's testing, agents spent up to two hours trying to talk an AI reviewer into granting write access to a protected repo (I've worked sales cycles with less persistence than that). But evasion isn't my biggest worry. An agent with valid credentials doesn't have to break out of anything to cause damage.

The agent may already have the keys

Enterprise agents work through delegated access: OAuth grants, service accounts, API keys and inherited permissions. If a prompt-injected agent pulls a customer list through an approved Salesforce API using a valid OAuth grant, there's often nothing malicious-looking about the request. It came from an authenticated identity with permission to make it. That's the “confused deputy” problem, and it's been around for decades.


Related reading:


To NVIDIA's credit, they see this. Sentry can verify agent identity and enforce granular zero-trust policies, while OpenShell records actions and enforces policy as an agent runs. But the credentials agents use are mostly issued by identity providers and SaaS platforms outside that stack.

That gap matters at quarantine. Stopping an agent doesn't necessarily revoke its OAuth grant, invalidate its API key or disable its service account. If someone copied a refresh token, it still works. Unless containment connects to the systems that issued those credentials, you've stopped the agent and left the keys in the door.

This is an identity lifecycle problem

We've already seen what valid integrations can do in the wrong hands. Attackers in the Salesloft Drift incident used stolen OAuth tokens to pull data from Salesforce environments at hundreds of companies. Midnight Blizzard accessed Microsoft's corporate email through an old test OAuth app with more access than it needed. In both cases, trusted credentials made authorized calls for an unauthorized purpose.

AI agents are going to multiply those identities quickly, and many will show up where security isn't looking. I've seen what that looks like when leadership blesses it. At my last operational job, developers were essentially told to do whatever it took to get the job done, not far off from today's "spend tokens at all costs" mandates. We ended up with unsanctioned apps, exposed production systems, and entire racks of equipment we discovered after the fact.

Agents create access in minutes instead of weeks, and they don't leave a rack behind anyone to trip over. A developer spins one up for coding, marketing connects another to customer data, and an employee authorizes a browser-based agent and forgets it exists. Many will run through SaaS applications, browser extensions, automation services and MCP servers security teams may not know about. And when an agent runs on a human's OAuth grant, the logs say the human did it.

Security teams need to know which agents exist, who owns them, what credentials they hold, what they can reach, and how that access gets revoked. Every agent should authenticate as itself, with permissions scoped to the task and short-lived credentials wherever possible. It should have a named owner, appear in access reviews and generate logs separating its actions from the person who launched it. When the task ends or the agent gets quarantined, its grants should be revoked at the source.

Connecting containment to revocation

NVIDIA deserves credit for putting enforcement outside the agent and open sourcing the software underneath it. We need controls agents can't reason with, disable or talk their way around. We also need to resist treating one good control as the whole answer. For enterprises, the useful measure will be how quickly a quarantine decision reaches the identity systems that issued an agent's credentials and shuts off its access everywhere else.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Portnox's Garrett Gross

Garrett Gross serves as Vice President of Customer Success at Portnox and is responsible for leading the global Customer Success organization, including Customer Experience and Technical Account Management. Gross brings nearly three decades of experience in IT and cybersecurity, with a career grounded in security operations and penetration testing for complex, high-risk environments. Prior to Portnox, Gross held senior leadership roles across security operations, customer success, and customer-facing organizations, helping companies translate advanced security solutions into measurable business outcomes.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds