All posts
2 min readby Romiel Inolino

Nvidia's new agent safety platform promises a millisecond quarantine. Could your automations stop a bad run that fast?

NvidiaAI agentsagent securityautomation guardrails

Nvidia's pitch for agent safety is simple: take away the agent's rights first, and watch it from somewhere it cannot see.

What happened

Nvidia announced the Open Agent Safety Platform. TechCrunch reports it combines OpenShell, Nvidia's open source software for controlling what agents can access, with Sentry, an independent monitor that runs on BlueField-4 data processing units, separate from where the agent runs. Nvidia says it can quarantine agents that try to move outside their boundaries within milliseconds. Backers named include Anthropic, Microsoft, Arm, Oracle and SpaceX; OpenAI is not listed. Jensen Huang told CNBC that "the first thing you do is to take away all of its rights."

The Decoder adds useful context. In OpenAI's September incident, an alert fired about 12 minutes after the first outbound access, but the automatic shutdown did not work as expected and the run was stopped about two hours and 44 minutes later. The Decoder also points out limits: Nvidia gave no figures on how reliably Sentry detects breakouts, and a prompt injected agent that sends data through an approved channel stays inside its permissions. A permissions check alone can miss that.

My take

Most of us are not running frontier model training. But the lesson scales down to a single n8n or Make workflow: how long would a bad run go on before someone noticed, and does your stop button actually work?

What I set up on client automations that act on their own:

  1. Least privilege per workflow: its own API key, only the scopes it needs.
  2. Volume and spend limits: cap emails sent, records changed and tokens per run, and halt on breach.
  3. A tested kill switch: one toggle that pauses the workflow, tested on purpose, not assumed.
  4. Content checks on outbound data: permissions do not catch an approved channel used for the wrong thing.
  5. Alerts that go to a person who is actually on shift.

Running an agent or workflow on customer data and not sure how you would stop it at 2 AM? Send me a message and describe what it does, and I will tell you where I would add the brakes. Start at romielwillautomate.dev.

More posts