AI Briefing
KO

Implementing Secure by Design for Autonomous AI Agents with NVIDIA OpenShell

·2026.03.24 00:00

Key point

NVIDIA has unveiled OpenShell, a sandbox-based runtime, to strengthen the security of autonomous AI agents.

Details

AI agents are moving beyond simply generating responses to taking direct actions such as reading files, executing code, and performing workflows. However, as agents evolve on their own and expand their capabilities, application-layer security risks also increase exponentially.

NVIDIA OpenShell is an open source security runtime designed to address this problem. It runs each agent within an isolated sandbox, separating application-layer tasks from infrastructure-layer policy enforcement.

Rather than relying on prompting to guide agent behavior, OpenShell places constraints on the environment in which the agent runs. This prevents an agent, even if compromised, from disabling security policies or leaking credentials and personal data. This is similar to a 'browser tab' model in which sessions are isolated and resources are controlled.

NVIDIA NemoClaw combines OpenShell with NVIDIA Nemotron models to provide an open source reference stack that makes it easy to build 'claws,' personal AI assistants. Users can run security-hardened agents across various environments through this, including cloud, on-premises, NVIDIA RTX PC, and DGX systems.

OpenShell and NemoClaw are currently in early preview, and NVIDIA is working with security partners including Cisco, CrowdStrike, and Google Cloud to build an enterprise-grade security ecosystem.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.