AI infrastructure is increasingly moving to Arm. Arm technology is deployed across every major hyperscaler, and Arm-based rack-scale servers have now overtaken x86 as the dominant platform for accelerated computing, according to IDC.
That shift becomes even more important as AI moves into the agentic era. AI agents don’t just generate answers; they run continuously, use tools, access data and take actions to complete tasks. As agents scale, they create two fundamental compute requirements: compute to run the agent, and compute to protect the agent.
Arm powers the compute for both: high-performance CPUs to run agentic workloads, and Arm-based infrastructure processors, such as DPUs, to provide independent observation, isolation, policy enforcement and security.
NVIDIA’s new Open Agent Safety Platform is the embodiment of this architecture in action.
Arm compute runs the agent #
The CPU is at the center of agentic AI Infrastructure. Agent runtimes, harnesses, orchestration, tool execution and applications all depend on CPUs, and those demands grow as agents become more capable and persistent, and operate concurrently at scale.
Arm already powers the majority of that compute across agentic and cloud workloads, with the Arm AGI CPU, and AWS Graviton, Google Axion, Microsoft Cobalt, and NVIDIA’s custom Vera CPU all architecturally distinct but compatible with the Arm software ecosystem. NVIDIA OpenShell brings secure agent execution to this broad Arm CPU ecosystem.
OpenShell establishes a secure runtime boundary around the agent, governing what it can access and the actions it can take. This means the same fundamental approach to secure agent execution can extend across an increasingly diverse ecosystem of Arm-based cloud and AI infrastructure.
Arm compute governs and contains agent behavior #
Running the agent is only one side of the equation. Agentic infrastructure also needs independent compute that can observe, isolate and govern policies outside the environment where the agent itself is running.
Arm-based DPUs and infrastructure processors provide that independent layer. By moving infrastructure services such as networking, monitoring, isolation and security away from the host CPU, they create a separate control point that remains independent of the agents and applications it is designed to protect.
This architecture already extends across a broad ecosystem of Arm-based DPUs. As these infrastructure processors are built on Arm CPU technology, developers and infrastructure providers can build security capabilities on a common compute architecture.
NVIDIA BlueField demonstrates this model within the Open Agent Safety Platform. BlueField-4, powered by NVIDIA Grace with 64 Arm Neoverse V2 cores, provides an independent infrastructure environment beyond the host. OpenShell integrates with NVIDIA Sentry on BlueField to extend policy enforcement from the agent runtime into this separate trust domain, enabling infrastructure and network controls to operate independently of the agent itself.
NVIDIA Sentry is a real-time watchdog that adds another layer, monitoring agent behavior and enabling an agent exhibiting unsafe behavior to be quarantined. Together, these capabilities demonstrate a broader system-level security model: Arm CPUs can host and run agent workloads, while Arm-based DPUs can independently observe, govern, isolate and help protect them.
Scaling agentic AI securely #
Agentic AI will require more compute as agents become more capable, persistent, and autonomous, but it will also require security to scale alongside that compute, without forcing a tradeoff between the two.
NVIDIA’s Open Agent Safety Platform demonstrates this approach, with Arm-compatible compute running agent workloads and independent Arm-based DPUs helping observe, isolate and protect them.
As agents expand from cloud infrastructure to edge devices and physical systems, these security boundaries will need to follow wherever agents run and act. With Arm increasingly at the heart of AI infrastructure, we have an important role to play in helping the ecosystem scale both performance and security together.
The agentic era is being built on Arm, and we’re committed to helping make it secure from the start.
Any re-use permitted for informational and non-commercial or personal use only.