Beyond Intelligence: How Trust Is the Benchmark That Matters in AI NVIDIA announced its Open Agent Safety Platform, an open software platform and reference system design that combines NVIDIA OpenShell open-source software for secure agent execution with the NVIDIA Sentry reference system design, an out-of-band watchdog running on NVIDIA BlueField-4 DPUs. Cisco said it will collaborate with NVIDIA to deliver an agentic trust solution that pairs the Open Agent Safety Platform with Cisco's Hypershield, AI Defense, Agentic Identity and Access Management, Agent Observability, and Splunk to protect agent deployments across data centers, public clouds, neoclouds, campuses and branches, industrial facilities, and robotics. The announcement frames trust, rather than model intelligence, as the constraint on how fast AI agents are adopted. Trust is the most important concept in AI today. For three years, we’ve been focused on making AI smarter. It’s been about what a model can do, benchmarks, context windows, reasoning scores, and so on. Those are important, but a quick scan at the news recently is all it takes to show us that the more consequential question today is what we think agents should be permitted to do? When you interact with a truly functional AI agent – whether it’s a personal agent or one you’re using at work – you immediately feel the weight of this question. Should this agent have access to my email? My credit card? Am I ok with this agent provisioning environments or making changes to a production system? How about resolving a customer’s problem from beginning to end. This is the difference between AI as an assistant that’s helping you in the moment, and AI that’s acting as an operator on your behalf. And it reveals fundamental tension. The more access and autonomy we give an agent, the more effective it becomes, but the more access and autonomy we grant, the greater the risk. That’s why trust, not intelligence, will be the true governor on how fast AI adoption can move. It’s the final boss of making AI part of our everyday lives and truly useful. Building Agent Safety Importantly, when I talk about trust, I’m not referring to an abstract idea or sentiment. I’m talking about an engineering problem, and engineering problems can be solved. Today, NVIDIA announced its NVIDIA Open https://nvidianews.nvidia.com/news/open-agent-safety-platform Agent Safety Platform https://nvidianews.nvidia.com/news/open-agent-safety-platform , an open software platform and reference system design to help secure agents from testing through deployment. It combines NVIDIA OpenShell open-source software for secure agent execution with the NVIDIA Sentry reference system design, an out-of-band watchdog running on NVIDIA BlueField-4 DPUs https://www.nvidia.com/en-us/networking/products/data-processing-unit/ . This goes beyond attempts to control an agent with a harness. It delivers an external control that has the full context of agents running in these environments. Understanding an agent’s intention or mission requires a deep understanding of the environment in which it’s running. Cisco and NVIDIA share a belief that a standards-based view of AI workloads, no matter where they run across an organization, is critical to making agent behavior observable and policies enforceable. Building on the success the two companies have enjoyed working on the Cisco Secure AI Factory with NVIDIA, Cisco is excited to collaborate with NVIDIA to deliver an agentic trust solution that leverages NVIDIA Open Agent Safety Platform along with Cisco’s Hypershield, AI Defense, Agentic Identity and Access Management, Agent Observability, and Splunk to protect agent deployments across data centers, public clouds, neoclouds, campuses and branches, industrial facilities, and robotics. This integrated stack has the depth needed to understand agentic intent and apply the fine-grained controls required to give agents access to resources they need while protecting the organization and the world from harm. Effective agentic controls need to be able to understand the full context of an agent, especially its intent. This requires a sophisticated policy engine that can understand the semantics of an agent interacting with tools and resources and can apply reasoning to the interaction. In short, the policy engine needs to be able to examine an agent’s actions and ask “does this look right” in very fine-grained detail. This kind of dynamic policy must be centralized, while enforcement should be distributed. Agents don’t queue up at a chokepoint, so the controls that govern them must sit wherever the agent is. That could be in the Operating System kernel, network, cloud, and the edge. But distributed enforcement produces distributed evidence, and that is where this approach usually falls apart. Point solutions may only see a small part of the bigger picture. If an agent’s actions live in one of a dozen consoles or containers, none of them have a singular view of what the agent did. Therefore, the record must converge even as the enforcement spreads out, which ultimately means we need one system of record for agentic policy control across the enterprise. What distributed workloads taught us A few years ago, we bet that security could no longer be something traffic passes through at the perimeter of the enterprise. Applications had spread across data centers, clouds, containers and edges, changing faster than any security team could review them. Security had to become hyper-distributed, with the network, the server, the kernel and the cloud container each acting as a control point rather than a transit path. That’s why we built Hypershield inside our Hybrid Mesh Firewall, created Smart Switches capable of inspecting and enforcing policy at every port, and why we continue to accelerate investment in eBPF, Cilium, and Tetragon through Isovalent. Enforcement in the kernel, next to the workload, is the only kind that keeps pace with a workload that moves. We built this architecture for distributed applications, but it turns out that agents need it even more urgently, because an agent in typical enterprise deployments doesn’t simply run in one place. It reaches beyond its container. It calls tools it didn’t write, deploys code it won’t stay to supervise, and delegates to agents in environments its operator doesn’t own. Agents need to interact with other agents or other tools to get their jobs done. This is the main challenge. How do we keep track of these busy entities that run at machine speed? No single vendor can solve this by themselves. The signal that should tighten a guardrail is never on the machine that raised the alarm. It’s in the network, in identity, in the cloud control plane, on the endpoint, and across every vendor in the estate. Engineering agentic trust into the enterprise Agentic trust has to be built everywhere agents live, which is more ground than any one layer covers. NVIDIA Open Agent Safety Platform combines OpenShell runtime controls with Sentry’s hardware-isolated agent governance, threat detection, attested telemetry, and millisecond-scale quarantine on BlueField-4. Cisco complements these capabilities across networks, applications, identity, and security operations to extend agent trust throughout organizations of any size and sophistication. We are working with NVIDIA Open Agent Safety Platform in several ways: - In the kernel. Cilium and Tetragon enforce at the process and system-call level, complementing NVIDIA https://build.nvidia.com/openshell OpenShell https://build.nvidia.com/openshell runtime controls and NVIDIA Sentry’s out-of-band protection on BlueField-4 DPUs. Cisco continues to lead and accelerate innovation in Cilium and Tetragon with NVIDIA and the rest of the open-source community to ensure that “in kernel”-level process visibility and enforcement is a reality. - Across networks and clouds. Hypershield carries enforcement everywhere the AI factory isn’t — cloud, campus, branch, industrial edge, robotics — and alongside the workloads an agent deploys and walks away from. Hypershield works with NVIDIA BlueField DPUs and DOCA, as well as Cisco’s SmartSwitches and workload agents, to provide distributed security and real-time threat detection. We are also extending Hypershield to leverage the NVIDIA Open Agent Safety Platform, so that a single policy governs an agent wherever it goes: written once and enforced by whichever control point sits closest to the action. - At the application layer. Cisco AI Defense integrates with DefenseClaw to validate and red-team agent models, assess tools, skills, and MCP servers before use, and enforce policy across agent, MCP, and tool activity. DefenseClaw has an integration with OpenShell limiting agent’s filesystem, process, network and inference access. Furthermore, Agent observability checks intended behavior and the integrity of skills, memory, and tools. - Across identity and access. Containment is the floor; this is what gets built on top of it. Zero Trust has to be reimagined for agents — non-human identity, delegated authority, and per-action authorization in place of standing access. It starts with discovery, finding every agent running anywhere in the enterprise including the ones nobody registered, and it ends with the ability to widen or revoke what any one of them can do, in real time. That is how you grant autonomy rather than simply restrict it. - At machine speed and scale. Cisco Data Fabric powered by Splunk Platform is the system of record for agents combining telemetry from across the ecosystem and the NVIDIA Open Agent Safety Platform, including Sentry’s attested telemetry to help correlate agent activity and policy decisions with broader enterprise security signals. With a system of record capable of handling agent-scale data volumes economically, we can understand the difference between malicious actions and “bad behavior” everywhere agents run. Splunk Agent Observability gives insight into agent reasoning paths and enables fine-tune agent behavior at scale. Splunk’s Agentic SOC provides detection and response of agent threats at machine speed and scale. Cisco and Nvidia have been building toward this reality for a while. We built the Secure AI Factory with NVIDIA so enterprises could stand up AI infrastructure that was secure on day one. We have driven switching and networking innovation together to make that infrastructure fast enough to be worth building, and we’re also developing important industry-specific models built on Nemotron. Delivering agentic trust is the next step of this journey. The security stack for autonomous agents is going to be infrastructure the entire industry depends on. Infrastructure like that belongs in the open, where the people relying on it can inspect it, challenge it, and improve it. That is a conviction we share with NVIDIA, and it is how we intend to keep building together. Agents are arriving faster than anyone predicted. If we want them to be as helpful and powerful as we believe they can be, trust has to travel with them everywhere we put them to work. Stay up on Thought Leadership from Cisco Get the latest blogs from Cisco Executives in your email. Subscribe to the Executive Platform https://app.feedpress.com/e/mailverify?feed id=CiscoExecutivePlatform Executive Perspectives Navigate the latest technology trends and get solutions with the help of Cisco executives. Go to Executive Perspectives https://www.cisco.com/c/en/us/solutions/executive-perspectives/index.html