# CSA Welcomes NVIDIA Open Agent Safety Platform

> Source: <https://cloudsecurityalliance.org/articles/cloud-security-alliance-welcomes-nvidia-open-agent-safety-platform-to-advance-its-mission-of-securing-the-agentic-control-plane>
> Published: 2026-09-28 20:52:00+00:00

# CSA Welcomes NVIDIA Open Agent Safety Platform

Published 09/28/2026

**Written by**

**Jim Reavis**

**,**

**Co-founder and Chief Executive Officer, CSA**

**.**

Cloud Security Alliance is building industry consensus around governance and security controls for autonomous AI. We welcome the launch of the [NVIDIA](https://nvidianews.nvidia.com/news/open-agent-security-platform) [Open](https://nvidianews.nvidia.com/news/open-agent-security-platform) [Agent Safety Platform](https://nvidianews.nvidia.com/news/open-agent-security-platform) and NVIDIA’s commitment to making autonomous AI safer to deploy at enterprise scale. NVIDIA is bringing its engineering capabilities across software and hardware to one of the most consequential challenges facing our industry: giving agents the freedom to do useful work while maintaining control over their access and actions. In a world that will someday have trillions of agents, we strongly support that mission and the opportunity it creates for enterprises to move forward with confidence.

As agents take on more responsibility, organizations need to connect their capabilities to established governance and risk objectives. A security leader approving an agent for production needs to understand its authority, the boundaries on its behavior, and the evidence that those boundaries hold. Developers need a practical way to implement those requirements without rebuilding security for every agent or workflow.

The NVIDIA Open Agent Safety Platform addresses this need through complementary infrastructure layers. NVIDIA OpenShell software provides a secure runtime governing agent execution, access to resources, and inference routing. NVIDIA Sentry, an out-of-band watchdog running continuously on [NVIDIA BlueField](https://www.nvidia.com/en-us/networking/products/data-processing-unit/)[™](https://www.nvidia.com/en-us/networking/products/data-processing-unit/)[-4](https://www.nvidia.com/en-us/networking/products/data-processing-unit/) DPUs and built on [NVIDIA DOCA](https://www.nvidia.com/en-us/networking/products/software/doca/)~~™~~ software extends enforcement into hardware infrastructure operating independently of the host, bringing in-silicon identity governance, threat detection, and isolation between tenants. NVIDIA Vera CPU systems provide compute for the demanding workloads that autonomous agents generate. Together, these capabilities create a substantial foundation for running agents with security integrated into their operating environment.

We are particularly encouraged by NVIDIA’s emphasis on enforcement outside the agent’s execution environment. This gives organizations a way to establish boundaries that operate independently of an agent’s reasoning. OpenShell’s open approach and support for different models and agent frameworks also give the security community a practical implementation around which to contribute, learn, and improve.

At CSA, we describe the governance and security mechanisms surrounding autonomous action as **Securing the Agentic Control Plane**. Our vision is to build industry consensus around the controls that platforms such as NVIDIA’s support, so customers can understand how a deployment aligns with their own governance and risk objectives. This work connects enterprise policy to runtime behavior and the evidence needed to demonstrate accountability.

The AI Controls Matrix (AICM) provides the foundational governance and control objectives. It helps organizations determine what must be protected, who is responsible, and how AI security fits into existing risk management. For customers evaluating the NVIDIA Open Agent Safety Platform, this provides a common starting point for connecting infrastructure capabilities to enterprise requirements.

STAR for AI provides the trust pathway, including third-party assurance through its Level 2 program. Independent assessment helps customers establish confidence in an AI service’s governance and controls within a defined scope. Our vision is for evidence from agent infrastructure and its operation to support that assurance process, making security capabilities easier for customers and assessors to evaluate.

The Agentic Trust Framework provides the Zero Trust architecture for agents. It connects verified identity, observed behavior, data governance, segmentation, and incident response to the autonomy an organization grants. This helps enterprises place runtime controls within a broader architecture that maintains oversight as agents take on more consequential work.

One potential connection between this governance vision and the NVIDIA Open Agent Safety Platform is Autonomous Action Runtime Management (AARM). AARM defines granular requirements for governing agent actions at execution time. These include interception before execution, evaluation against policy and task context, explicit authorization decisions, and tamper-evident records bound to agent identity. It gives enterprises and technology providers a shared specification for describing what runtime security must accomplish.

Consider a coding agent assigned to fix a defect. It needs access to an approved repository and development tools. Publishing a production release may require separate authorization. AARM provides requirements for evaluating that distinction at the moment of action, including when to require human approval or defer execution. OpenShell supplies concrete enforcement capabilities around the agent’s environment. Mapping those capabilities and the surrounding enterprise controls to AARM would help customers understand how the complete deployment meets their requirements.

That connection between specification and implementation is valuable to everyone involved. Enterprises gain a consistent basis for evaluating deployments. NVIDIA and its ecosystem gain clearer customer requirements and a common language for explaining how complementary controls work together. Implementation experience can, in turn, improve the standards. We see a strong opportunity for the community to develop practical mappings, tested policy patterns, and reusable evidence around the platform.

Security Analysis and Guidance Exchange (SAGE) provides a common format for sharing policy and security reasoning between people and the systems that govern agents. It combines human-readable Markdown with YAML metadata, JSON Schema validation, and safeguards for provenance and integrity. Our vision is to connect that guidance to the agent control substrate through validated integrations, keeping policy understandable to the people accountable for it.

For customers, the intended result is a traceable connection from a governance objective to an architectural decision, a runtime policy, and evidence of what happened. That can make deployment reviews more consistent and help organizations expand agent use within their risk tolerance. The most useful measures will include how quickly teams can approve a new use case, how clearly they can explain its permissions, and how reliably they can demonstrate that controls operated as intended.

NVIDIA deserves credit for investing in the infrastructure needed to make this future practical. CSA welcomes the opportunity to contribute our research community and consensus standards to that mission. We encourage enterprises, developers, and security providers to explore the NVIDIA Open Agent Safety Platform and bring their implementation experience into the standards process. Together, we can make secure, accountable autonomy easier to implement and easier to trust.

### Resources

NVIDIA: [OpenShell](https://build.nvidia.com/openshell) | [Documentation](https://docs.nvidia.com/openshell/about/overview) | [GitHub repository](https://github.com/NVIDIA/OpenShell) | [BlueField](https://www.nvidia.com/en-us/networking/products/data-processing-unit/) | [DOCA](https://www.nvidia.com/en-us/networking/products/software/doca/)

CSA: [AICM](https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1) | [STAR for AI](https://cloudsecurityalliance.org/star/ai) | [Agentic Trust Framework](https://cloudsecurityalliance.org/artifacts/operationalizing-the-agentic-control-plane-integrating-the-agentic-trust-framework) | [AARM](https://aarm.dev/spec) | [SAGE](https://labs.cloudsecurityalliance.org/sage/)

###### Unlock Cloud Security Insights

*Subscribe to our newsletter for the latest expert trends and updates*

###### Related Articles:

###### [The Vital Trifecta](https://cloudsecurityalliance.org/articles/the-vital-trifecta)

**Published:** 09/24/2026

###### [Lessons Learned on Securing Multi-Agent Systems: NIST Agent Security RFI](https://cloudsecurityalliance.org/articles/lessons-learned-on-securing-multi-agent-systems-nist-agent-security-rfi)

**Published:** 09/23/2026

###### [A New Security Challenge: The Curious Case of Prompt Language Analysis](https://cloudsecurityalliance.org/articles/a-new-security-challenge-the-curious-case-of-prompt-language-analysis)

**Published:** 09/22/2026

###### [The Human-Machine Partnership: Architectures for Reliable AI](https://cloudsecurityalliance.org/articles/the-human-machine-partnership-architectures-for-reliable-ai)

**Published:** 09/21/2026
