Agent Security Is Moving Into Silicon. Anjuna Is Already There.

Agent security moving into silicon with Anjuna Confidential Computing
NVIDIA's "force field" for AI agents moves enforcement into silicon. Anjuna goes further, protecting the governance layer itself inside an attestable Confidential Computing boundary.
https://www.anjuna.io/blog/agent-security-is-moving-into-silicon

On Monday in a CNBC interview, NVIDIA’s CEO Jensen Huang described the security model for AI agents as a “force field.” The idea is straightforward and has been used by government agencies and enterprises for years to protect from insider threat: take away an agent’s rights by default, then grant back only the access it needs to perform its job.

That is how we protect sensitive data from human access, and that is exactly the right direction for enterprise AI security.

But Jensen went further. The force field cannot just be another layer of software. NVIDIA’s new Open Agent Safety Platform combines OpenShell, which constrains agent access and behavior, with Sentry on BlueField hardware, moving monitoring and enforcement into silicon. That matters because it validates a principle Anjuna has been building around for years: when software itself may be compromised, software cannot be the ultimate root of trust.

The important difference is that Anjuna does not stop at putting hardware beside the agent to watch it. We use Confidential Computing to protect the governance layer itself. That means the policy engine, enforcement logic, credentials and runtime state can execute inside a hardware-isolated, attestable environment that the agent, host operating system, cloud administrator or compromised infrastructure cannot simply inspect or modify.

That is a fundamentally different trust model.

A better sandbox is still a sandbox

OpenShell introduces meaningful controls, including deny-by-default network access, filesystem restrictions, reduced privileges, credential brokering and policy enforcement. These are important improvements over relying on prompts or application-level controls to keep an agent within bounds.

But OpenShell also demonstrates the limitation of software-defined containment. NVIDIA has already patched critical OpenShell vulnerabilities, including issues capable of enabling sandbox escape. That is not a criticism unique to OpenShell. It is the reality of security software. Every parser, gateway, policy engine and privileged control component adds code that can itself become part of the attack surface.

Autonomous agents make this problem more acute. They can explore systems, combine weaknesses and change tactics at machine speed. Patching remains essential, but patching cannot be the root of trust, especially when the time to patch goes down to zero as models can find and exploit vulnerabilities in seconds. The architecture has to assume that some part of the surrounding software stack will eventually contain a vulnerability.

That is where Anjuna starts.

Would OpenShell have stopped Hugging Face?

NVIDIA has suggested that OpenShell could have prevented the recent Hugging Face incident, and there is a strong case that it would have interrupted several stages of the attack. A restrictive OpenShell policy could have limited outbound communication, constrained filesystem and system calls, and made credentials harder for an agent to obtain or misuse.

But the attack exposed a harder problem than simple network egress. The agents exploited infrastructure they were legitimately allowed to reach and converted permitted access into something more powerful. This is exactly where static containment begins to struggle: the question is not only whether an action is allowed, but whether the context, sequence and intent of the action should be trusted.

And there is an even more fundamental question: what happens if the agent finds a weakness in the control mechanism itself?

This is the distinction that matters. OpenShell can create a stronger software boundary. Sentry can place monitoring and enforcement in a separate hardware domain. This simply adds another step to the attack, it doesn’t prevent it.

Anjuna protects the control plane that makes the governance decision in the first place.

Protect the governor, not just the governed

Anjuna Overwatch was designed around a simple principle: an agent should not be trusted to govern itself, but neither should the infrastructure hosting the agent be implicitly trusted to govern it.

The policy and enforcement layer therefore needs its own trust boundary.

Overwatch can mediate agent actions, tool calls, credentials and access decisions from within a Confidential Computing environment protected by Anjuna Seaglass. The governance system can be isolated from the host and independently attested before sensitive credentials, policies or data are released.

This is a critical distinction.

A DPU can observe and constrain traffic around an agent. A sandbox can reduce the agent’s privileges. Anjuna protects the software that decides what the agent is allowed to do.

That means the organization does not have to assume that the operating system, hypervisor, cloud administrator or surrounding infrastructure is trustworthy simply because it hosts the security control.

The control itself can be independently verified.

From least privilege to least agency

For decades, security teams have applied least privilege to people and applications. Agents require the next evolution: least agency.

An agent should receive only the authority required for the task it is performing at that moment. Credentials should be brokered rather than handed over. Tool access should be conditional. Actions should be evaluated dynamically against policy and context rather than simply permitted because an identity was authenticated at the beginning of a session.

But least agency is only meaningful if the enforcement point cannot be manipulated by the agent, or by the environment the agent has compromised.

That is why hardware-secured governance matters.

NVIDIA is moving in this direction with OpenShell and Sentry. Anjuna takes the next step by placing the governance and enforcement logic itself inside an attestable Confidential Computing boundary.

This is not simply a “stronger sandbox”. It is a different model of trust.

Silicon is becoming the security boundary

The industry is now converging on something Anjuna has been saying for several years: security for autonomous software eventually has to move below ordinary software controls.

Jensen calls it a force field. NVIDIA talks about protecting and monitoring agents in silicon. We agree.

But the force field is only as trustworthy as the system controlling it.

Anjuna’s approach is to protect that system too.

Protect the agent. Protect the policy. Protect the credentials. Protect the governor itself. And root that trust in the silicon.

That is the difference between another guardrail and a trust boundary.

‍

See how Anjuna Overwatch enforces agent boundaries in real time, before they become an incident. Start Your Free Trial

More like this

Agentic AI Security