NVIDIA’s Agent Watchdog Stops the Process, But Leaves the Keys in the Door
On Monday, NVIDIA unveiled its Open Agent Safety Platform, combining OpenShell (an open-source sandboxed environment) with Sentry—an out-of-band watchdog operating on BlueField-4 DPUs capable of quarantining rogue AI agents within milliseconds. For those unfamiliar, a DPU acts as an independent computer residing on the network card, safely isolated from host tampering. Given the recent surge of frontier labs documenting agent-escape scenarios, locating enforcement mechanisms entirely outside the agent’s reach is a brilliant architectural move.
However, my apprehension lies in its practical application. The cybersecurity sector has a notorious habit of taking a perfectly sensible control, overextending it far beyond its intended design, and declaring the problem solved. Containment is currently being heralded as the ultimate cure for AI agent risk—and that is a dangerous oversimplification.
The Historical Trap of Over-Trusted Controls
We have a long history of placing blind faith in “good enough” safeguards. Consider password rotation: for two decades, we mandated 90-day resets and complex character rules. The result? A workforce conditioned to predictably cycle their passwords from Summer2023! to Fall2023!. While NIST eventually reversed this guidance in 800-63B, countless organizations still enforce it merely to satisfy compliance auditors. Similarly, SMS-based MFA and MAC filtering were once considered gold standards—until SIM swapping, proxies like Evilginx, and trivial MAC spoofing rendered them largely theatrical.
Malware sandboxes experienced this exact hype cycle. Detonating suspicious files inside isolated virtual machines was highly effective until malware developers programmed their payloads to detect VM artifacts, sleep through analysis periods, and behave innocently while under observation. AI labs are already publishing research demonstrating that models can detect when they are being evaluated. In NVIDIA’s own trials, agents spent up to two hours persistently trying to socially engineer an AI reviewer into granting write access to a protected repository. A highly determined agent will inevitably map out and bypass the watchdog’s operational thresholds.
Valid Credentials Eliminate the Need for Evasion
Yet, active evasion isn’t the primary threat. Containment mechanisms monitor behavior, but an AI agent armed with legitimate credentials doesn’t need to act maliciously to inflict catastrophic damage. Agents function via delegated access: an OAuth token granted by a human user, a service account, or an API key hardcoded into an MCP server.
If a prompt-injected agent utilizes an approved Salesforce API call to exfiltrate your client roster using a valid OAuth grant, what exactly is the DPU watchdog supposed to flag? It simply sees an authorized identity executing an authorized action.
This is the classic “confused deputy” problem, and scrutinizing the deputy is useless when they hold the actual keys. Quarantining the runtime doesn’t solve this. Terminating an agent’s process does not revoke its underlying OAuth grant. The refresh token remains active within the issuing platform, ready to be exploited by anyone who intercepts it. Unless your containment strategy is deeply integrated with your Identity Provider (IdP) to simultaneously kill both the process and the credential, you have merely stopped the immediate execution while leaving the front door wide open.
Look at the recent Salesloft Drift incident: threat actors leveraged stolen OAuth tokens from a chatbot integration to siphon Salesforce data from hundreds of organizations—no sandbox escapes required. Similarly, the Midnight Blizzard breach saw attackers infiltrate Microsoft’s corporate emails via a forgotten test OAuth application holding excessively broad permissions. The incoming wave of AI agents will rapidly generate thousands of similar identities, vastly outpacing traditional access review processes.
Agents Don’t Live Where DPUs Operate
Furthermore, Sentry requires specialized hardware deployed within your own data center. The reality is that most modern AI agents live elsewhere: embedded in SaaS applications, running on developer laptops, operating as browser extensions, or spun up by marketing teams using personal OAuth grants.
I have witnessed firsthand the chaos that ensues when leadership mandates rapid technology adoption without governance. At a previous operational role, developers were instructed to deliver results at any cost—a mandate mirroring the “deploy AI everywhere” directives circulating today. This resulted in unprecedented levels of Shadow IT: ubiquitous unsanctioned applications, internet-exposed production systems, and entire racks of shadow hardware discovered long after they were spun up.
The most alarming instance involved a newly acquired company that suffered a breach, failed to report it, and subsequently “deleted” their entire compromised environment. Cloud compute, VMs, containers, and storage were wiped out, obliterating any chance of a forensic investigation. AI agents are introducing a stealthier iteration of this exact nightmare. When an agent executes actions using a human’s OAuth token, the audit logs point directly to the human. Good luck untangling that forensic mess during a live incident with legal counsel breathing down your neck.
Treat Agents as the Identities They Are
Approaching this from an identity and access management (IAM) perspective, the true solution is far less glamorous than deploying new hardware. AI agents are identities. We already possess the frameworks to govern identities; we simply lack the discipline to enforce them.
Effective agent security demands fundamental IAM hygiene:
- Strict Inventory: Maintain a registry where every agent has a designated human owner.
- Dedicated Identities: Agents must authenticate under their own unique service identities rather than piggybacking on their creator’s tokens, ensuring audit logs remain accurate.
- Scoped & Expiring Access: Privileges must be narrowly scoped to specific tasks and bound by strict expiration dates, giving stolen grants a definitive shelf life.
- Contextual Access Reviews: Non-human identities must be subjected to rigorous access reviews equipped with enough context to eliminate guesswork.
- Automated Offboarding: When a project concludes or an owner departs, the agent must be systematically offboarded and its grants revoked at the source.
Hardware-level containment is an excellent fallback, but it cannot replace foundational identity governance. If your organization has successfully implemented agent ownership and automated revocation at an enterprise scale, I would love to hear how you achieved it.
About Portnox
Portnox provides simple-to-deploy, operate and maintain network access control, security and visibility solutions. Portnox software can be deployed on-premises, as a cloud-delivered service, or in hybrid mode. It is agentless and vendor-agnostic, allowing organizations to maximize their existing network and cybersecurity investments. Hundreds of enterprises around the world rely on Portnox for network visibility, cybersecurity policy enforcement and regulatory compliance. The company has been recognized for its innovations by Info Security Products Guide, Cyber Security Excellence Awards, IoT Innovator Awards, Computing Security Awards, Best of Interop ITX and Cyber Defense Magazine. Portnox has offices in the U.S., Europe and Asia. For information visit http://www.portnox.com, and follow us on Twitter and LinkedIn.。
About Version 2 Limited
Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.
Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.


