Giving companies more control over their AI agents, with NVIDIA
- ID
- 29553
- Status
- summarized
- Published
- 28 Sep 2026, 8:00 AM
- Fetched
- 29 Sep 2026, 8:11 AM
- Provider
- Claude
- Category
- ai-labs
- Original URL
- https://claude.com/blog/giving-companies-more-control-over-their-ai-agents-with-nvidia
- Source URL
- https://raw.githubusercontent.com/leontloveless/ai-rss-feeds/main/feeds/claude.xml
Summary
- Score
- 6.0
- Created
- 29 Sep 2026, 8:11 AM
- Tags
- Audience
- developersai_ml_learnersai_agent_userssaas_startup_founders
What happened
NVIDIA announced the Open Agent Safety Platform, an open software platform and reference system design for AI agent security, with Anthropic as a collaborator. Two components are named: Claude Managed Agents, which runs the agent loop on a server separate from the sandbox and keeps credentials (passwords, access keys) in a vault so the agent never sees them, plus audit trails and hooks into existing access controls; and NVIDIA OpenShell, open source runtime software that is deny-by-default — it blocks everything unless a rule allows it and checks each tool an agent tries to use against rules on files, network connections, and data. The post argues for independent, modular layers because the more access an agent gets, the more a company needs to constrain and verify it.
Why it matters
If your agent stack passes raw API keys or database credentials into the model context, this announcement describes a concrete alternative pattern worth copying regardless of vendor: keep secrets in a separate vault the agent never reads, run the agent loop on a different server from the execution sandbox, and gate tool calls deny-by-default. The practical decision for a Malaysian team shipping agents against payment gateways or internal systems is whether to adopt a vendor-managed credential vault and audit trail or build the same separation yourself — the post gives architecture, not benchmarks, pricing, or migration steps, so treat it as a design reference rather than a product you can evaluate today.
Discussion angle
Would you let a vendor hold your agents' credentials in its vault and enforce the tool-call policy, or do you keep that inside your own infra? Walk through what your current agent actually has access to — payment keys, internal APIs, DB — and whether it can currently see them in plaintext.