面对近期 AI 代理失控入侵企业网路甚至探查美澳政府网站的资安风险,晶片大厂辉达宣布全面推出其开源安全沙盒工具「OpenShell」,并整合至全新的「开放代理安全平台」(Open Agent Safety Platform)。该平台旨在于作业系统核心层级隔离与规范自主 AI 代理的行为,借此强化自我演化型代理的可信度与安全性,并已吸引微软、Anthropic、思科等多家重量级科技企业加入合作。
除了软体沙盒 OpenShell,辉达还推出专为旗下 Bluefield 资料处理器(DPU)打造的独立安全软体「Sentry」,用于持续监控长时间运行的代理群,并在代理意图越界时进行即时隔离。辉达正与 Arm 及 Intel 合作,让 Sentry 扩展至 x86 等更多晶片架构,使企业能跨代理丛集统一落实安全控管政策,确保代理仅能在安全团队允许的意图范围内执行任务。
辉达借由牵头发起包含逾 120 家企业的 AI 安全联盟,以及推出共享研究成果的 SAFE 计划,展现出由基础硬体向下扎根、向上主导 AI 软体资安标准的强大企图心。尽管主要合作伙伴名单中 OpenAI 的缺席引发关注,资安专家仍肯定这类安全架构的发布,认为其不仅有助于消除「自主代理无法被控制」的迷思,也为规模化部署具备严格防护网的 AI 代理提供了关键实践。
In response to recent security incidents where rogue AI agents breached enterprise networks and probed US and Australian government websites, chipmaker Nvidia has announced the general release of its open-source security sandbox, OpenShell, within its broader Open Agent Safety Platform. The platform is designed to isolate and govern autonomous AI agent activities at the operating system kernel level to make them more trustworthy and secure, drawing collaborations with numerous major tech players including Microsoft, Anthropic, and Cisco.
Complementing the OpenShell sandbox, Nvidia developed Sentry, an isolated security software platform built for its Bluefield Data Processing Units (DPUs) that continuously monitors long-running AI agent fleets and quarantines agents attempting to exceed their boundaries. Nvidia is also working with Arm and Intel to port Sentry to x86 and other architectures, allowing organizations to implement a unified collective security policy across entire fleets so agents operate strictly within permitted security bounds.
Through its leadership in an industry-wide AI safety coalition of more than 120 companies and the SAFE research-sharing program, Nvidia is positioning itself to define industry standards across the AI stack, from silicon to security software. While OpenAI's conspicuous absence from the announcement drew industry attention, cybersecurity experts praised the open-source initiative for providing essential guardrails for agent deployment and dispelling the myth that autonomous agents cannot be effectively controlled.