Key takeaways
- CrowdStrike and NVIDIA expanded their strategic collaboration around the NVIDIA Open Agent Safety Platform, establishing independent security controls across software, runtime, and silicon layers.
- The architecture pairs NVIDIA OpenShell runtime governance with NVIDIA Sentry on BlueField-4 DPUs, enabling out-of-band monitoring and millisecond-level quarantine for errant agents.
- Telemetry from NVIDIA DOCA Argus feeds into CrowdStrike Falcon Next-Gen SIEM, giving enterprise security teams infrastructure visibility to correlate agent data access with threat intelligence.
- The approach separates enforcement from model behavior, treating autonomous AI agents as privileged identities governed by external Zero Trust policies rather than self-policing logic.
CrowdStrike and NVIDIA have expanded their strategic collaboration to secure enterprise autonomous AI agents through the newly announced NVIDIA Open Agent Safety Platform. The open reference architecture combines NVIDIA software and hardware isolation mechanisms with the CrowdStrike Falcon cybersecurity platform. By establishing independent controls across execution runtimes, operating environments, and Data Processing Unit (DPU) silicon, the joint architecture addresses a fundamental operational problem: autonomous agents cannot serve as their own security boundary when executing tasks across critical enterprise systems.
Multi-layered isolation across silicon and runtimes
The NVIDIA Open Agent Safety Platform introduces a multi-tiered defense structure designed to govern agent actions from code execution to physical silicon. At the software tier, NVIDIA OpenShell provides an open-source secure runtime that restricts how agents execute instructions, isolates inference environments, and bounds access to external tools and internal data stores. This runtime integrates with the joint Secure-by-Design AI Blueprint, which embeds Falcon governance and policy guardrails directly into the agent execution lifecycle.
Hardware-level enforcement operates below the host operating system. NVIDIA Sentry functions as an independent security watchdog hosted on NVIDIA BlueField-4 DPUs. Utilizing NVIDIA DOCA software frameworks, Sentry performs out-of-band inspection of agent activity, verifies cryptographic workload identity, and enforces Zero Trust access rules across network interfaces, storage arrays, and enterprise APIs. Because Sentry operates in silicon independently of the host CPU running the model, it can detect policy violations and isolate or quarantine compromised agents within milliseconds without relying on the host operating system.
| Architecture Layer | Enforcement Technology | Primary Security Function |
|---|---|---|
| Software & Runtime | NVIDIA OpenShell | Constrains execution boundaries, sandboxes inference, and governs tool invocation |
| Hardware & Network | NVIDIA Sentry on BlueField-4 DPUs | Provides out-of-band telemetry, attests agent identity, and executes millisecond isolation |
| Enterprise Context | CrowdStrike Falcon Platform | Correlates agent telemetry with threat intelligence and enterprise-wide identity state |
Why autonomous agents demand independent security boundaries
Traditional enterprise security models never permit an application or operating system to act as its own sole arbiter of compromise. Enterprise architectures deploy firewalls, endpoint sensors, and external identity providers to monitor workloads objectively. Autonomous agents represent a distinct operational challenge because their nondeterministic execution paths make internal software boundaries unreliable. Model system prompts and internal guardrails can guide output tone, but they remain vulnerable to indirect prompt injection, tool misuse, and context manipulation.
When enterprises grant autonomous agents persistent identities, system credentials, and direct API access to corporate databases, those systems can introduce significant operational hazards. As noted in discussions surrounding how AI agents introduce insider security risks, software agents capable of executing transactions require supervisory mechanisms that operate outside the model’s reasoning loop. The joint CrowdStrike and NVIDIA approach treats agents as privileged digital identities subject to least-privilege policies, explicit authorization gates, and continuous external behavioral analysis.
Operational impact for enterprise IT and security teams
For enterprise IT directors, security architects, and platform engineering leads, this reference design shifts agent monitoring from fragmented application logs to unified Security Operations Center (SOC) workflows. CrowdStrike has integrated NVIDIA DOCA Argus telemetry into CrowdStrike Falcon Next-Gen SIEM. This integration enables defenders to ingest infrastructure-level network and compute events directly from DPUs, allowing security analysts to evaluate whether an agent accessing sensitive files or initiating lateral connections aligns with normal operational baselines.
The initiative complements existing capabilities within CrowdStrike Falcon Guardian and Falcon Cloud Security integrations with NVIDIA NIM microservices, which safeguard AI factories against dataset tampering, model poisoning, and unauthorized extraction across the model deployment lifecycle. Organizations recognized by industry analysts, such as those evaluating proactive security platforms, increasingly require this unified posture across legacy workloads and emerging agentic deployments.
Infrastructure constraints remain an important evaluation factor. While the NVIDIA OpenShell runtime can be implemented across standard containerized environments, the hardware-enforced out-of-band monitoring provided by Sentry requires data center servers configured with BlueField-4 DPUs. Organizations running agent workloads on standard cloud compute instances without dedicated DPU acceleration will need to rely primarily on software-level runtime controls until compatible hardware becomes standard in public cloud fleets.
What happens next
NVIDIA is releasing the Open Agent Safety Platform as an open reference design, allowing third-party security vendors, cloud hosting providers, and systems integrators to incorporate the runtime specifications and hardware hooks into their platforms. CrowdStrike plans to expand Falcon platform integrations, providing deeper runtime monitoring and automated remediation actions tailored to multi-agent architectures.
IT and cybersecurity leaders should review existing internal agent deployments to catalogue what credentials and database permissions autonomous tools currently possess. Security teams planning large-scale agent rollouts should evaluate whether their host infrastructure supports hardware-assisted inspection through DPUs or if immediate security postures must rely on runtime sandboxing and identity federation.
Sources
- CrowdStrike and NVIDIA Extend Security Across the AI Stack
- NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment | NVIDIA Newsroom
- CrowdStrike and NVIDIA Unveil Secure-by-Design AI Blueprint for AI Agents
- CrowdStrike and NVIDIA Bring Enterprise-Grade Security to AI Factory
- NVIDIA Partnership Redefines Cybersecurity with Always-On AI Agents
- CrowdStrike, NVIDIA unveil ‘secure-by-design’ autonomous AI agent blueprint – Cyber Daily
- CrowdStrike and NVIDIA Secure Full LLM Lifecycle for AI


