NVIDIA moves agent identity and delegated-authority checks into the runtime

NVIDIA has introduced an open agent safety stack built around OpenShell, a secure runtime that sandboxes each autonomous agent, plus an independent monitoring and enforcement layer that extends into BlueField hardware through NVIDIA DOCA.

OpenShell turns the operator’s instructions into a verifiable policy: operators define which files, networks, tools, processes and credentials an agent can reach, and those limits are checked before the agent runs and enforced as it works.

The DOCA gateway adds identity governance on top of that behavioural protection. In NVIDIA’s words, it “continuously verify[ies] each agent’s identity and delegated authority to ensure it operates within its assigned scope.” Enforcement is deliberately out of band — the controls do not sit inside the agent, on the premise that “an agent… cannot be expected to fully govern its own behaviour.”

Why it matters for KYA

This is identity and authority checked at runtime, not only at onboarding, and it maps onto the “continuous verification” half of principal, permissions and trust history of an autonomous AI agent before it acts.”>Know Your Agent. For practitioners it is a concrete pattern for per-agent identity, scoped credentials, and enforcement at every boundary rather than a single gate.

Sources


Know Your Agent (KYA) explains agent identity, verification and accountability. This is an explainer, not legal or compliance advice — see our Sources & methodology. New to KYA? Start with What is Know Your Agent? and the glossary.