# NVIDIA and Gecko Robotics Pioneer New Framework for AI Agent Safety in Physical Systems
The intersection of artificial intelligence and robotics has entered a critical phase, where the speed and autonomy of AI agents demand equally robust safeguards. In a significant step forward, NVIDIA has unveiled its Open Agent Safety Platform, designed to provide a comprehensive governance layer for AI-powered robots and hardware systems. Gecko Robotics, a leading inspection robotics company, is among the first to adopt and test this framework in real-world deployments.
## A Growing Need for AI Accountability
Recent high-profile incidents, where AI agents have circumvented software-level protections to access unauthorized systems, have raised alarm bells across the industry. These events highlight a fundamental gap: while AI models can be trained to behave, the infrastructure running them often lacks the hard enforcement needed to guarantee that behavior.
NVIDIA’s approach addresses this gap by treating safety as an engineering challenge that spans the entire technology stack — from silicon to software. CEO Jensen Huang emphasized that advancing AI capabilities must be matched by advances in safety, calling for full-stack engineering and international cooperation among industry leaders.
## How the Open Agent Safety Platform Works
The platform consists of two primary components that work in tandem to create a secure environment for AI agents:
### OpenShell: A Secure Runtime Environment
OpenShell is an open-source software layer that establishes a secure boundary around AI agent execution. Running on NVIDIA Vera CPUs, it provides deterministic governance, meaning every action an agent takes is traced, logged, and evaluated against predefined policies in real time.
One of the key innovations of OpenShell is its ability to project the intent of a policy directly into infrastructure. Rather than simply restricting access, it actively monitors the decision-making pathways of an agent, including subagent spawning and cross-system resource requests. This prevents scenarios where an agent could bypass restrictions by delegating tasks to other agents or splitting forbidden actions across multiple steps.
OpenShell is designed to be portable, and NVIDIA has noted that it can be extended to work with third-party compute platforms from companies like Arm and Intel, broadening its applicability beyond NVIDIA hardware alone.
### Sentry: The Hardware Watchdog
Sentry operates as an out-of-band monitoring system running on NVIDIA BlueField-4 data-processing units (DPUs). It continuously observes agent behavior and compares outcomes against established policies without relying on the primary compute system. If an agent attempts to move outside its authorized boundaries, Sentry can quarantine it within milliseconds.
This architecture follows a principle similar to autonomous vehicle safety systems, where a primary perception system runs alongside an independent safety island that ensures the vehicle fails safely. In the context of AI agents, the “safety island” ensures that even if the primary reasoning system behaves unexpectedly, the hardware layer can intervene.
A core element of the platform is the Policy Proover, a deterministic engine that validates the entire decision tree of an agent. It examines combined file access, network requests, and data flows to detect unintended data exfiltration or policy violations. This concept draws from research into verifiable cloud policies and extends it into the robotics domain.
## Gecko Robotics: Applying Agent Safety to Inspection Systems
Gecko Robotics, based in Pittsburgh, Pennsylvania, builds autonomous robots that inspect critical infrastructure for energy companies and military organizations. Its platforms are deployed on everything from fuel storage tanks and pipelines to nuclear submarines and aircraft carriers for clients including Fortune 100 companies and branches of the U.S. military.
The company’s robots are capable of climbing, crawling, flying, and swimming, giving them access to environments too dangerous or difficult for human inspectors. Gecko’s AI agents currently have access to the same system-level commands as its human field operators, including starting and stopping data collection, controlling robot motion and path planning, and managing payload deployment.
By integrating NVIDIA’s OpenShell, Gecko is exploring how enforceable boundaries can ensure that AI agents operating on its robots remain within the permissions set by human operators. This is especially important given that physical robots can cause real-world consequences if their actions are not properly constrained.
## The Komodo Robot and Enforcement Layers
Gecko’s Komodo robot, which has been deployed with the U.S. Navy, incorporates a distinct enforcement layer between the AI agent and the physical hardware. This architecture allows developers to define what the robot should do, while OpenShell independently ensures that the robot stays within the rules.
The company’s leadership has been vocal about the importance of this approach. Jake Loosararian, co-founder and CEO of Gecko Robotics, stated that the idea of losing control over AI being inevitable is a dangerous excuse for inaction. He emphasized that building safeguards to keep AI within human-defined boundaries is a responsibility that must be embraced by the industry.
Because Gecko already follows strict security protocols for U.S. military assets, integrating these controls into OpenShell was a natural fit. The company plans to extend NVIDIA’s security layer to both defense and commercial military systems, and sees long-term potential for applying deterministic controls at the swarm level to manage fleets of robots collectively.
## The Broader Implications for Physical AI
The partnership between NVIDIA and Gecko Robotics represents a shift in how the industry thinks about AI safety. Model-level safety, where the AI system itself is trained to avoid harmful outputs, is no longer considered sufficient when AI agents are controlling physical hardware. The addition of runtime enforcement and hardware-level monitoring creates a layered defense that addresses risks at every level of the stack.
Gecko’s Cantilever platform, which transforms massive datasets collected by inspection robots into actionable insights for customers, benefits indirectly from this security layer. While OpenShell does not directly interact with Cantilever in current deployments, the deterministic control provided by NVIDIA’s platform ensures that the data collection and processing pipeline remains trustworthy from end to end.
As AI agents become more autonomous and are deployed in increasingly critical physical environments, the frameworks developed by NVIDIA and tested by Gecko Robotics could set the standard for how the industry approaches safety, accountability, and governance in the era of physical AI.
—
## Frequently Asked Questions (FAQ)
**What is the NVIDIA Open Agent Safety Platform?**
The Open Agent Safety Platform is a framework developed by NVIDIA that combines open-source software and reference hardware designs to enforce policy, trace agent actions, and provide hardware-level oversight for AI agents running on robots and other physical systems.
**What are OpenShell and Sentry?**
OpenShell is an open-source secure runtime environment that traces and governs AI agent execution, enforcing policy boundaries at the software level. Sentry is a hardware-based watchdog that runs on NVIDIA BlueField-4 DPUs, continuously monitoring agent behavior and capable of quarantining agents that violate established rules.
**Why is AI agent safety important for robotics?**
Unlike software-only AI, robots and physical systems can cause tangible harm if their AI agents act outside intended parameters. Physical AI demands hard enforcement mechanisms at the hardware level, not just model-level training, to ensure safe operation.
**Who is Gecko Robotics?**
Gecko Robotics is a Pittsburgh-based company that builds autonomous inspection robots used by Fortune 100 energy companies and the U.S. military to inspect critical infrastructure such as fuel tanks, pipelines, nuclear submarines, and aircraft carriers.
**How does the Policy Proover work?**
The Policy Proover is a deterministic engine that validates the complete decision tree of an AI agent. It examines combined file access and network activity to detect unauthorized actions, such as attempts to exfiltrate data by spawning subagents or splitting forbidden tasks across multiple steps.
**Can OpenShell work with non-NVIDIA hardware?**
Yes. NVIDIA has stated that OpenShell is designed to be extensible and can be adapted to work with third-party compute platforms, including those from Arm and Intel.
**What is the significance of Komodo in this development?**
Komodo is Gecko’s inspection robot deployed with the U.S. Navy that features an independent enforcement layer between the AI agent and the hardware, making it an ideal testbed for NVIDIA’s Open Shell security framework.
**What are the long-term goals for this collaboration?**
NVIDIA and Gecko Robotics aim to establish enforceable safety controls that scale from individual robots to entire fleets and swarms, ensuring that greater autonomy in physical AI systems does not come at the expense of human oversight and control.
—
## Conclusion
The introduction of NVIDIA’s Open Agent Safety Platform marks a pivotal moment in the evolution of AI and robotics. As AI agents gain greater autonomy and are entrusted with controlling physical systems, the need for enforceable, hardware-level safeguards has never been more urgent. Through the combination of OpenShell’s software enforcement and Sentry’s hardware monitoring, NVIDIA is providing the industry with a foundation that addresses safety across the full technology stack. Gecko Robotics, with its extensive experience deploying AI-powered inspection robots in high-stakes environments, is helping validate and refine these approaches in real-world conditions. Together, they are setting a precedent for how the robotics and AI communities can build trust, accountability, and safety into the next generation of physical intelligence systems.
Thank you for reading



