{"id":2107996,"date":"2026-10-08T09:14:07","date_gmt":"2026-10-08T07:14:07","guid":{"rendered":"https:\/\/www.luxsure.fr\/?p=2107996"},"modified":"2026-10-09T01:32:43","modified_gmt":"2026-10-08T23:32:43","slug":"nvidia-openshell-ai-agent-limits","status":"publish","type":"post","link":"https:\/\/www.luxsure.fr\/en\/2026\/10\/08\/nvidia-openshell-ai-agent-limits\/","title":{"rendered":"What an AI agent must not be able to do, even when it is wrong"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><em>On 21 September 2026, NVIDIA published a text on the security of AI agents. For a Maison considering entrusting tasks to them, the first question is put to management: who can say no to the agent, and by what means?<\/em><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>An attachment, an export<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sa\u0161a Zdjelar, who signs the post, takes a scenario that fits in three lines. An agent updates a client record. In an attached document, it encounters malicious instructions and tries to export the data to an unauthorised destination. According to NVIDIA, a network policy must block the transfer. Protected logs must also keep a trace of the tool call, the authorisation decision and its outcome, so that the security team knows which tool was used and which destination the agent was aiming for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The right to modify a record does not give the right to export it. The agent can request additional access, but it cannot grant it to itself.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The instruction and the fence<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NVIDIA writes that a security boundary must hold even when the agent makes the wrong decision. Instructions and guardrails can steer its behaviour, but the environment in which it runs must impose its limits on files, network destinations and processes, without depending on the agent&#8217;s reasoning. Asking an agent to be careful means counting on its answer on the very day it has been deceived.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The manufacturer presents OpenShell as an open-source runtime environment that applies policies out of the agent&#8217;s reach and isolates its work in a sandbox. Cisco (DefenseClaw, a governance layer) and JFrog (verification of the skills the agent may use) plug into it. A reservation is in order: NVIDIA is here describing its own offering and those of its alliance partners, and the post provides neither measurement nor test result. This does not prove that these tools fail, only that the promise is not established by this text.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Four things to demand before going live<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let us transpose, without claiming to describe a real case. An agent tasked with finding a reference in a document collection has no reason to read client contact details. A tool that prepares a draft has no reason to be able to publish it. These two refusals are a management decision before being an IT setting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The post draws four requirements from this. Each agent carries a traceable identity and credentials limited to its task. Prior tests show that the controls block the obtaining of out-of-scope credentials and the sending of sensitive data to an unauthorised destination. These tests are redone after any change of model, tool or working procedure. A named person in charge decides, in light of the results, whether the system can go into production, and procedures exist to withdraw access and contain an incident.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The vendor can sell the fence. It cannot write, in place of management, what the agent is allowed to touch. As long as a Maison cannot complete the sentence \u201cthis agent can read this, modify that, and only this person can suspend it,\u201d the choice of tool matters little.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>NVIDIA reminds us that an agent&#8217;s security depends on limits enforced outside its reasoning. For houses, this distinction directly concerns access to archives and client data.<\/p>\n","protected":false},"author":214,"featured_media":2094189,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[77972],"tags":[30184,57600],"class_list":["post-2107996","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-luxury-and-ai","tag-luxury-en","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/posts\/2107996","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/users\/214"}],"replies":[{"embeddable":true,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/comments?post=2107996"}],"version-history":[{"count":0,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/posts\/2107996\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/media\/2094189"}],"wp:attachment":[{"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/media?parent=2107996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/categories?post=2107996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.luxsure.fr\/en\/wp-json\/wp\/v2\/tags?post=2107996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}