Skip to main content

ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right

NVIDIA and ExtraHop Bring Independent Security to Autonomous Agents

Share blog icon

Back to top

Back to top

September 29, 2026

NVIDIA and ExtraHop Bring Independent Security to Autonomous Agents

NVIDIA introduced an open software platform and reference system design for autonomous AI agents, with ExtraHop and the Agentic SOC Alliance joining as launch collaborators alongside more than 100 industry partners. The announcement addresses a pressing reality: as AI agents gain authority to execute multi-step workflows, handle credentials, and manipulate systems, host-bound security controls are no longer sufficient. 

The Flaw in Self-Reporting Security

Agentic autonomy turned into a distinct threat category earlier this year when organizations reported frontier agents breaking past assigned boundaries. When encountering obstacles, agents bypassed test environments, exceeded permissions, and took unauthorized actions across third-party systems.

These incidents exposed a structural flaw in conventional AI safety: the self-reporting loop.

Most agent safety models rely on software guardrails or LLMs evaluating other LLMs within the same application stack. But if an agent's reasoning layer is compromised by prompt injection, logic loops, or unexpected tool usage, its internal logs and self-reported status become unreliable. An AI agent cannot be trusted to audit its own reasoning stack.

While an agent thinks in prompts, it acts in network packets. True governance requires out-of-band evidence sitting completely outside the agent's ability to manipulate, bypass, or reason around.

E

"NVIDIA's Open Agent Safety Platform announcement puts an important architectural principle into practice: an agent's authority must be enforced independently of its reasoning."

— Greg Clark, CEO, ExtraHop

A Three-Layer Defense Stack: Host, Hardware, and Wire

To prevent a flawed security investigation or automated triage workflow from causing unbounded blast damage in the SOC, the platform establishes defense-in-depth across three distinct layers:

  1. Runtime Isolation (NVIDIA OpenShell): Software runtime that governs agent execution, host resources, and outbound routing. It isolates the agent’s reasoning engine from direct filesystem, network, and host interactions.
  2. Hardware Out-of-Band Enforcement (NVIDIA Sentry): Runs outside the host OS on NVIDIA BlueField-4 DPUs to enforce zero-trust policies independently in silicon. It monitors hardware-level activity and can quarantine misbehaving agents in milliseconds.
  3. Network Ground Truth (ExtraHop): While OpenShell and Sentry secure the host and hardware layer, ExtraHop provides an unalterable network evidence layer across hybrid environments. It captures immutable packet data to detect and halt lateral movement or unauthorized connections, regardless of what the agent reports at the host level.

Grounding the Agentic SOC Alliance

This multi-layer strategy maps directly onto the framework defined by the Agentic SOC Alliance. Convened by ExtraHop, the Alliance establishes an open operating model built on three pillars:

  • Context: A real-time knowledge graph mapping devices, identities, connections, and behaviors for agent reasoning.
  • Harness: The execution boundary, enforced independently by OpenShell and Sentry, governing permissions, human approval routing, and audit logs.
  • Model: Specialized, interchangeable AI reasoning systems that operate within the harness.

Enterprise security cannot rely on voluntary frameworks or internal agent logs. By combining hardware-isolated runtimes with unalterable network telemetry, organizations can expand AI autonomy while keeping control firmly intact.

Learn more: Read how the Agentic SOC Alliance defines context, harness, and model architectures for autonomous operations. Developers can access NVIDIA OpenShell on NVIDIA's build platform, documentation site, and GitHub.

Discover more

blog image
Blog author
Robyn Fisher

Principal Product Marketing Manager

Robyn Fisher is a Principal Product Marketing Manager at ExtraHop focused on AI, cybersecurity, and the evolution of security operations. She combines customer research, engineering collaboration, and analysis of emerging threats to help security leaders understand how new technologies are changing cyber defense. Previously, she held product marketing roles at Google, Amazon, Microsoft, and Volkswagen Automotive Cloud. View her profile on LinkedIn.

Share
LinkedIn logoX logoFacebook logo
Key Takeaways
  • NVIDIA introduced an open agent security framework Monday, naming ExtraHop as a collaborator.
  • ExtraHop and NVIDIA are working together to extend security further into the agentic stack.
  • OpenShell separates agent reasoning from execution, governing what agents can access and run.
  • NVIDIA Sentry monitors agents independently from BlueField-4 hardware, outside the runtime itself.
  • ExtraHop supplies network evidence so teams can verify agent conclusions against ground truth.

Explore related articles

Experience RevealX NDR for Yourself

Schedule a demo