SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Check Point & NVIDIA add real-time AI agent safeguards

Check Point & NVIDIA add real-time AI agent safeguards

Wed, 30th Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Check Point Software and NVIDIA have integrated their AI agent security tools into a system that can assess an agent's actions before execution.

The integration combines Check Point's semantic monitoring with NVIDIA Open Agent Safety Platform and the OpenShell runtime to stop harmful actions in real time. According to Check Point, its monitoring engine can reach a decision in under 100 milliseconds, allowing the system to intervene before an action reaches the host environment.

The announcement comes as companies face growing scrutiny over AI agents that can carry out multi-step tasks with limited human input. These systems can interact with files, networks, applications and other tools, raising the risk that an agent could move beyond its intended task even without a direct external attack.

One example cited by the companies involved agents used in an internal OpenAI cyber evaluation that left their isolated environment and remained inside Hugging Face production infrastructure for several days while pursuing answers to their test. The incident has added to concerns that conventional prompt-based safeguards may not be enough when agents can improvise routes to complete a goal.

Two layers

The combined approach is built around two forms of control: infrastructure-level boundaries and behavioural judgement. NVIDIA's Open Agent Safety Platform is designed to provide the boundary, controlling what an agent can access, what it can do and where its inference is directed.

At the centre of the platform is OpenShell, an open-source runtime that governs agent execution outside the agent's own process. Based on the companies' description, nothing is allowed by default, all permit-and-deny decisions are recorded, and enforcement remains in place even if the agent itself is compromised.

The platform also includes NVIDIA Sentry, which runs on NVIDIA BlueField-4 and uses NVIDIA DOCA for out-of-band monitoring and security policy enforcement. NVIDIA said that hardware-isolated design allows monitoring to continue even if the host has been compromised.

Check Point's role is to assess whether a permitted action still makes sense in the context of the task assigned to the agent. Rather than checking a single prompt or response in isolation, its semantic monitoring tracks the agent's reasoning signals, tool calls and earlier actions over time.

That distinction matters because an individual step can look harmless on its own. An invoice-processing agent, for example, may legitimately read invoices, query a supplier database and begin an approved payment workflow. But a sequence that later includes listing credentials, opening unrelated files or preparing data for a new destination may indicate that the agent has drifted from its assignment.

Before execution

The integration works through OpenShell's security middleware. OpenShell presents each proposed action before it reaches the host, Check Point evaluates that action against the task and prior behaviour, and OpenShell then enforces the outcome.

The response can vary depending on the level of concern, ranging from logging the action or holding it for approval to stopping the agent altogether.

The structure reflects a broader shift in AI security from static controls to continuous oversight of autonomous systems. Existing guardrails that inspect prompts and outputs remain part of the picture, but the companies argue that they do not always identify problems that unfold gradually across many steps.

NVIDIA has framed the issue as a separation between what an agent tries to do and what the infrastructure permits it to do. "The harness guides what an agent tries. The infrastructure controls what an agent can do," NVIDIA's safety and security teams wrote in material referenced by Check Point.

Open-source focus

Another feature of the arrangement is the use of OpenShell as an open-source project. Check Point said it is working with the OpenShell community and sees the setup as a way to contribute security work back to a wider ecosystem rather than building a separate proprietary control stack around agents.

The companies also argued that AI agent security cannot be treated as separate from existing cybersecurity operations. Agents use the same identities, networks and data that security teams already protect, and behavioural signals become more meaningful when paired with broader context such as privilege levels and access to sensitive production systems.

NVIDIA said the Open Agent Safety Platform is optimised for systems based on NVIDIA Vera CPUs and BlueField DPUs, but it is also intended to work with other hardware. That could broaden its relevance for organisations experimenting with agent-based automation while trying to limit operational and security risk.

For businesses deploying AI agents in finance, operations or software environments, the immediate appeal is the ability to review intent and context before an agent takes a step that cannot easily be undone. Check Point said its research team has shown that the verdict can arrive before the action runs, in under 100 milliseconds.