×

Gecko Robotics partners with NVIDIA to add security and control to AI agents

Gecko Robotics partners with NVIDIA to add security and control to AI agents

Gecko uses NVIDIA’s new AI-powered security layer in its inspection robots. Source: Gecko Robotics

NVIDIA Corp. today announced its Open Agent Safety Platform, which consists of the open source software OpenShell and the Sentry reference system design. They are intended to strengthen governance and control over hardware, processing and software for robots running AI agents. Among the more than 100 organizations working with NVIDIA technology is Gecko Robotics Inc.

After recent incidents where OpenAI AI agents bypassed application-level controls to attack Hugging Face, AI and robotics developers have been working on traceability, accountability, and preventative measures.

“As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI security,” said Jensen Huang, CEO of NVIDIA. “Safety and security require full-stack engineering. The NVIDIA Open Agent Safety Platform brings together industry, researchers, and public sector organizations to share best practices, align on remediation methods, and foster international cooperation.”

Editor’s Note: Physical AI is one of the topics covered in the RoboBusiness 2026 session, which will be held on October 20 and 21 in Santa Clara, California. Register now to participate.



Register now and help us celebrate 20 years of RoboBusiness!

NVIDIA OpenShell and Sentry enforce policies

OpenShell provides a secure runtime boundary that tracks all actions and enforces policies while AI agents run on NVIDIA Vera CPUs. According to NVIDIA, it provides deterministic governance for agent execution, access, and inference targeting.

As open source software, OpenShell can be extended to work with third-party computing platforms, including those from Arm and Intel, the Santa Clara, California-based company added.

NVIDIA Sentry adds an out-of-band watchdog that runs on BlueField-4 data processing units (DPUs) to continuously monitor agent behavior. Track results against policies, the company said. Sentry can quarantine agents who attempt to leave its borders in milliseconds.

“For the agent economy to grow, we need a reliable foundation for silicon and software,” said Justin Boitano, vice president of enterprise artificial intelligence at NVIDIA, during a press conference. “We want to involve everyone to promote a new level of officer safety.”

“The independent trust domain is like how self-driving cars work,” he explained. “The primary system handles perception, and a safety island ensures that the overall system fails safely. The same principles apply to frontier AI systems.”

OpenShell can offload security to silicon or DPU as needed, and Sentry observes the reasoning traces. A Policy Proover in the NVIDIA Open Agent Safety Platform is deterministic and runs at a faster rate.

“If you write a policy that says an agent can’t read code from Github, an agent could spawn separate subagents to read it and then publish that information, with fleets overriding global policies,” Boitano said. “Policy Proover validates the core decision tree, examining combined file and network access to detect inadvertent extractions. It derives from AWS S3 lookup to create auditable policies.”

“We think long-term agent behavior is a different problem than sandboxing,” he added. “OpenShell is projecting policy intent into infrastructure.”

The NVIDIA Open Agent security platform includes OpenShell and Sentry. Source: NVIDIA

Gecko gives the AI ​​agent control over the robot’s movement

While the recent security incidents occurred entirely within the software, Gecko Robotics said it revealed a potential problem with all AI agents, including robots. The company used NVIDIA OpenShell to explore how enforceable boundaries can keep AI-powered robots operating within human-defined permissions. Gecko said its goal is to establish the safeguards needed to implement greater autonomy responsibly.

“As Jensen says, safety is a technical issue, not a legal one,” said Jake Loosararian, co-founder and CEO of Gecko Robotics. “The idea that losing control of AI is inevitable is a dangerous excuse for inaction. We have a responsibility to create safeguards that keep AI within the limits set by humans.”

“What NVIDIA has built with the Open Agent Safety platform, and what Gecko is testing for robots, is to address risk before it reaches the physical world and help ensure that greater autonomy doesn’t come at the expense of human control,” he added.

Gecko uses robots that can climb, crawl, fly and swim on critical infrastructure, including for Fortune 100 energy companies, as well as the U.S. Air Force and Navy. Its systems inspect everything from fuel tanks to nuclear submarines and aircraft carriers.

Ariel Weingarten, director of engineering at Gecko, said this The robot report that its agents have access to the same system commands as its field operators, including:

  • Starting and stopping data collection
  • Robot motion controls and path planning
  • Raise and lower payloads

They don’t manage the data lifecycle or upload to Gecko’s governance cloud, he said.

As research into the safety of AI agents continues, Pittsburgh-based Gecko is using NVIDIA OpenShell to define secure runtime boundaries that developers can use to define which actions systems can take and which are not allowed.

The Komodo robot includes the application layer

Gecko’s Komodo, a robot that has been deployed with the US Navy, places an independent application layer between the AI ​​agent and the hardware. “The developer decides what Komodo should do; OpenShell ensures it stays within the rules,” the company said.

“Physical AI and robotics represent the next frontier of technology,” said Gecko Robotics. “Moving intelligence from software to machines also brings greater responsibility. Model-level security alone is not enough.”

Because Gecko already follows well-defined security controls for U.S. military assets, implementing them in OpenShell was not a challenge, Weingarten said.

“By building enforceable controls across the entire technology stack, NVIDIA and Gecko are helping to ensure safeguards that govern the progress of physical AI as quickly as the technology itself,” the company added.

Gecko’s AI-powered Cantilever platform transforms the massive data sets its robots collect into actionable insights. The company said its systems enable data- and evidence-based facility decisions, delivering a return on investment (ROI) for customers.

Because OpenShell sits within the confines of a Komodo field system, it doesn’t interact directly with Cantilever, Weingarten noted. Gecko plans to use NVIDIA’s security layer for both defense and military systems in the future, he said. Deterministic control could also help at the swarm level.

“It is certainly useful to have invariants at the single unit level that can be used to reason about swarm/fleet dynamics,” Weingarten said. “We are excited to evolve as we move from individual system control to agent-assisted operation of an entire implementation.”

Post Comment