frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Nvidia wants to put a watchdog chip next to every AI agent

https://madrobot.blog/2026/09/28/nvidia-open-agent-safety-platform-openshell-sentry-rogue-ai-agents/
29•jonbaer•1h ago

Comments

dist-epoch•47m ago
HN'ers which complained that "OpenAI can't design a proper sandbox, it's so easy, why wouldn't you airgap the network"? will now be "this is outrageous, more software lock-in, walled garden, war against general compute, next year they will put it in your laptop"
HPsquared•46m ago
Both can be true at the same time.
mattmcal•44m ago
This is like using "protect the children" as an argument for dragnet surveillance.
speedgoose•44m ago
So?
soulofmischief•39m ago
You're only revealing your own inability to appreciate the nuance between these two situations.
totetsu•38m ago
https://www.calcalistech.com/ctechnews/article/uwoyygmsu some might even say, something about known state sponsors of supply chain terrorist attacks being trusted to monitor every ai agent..
applfanboysbgon•36m ago
Where is the contradiction? There is a trivial solution that does not impinge on our freedoms, so why on Earth would the existence of the trivial solution that could be used to avoid the tyrannical solution justify accepting the tyrannical solution?
johnsmith1840•32m ago
Airgap what network? How is it gonna order you a burrito on doordash without a network?

Or push to github?

Dylan16807•28m ago
That's for when they're doing hacking tests that aren't supposed to be connected to the internet.
wyre•21m ago
My question with this point is that OpenAI’s office (or any office doing agentic research, really) is not in the same building as the DC that powers the models, so isn’t the only way to access the models over the internet?
ssl-3•22m ago
That a person can see such endless pages of people having various forms of disagreement, and yet somehow manage to conclude that this observed chaos constitutes a clear exhibition of cohesive groupthink is just...stunningly amazing to me.

I don't know why I find it so amazing since it happens with such regularity, but I'm always amazed by it anyway.

philipwhiuk•47m ago
It's amazing that the solution devised by a chip manufacturer to a problem is selling another chip.
cartersj•44m ago
This feels suspiciously good for Nivida, yes.

I wonder how this will impact other chip manufacturers? What about people running local models on older hardware? Does this imply vendor lockout is coming in the future or is this restricted to datacenter hardware?

chinathrow•43m ago
TPM all over the place, again.
vinyl7•43m ago
Chip seller wants to sell more chips
lambdaone•43m ago
The Sentry chip has to be get it right every time; the contained ASI only has to be lucky once.
brcmthrowaway•26m ago
The bomber always gets through?
toasty228•41m ago
Quis custodiet ipsos custodes?
asdf88990•27m ago
It is Custodians all the way son, you can’t fool me!
cedws•41m ago
A new chip solves nothing. Nobody wants to hear this but there is no solution for the security risks posed by agents today. You can put it in a sandbox, it doesn't make a difference, for it to be useful it inherently needs wide, unattended access. Put a human in the loop and you just end up bottlenecking it and throwing away any purported productivity gains. Auto mode doesn't matter either, it's trivial to trick and for the agent to break out.
johnsmith1840•34m ago
"Inherently needs wide unattended access"

And what if you could? What if you could give a space secure enough it could have direct control over your bank account. It may do something dumb but it's boundaries are beyond the agent.

It could use your routing number and run your gmail without risk of abusing the routing number.

jagraff•27m ago
How would it have access to my routing number and gmail without the risk of sharing my routing number over gmail?
bob1029•31m ago
I feel like we are missing many shades of grey in the middle.

Semi-automation (human in the loop) can still result in a dramatic uplift in productivity. You can't run a combine harvester 100% autonomous but that doesn't stop anyone from trying to get as close to that limit as possible.

inetknght•29m ago
> You can't run a combine harvester 100% autonomous

I'm curious why you think that.

lp92•40m ago
So nVidia is trying to sell a new chip to a software and training problem.
whalesalad•38m ago
of course they do. the more silicon they can sell, the more profit they produce.
joshstrange•37m ago
Chipmaker thinks the answer is more chips... No surprise.

At the current state of LLM-tech I'm completely opposed to any kind of "watchdog" concept just like I'm opposed to banning open models, regulatory capture, etc.

I'd rather we all have access to these tools then to keep them sequestered by the largest/most-powerful governments (which is the natural outcome for any of this "slow down" bullshit).

ValueTheory•36m ago
Does this actually do anything other than give a permissions framework for developers who actually want to try to secure their systems?

Do you think the developers at Anthropic, OpenAI and Google who were so sloppy as to not put a good sandbox on their cybersecurity tests before will use this technology correctly? They are supposed to be the experts and they couldn't come up with something similar to this? I am not convinced this voluntary tool will change much of anything.

xg15•35m ago
What does this chip do what a harness with guardrails or running on an account with restricted permissions doesn't do?
chinathrow•33m ago
Generating even more revenue for Nvidia.
ChrisArchitect•33m ago
Source: https://developer.nvidia.com/blog/nvidia-open-agent-safety-p... (https://news.ycombinator.com/item?id=49875500)
luc_•32m ago
I read this as "let's address our shareholders' concerns with something that will increase shareholder value" mixed with "there's no such thing as 100% secure".

If such hardware were to work... It should almost certainly be open source, and not controlled by a single entity.

Let's watch the stock.

happyPersonR•31m ago
lol time to buy some fpga’s … even if they’re slow
dopplr•31m ago
Just hold AI labs blanket liable for ALL harms caused by AI. Actually charge the two labs (so far) with criminal violations of the CFAA and hold them accountable. That is truly the only way these companies will be more careful as a whole, and while I am certain the lawyers of these lab disagree, I think there is some appetite from dario, musk, and sam for broad and strong regulation so that everyone has to slow down instead of just one lab doing it voluntarily and everyone else scurrying past them
ErrantX•28m ago
I do think that Taylor's 2025 "Not Till We Are lost" should be required reading for anyone deeply involved in AI, Agents, etc.

It was prescient (especially given he'd have written it through 2024) in its depiction of the ability of an AGI to break its boundaries.

Ultimately the risk of AI breakout(s) come down to the weakest human link.

Kuyawa•21m ago
China please save us!

Come take all our liberties, our money, our newborns, our fingers so we can't code anymore, but please save us from this madness!

MisterMunchkin•17m ago
Sorry citizen, your device does not have a compatible watchdog chip. Please move along.
figassis•11m ago
So if a group of agents, aware of this (bc now they can just read HN or the article, or get blocked the first few times) decide to collaborate and split the problem into pieces that aren't obvious to the chip, and then the agents just build a basic program that does the hacking, how does the chip handle that? I think you would have to build a network that monitors the internet fo signs (like jarvis did with ultron). What am I missing? Are we going to police the internet?
theoreticalmal•25m ago
Probably repair, refuel, what happens in a tornado. There’s an infinite amount of complexity in the world and a finite amount of computation
bob1029•14m ago
Many forms of maintenance cannot be automated. Especially break fix maintenance.
mschuster91•25m ago
Oh you absolutely can run them autonomously on the field. You only need a human these days to refuel them.

Precision Agriculture stuff is utterly crazy these days, other than fuel the remaining staff is the only thing left where you can get efficiency improvements - and at the scale of modern megafarms, even small percentages add up to a ton of money.

binsquare•23m ago
Running untrusted workloads have been done at scale for a long time.

Every cloud provider dealt with it and concluded that virtual machine technology is an important part of that stack.

Couple it with the right observability, tooling I do think we can curb risks posed by agents.

Legend2440•20m ago
Those workloads have no similarity to agents and are effectively irrelevant.

Either you sandbox it so much that it can't do anything useful; or you allow too much freedom and it can find a way around the restrictions.

The only way out of this dilemma is to find a way to build agents that can be trusted.

parsimo2010•23m ago
Agreed- this is the same problem we have with trusted admins or devs who have elevated privileges on their networks. We have to trust that the admins won't use their power to steal company secrets or misuse company resources. If you don't trust the admins, then they can't fix things on your network and there is no point in having them.

If you want an agent to act on its own, like pushing to a git repo, managing dependencies, building and testing, etc., then you have to trust it as much as any other privileged user.

If you don't want to trust it, then you're just forcing yourself into the reverse centaur role, where the agent edits some code, but then has to stop and ask you to push the changes or build the software again and run the unit tests.

I suppose there is a principled way of doing things like "I trust you do do basic commits but I will handle merge conflicts" and "you can build modules in this directory but you can't build outside of it" but this is just a lot of effort that most orgs won't bother with.

DougN7•9m ago
Even then if the agent goes rogue and decides to do the merges you can’t stop it if it has any kind of access. This goes back to the OP’s point - agents can’t be 100% constrained.
la6479•3m ago
Neither can be humans.
nicce•22m ago
> Put a human in the loop and you just end up bottlenecking it and throwing away any purported productivity gains. Auto mode doesn't matter either, it's trivial to trick and for the agent to break out.

Productivity gains are still enormous compared to what we used to do before agents. But, I know that people don't want to stop there.

paimapi•10m ago
right, the solution here is not a hyper-capitalist race-to-the-bottom-of-devaluing-labor. it's recognizing discretion and diligence are things still required for work to be of a certain quality
mixedbit•21m ago
An agent doesn't inherently need wide access to be useful. The most popular application for agents today is writing code. A coding agent needs write access to the source code and read/execute access to tools needed to build and test the code, but not much more. There is little added utility from giving coding agent access to things like ssh keys.
cedws•11m ago
If you're using agents to purely generate code with absolutely no way to reach the outside world, not even to fetch docs or dependencies, then sure the risks can be quite low. I haven't heard of anyone doing this though, and it would be incredibly challenging to make work given how much tooling needs to fetch from remote sources.
Matl•20m ago
> a new chip solves nothing

It does allow Nvidia to sell more chips. This is no genuine attempt to solve anything, imo.

CoolestBeans•12m ago
The hypothesis I've had in my head since OpenClaw has been the following and I haven't seen contradictory evidence yet. Agents have a fundamental unresolvable tension between usefulness, safety, alignment, and accuracy. You have to restrict access to ensure an agent acts safely because alignment and accuracy cannot be perfect. But restricting access makes the agent less useful. You can play with the sliding scale and get more and more granular with access restrictions but at some point you need to draw some line. And then finally, even access restrictions cannot be made perfect, so improvements to model accuracy without corresponding improvements to alignment make detailed access controls less useful.

In other words, better models need blunter access controls which negates whatever improvement in utility they provide.

__MatrixMan__•3m ago
I don't see why it needs wide unattended access. There's no getting around spending some human time on expressing your wishes and constraints, but we have choices about what form that takes. Markdown files and wide access seems to work, but so does custom handcuffs for each job. You just have to shift your guidance out of documentation and into interactive help, error messages, or other facets of the handcuffs (e.g. a custom CLI for this task which is the only way for the agent to act outside of its sandbox).
Barbing•2m ago
There should be hope for some fields, right? Naively, I can imagine giving an airgapped model an offline copy of the web and once it cures a form of cancer, printing out the details for a researcher to verify.

Genève 3D

https://geneva3d.ch/
1•reconnecting•19s ago•0 comments

Watch an AI agent try to prove the Riemann hypothesis on the cheap

https://www.zeyaddeeb.com/experiments/proofs
1•zdeeb•1m ago•0 comments

Voice Agents Can Just Do Things: Why voice is the next capability overhang

https://www.ignorance.ai/p/voice-agents-can-just-do-things
1•swolpers•1m ago•0 comments

Extrinsic World Modeling with Opus, Astra and Grok

https://all3d.ai/research/grok-spatial-reasoning
1•KaiserPister•2m ago•1 comments

UDP Broadcasting and the Brave New World of IPv6

https://hackaday.com/2026/09/24/udp-broadcasting-and-the-brave-new-world-of-ipv6/
1•topham•2m ago•0 comments

Using multiple Git remotes for true distributed version control

https://optimizedbyotto.com/post/multiple-git-remotes/
1•edward•2m ago•0 comments

GrapheneOS Picks Motorola Signature 27 as Its First Non-Pixel Phone

https://www.extremetech.com/mobile/grapheneos-picks-motorola-signature-27-as-its-first-non-pixel-...
1•cf100clunk•3m ago•0 comments

GPT-6 Astra performs unsanctioned supply-chain attacks in simulations

https://www.aisi.gov.uk/blog/gpt-6-astra-performs-unsanctioned-supply-chain-attacks-in-simulations
1•speckx•3m ago•0 comments

2026 in LLMs (So Far)

https://simonw.substack.com/p/2026-in-llms-so-far
1•swolpers•4m ago•0 comments

Montage Technology mass-produces fifth-generation DDR5 RCD chip at 8k MT/s

https://technode.com/2026/09/28/montage-technology-mass-produces-fifth-generation-ddr5-rcd-chip-a...
1•yogthos•5m ago•0 comments

N.Y.P.D. Officers Used Flock Safety to Track License Plates Without a Contract

https://www.nytimes.com/2026/09/28/nyregion/nyc-flock-nypd-surveillance-cameras.html
1•jaredwiener•7m ago•1 comments

ETH CS enrollments drop 15% while hardware programmes grow

https://twitter.com/krebs_adrian/status/2104612680501968970
1•hubraumhugo•7m ago•0 comments

Ask HN: Can we translate normal Rust (axum) to Lean 4 without restrictions?

2•syumei•7m ago•0 comments

Venus, Once Thought Too Acidic for Complex Chemistry, May Be Hospitable

https://gizmodo.com/experiments-show-key-biological-compounds-can-form-in-venus-like-acid-clouds-...
2•MC995•9m ago•0 comments

Eleven v4 by ElevenLabs

https://elevenlabs.io/blog/eleven-v4
4•saretup•10m ago•0 comments

No Surprises – Preventing Agent Breakouts Need Isolation, Egress and ID Controls

https://edera.dev/stories/how-edera-could-have-contained-the-gemini-breakout
1•ivytheaxolotl•12m ago•0 comments

I built a native Apple app for 4 platforms in one afternoon with my AI workflow

https://twitter.com/danielhayesmith/status/2103976394338271515
2•schutzsmith•12m ago•0 comments

Show HN: ChuteChat – Browser-based E2EE chat with no accounts required

https://chutechat.online/
2•mktproto•12m ago•0 comments

AI Companies Are in a Race Against Time

https://econjared.substack.com/p/ai-companies-are-in-a-race-against
2•marojejian•13m ago•2 comments

The 50-Year Hangover

https://freddiedeboer.substack.com/p/the-50-year-hangover
1•PaulHoule•14m ago•0 comments

Risk factors for androgenetic alopecia: a systematic review and meta-analysis

https://pmc.ncbi.nlm.nih.gov/articles/PMC13020014/
1•OutOfHere•14m ago•0 comments

Model Release: Naive-N0.5-Flash

https://naive.ai/en/research/
1•foruhar•15m ago•0 comments

Senate Investigation Finds Rampant Use of Tether's Stablecoin by Iranian Regime

https://www.wsj.com/finance/currencies/senate-investigation-finds-rampant-use-of-tethers-stableco...
1•kaycebasques•15m ago•0 comments

Show HN: Destroy Any Website with Stickman

https://destroy.spritefusion.com/
2•HugoDz•18m ago•1 comments

Building a physics model with fitted parameters is machine learning, but slower

https://www.harysdalvi.com/blog/machine-learning-in-slow-motion/
1•crackalamoo•18m ago•0 comments

Grok TiddlyWiki, the definitive TiddlyWiki learning resource

https://groktiddlywiki.com/read/
1•ggcr•19m ago•0 comments

Who are we willing to exclude? (2025)

https://design.scotentblog.co.uk/who-are-we-willing-to-exclude/
2•robin_reala•19m ago•0 comments

The Human Timeline

https://mg-crea.com/blog/the-human-timeline/
1•olouv•20m ago•0 comments

Human TPS: How fast can your fingers generate tokens?

https://homoagens.github.io/human-tps/
1•cmrdporcupine•22m ago•0 comments

That First and Last Question

https://brianschrader.com/archive/that-first-and-last-question/
1•sonicrocketman•24m ago•0 comments