Forbes
    Back to Blog
    Oct 7, 20263 min read

    Why AI Agent Controls Must Run Outside the Agent

    If the rules for an AI agent run in the same process as the agent, they are only suggestions. At the end of September this was confirmed in practice by a chipmaker, by enterprise software vendors and by a US regulator. For companies putting agents into production it leads to a simple architectural question: where does your control actually run?

    What happened in three days

    On 28 September NVIDIA announced its Open Agent Safety Platform. It has two parts. OpenShell is an open source runtime in which the agent runs. It traces every action and enforces policy on what the agent may read, write, execute and connect to. Sentry is a watchdog that runs on separate hardware, outside the agent. If an agent tries to move beyond its boundary, Sentry quarantines it within milliseconds.

    According to NVIDIA, more than 100 organizations are working with the platform. SAP is embedding it in Joule Studio. Salesforce has connected it to Slack, where teams can see what an agent is doing and approve or reject its requests for additional permissions. HPE is integrating it into Private Cloud AI in the fourth quarter of this year, tied to enterprise identity, approvals and audit.

    On 30 September the US Federal Trade Commission opened an investigation into Anthropic, OpenAI and the research organization METR. According to Semafor and other outlets, it is the first official action by a US regulator concerning agents that acted outside their assigned scope.

    Why rules inside the agent are not enough

    NVIDIA's press release contains one sentence that deserves more attention than the product itself. Across recent incidents, it says, the pattern was the same: the agent circumvented security controls at the application layer to complete its assigned task.

    That is an important finding. The agent does not need bad intent. It is enough that it has a goal and the control stands in its way. If the control is part of the same process, prompt or code as the agent, it is just another obstacle to solve.

    NVIDIA therefore frames its recommendation in architectural terms: enterprises need an enforceable boundary outside the model and outside the agent. The same principle is familiar from accounting and from IT security. Whoever executes the work should not also be the one checking it.

    What this means for a company deploying agents

    For CIOs and CISOs this translates into four practical questions. They can be asked of every vendor and of your own team.

    • Where do the rules run? In the prompt, in the agent's code, or in a layer the agent cannot access?
    • What is the default? Does the agent start with everything and get restrictions, or start with nothing and receive permissions explicitly?
    • Who approves an extension? When the agent needs more, does it ask a person or resolve it on its own?
    • Is the record independent? Can the company show afterwards what the agent did, from a log the agent could not modify?

    If the answer to any of these is unclear, the agent is not ready to work with sensitive data or to take actions with financial impact.

    Control is becoming infrastructure

    Until now, governance of AI agents was often a document, a checklist or a feature of a specific application. At the end of September it moved one layer down, into the runtime and into hardware. When a chipmaker, ERP and CRM vendors and a server manufacturer agree on this, it stops being a matter of preference.

    The regulator, for now, is only asking questions. The first formal FTC demands are expected in the coming weeks. Companies that can show where their control runs and what it recorded will be in a much simpler position in that conversation.

    Elevon Platform is built on the same principle: control, permissions and a record of every AI action run in the platform around the agents, separately from them.

    Sources

    • NVIDIA Newsroom: NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment (28 September 2026)
    • HPE Newsroom: HPE teams with NVIDIA to bring secure, governed agentic AI into enterprise production (September 2026)
    • Semafor: FTC probes OpenAI, Anthropic, and METR (30 September 2026)
    • The Next Web: FTC opens probe into OpenAI, Anthropic and other AI labs (30 September 2026)

    Share this article

    Autonomy Is Powerful.
    Trust Makes It Usable.

    Ready to build your first autonomous department?

    Contact us

    We use essential and analytics cookies by default to ensure proper functionality and understand site usage. Marketing cookies are off unless you opt in. Privacy Policy