MARKETS, CREDIT & POLICYAbout & methodology
c.The Credit CurrentDAILY INTELLIGENCEWhat matters in Credit
Back to newsfeed
AI · Company announcement

NVIDIA introduces agent-safety controls with Citi and JPMorganChase participating

NVIDIA announced its Open Agent Safety Platform on September 28, combining OpenShell runtime software with the Sentry reference system design. NVIDIA says Citi and JPMorganChase are collaborating on shared open-source agent-safety technologies. OpenShell is broadly available; Sentry describes an additional, hardware-isolated monitoring and enforcement layer. The announcement establishes a technology release and named collaboration, not evidence that either bank has deployed the full platform across its operations.

2 min read · estimatedAI-generated analysis · Methodology
My private notes

Only in this browser; never published or sent to the site. Use Backup & restore on the Saved tab to transfer notes. Anyone using this browser profile can read them.

0 / 10,000 characters

No note saved yet.

0% through article

Tap a dotted-underlined term for a definition. Use Aa in the navigation for reading preferences.

Why it matters

IBM’s same-day announcement adds a concrete identity-and-access component: IBM Agent Identity, currently in public preview, and HashiCorp Vault integrate with OpenShell. Analysis: for a bank, the important design question is which system enforces an agent’s authority when the model makes an unexpected decision. A prompt telling an agent to avoid customer data is weaker than a separate control that denies access. A useful pilot would start with a narrowly defined task, a dedicated identity, limited credentials, approved destinations and a record of tool calls. Hypothetical test: an agent assigned to summarize a risk report attempts to upload the underlying customer file to an unapproved service. The evaluation should establish whether the request was blocked, whether attempted workarounds were detected and whether the stop procedure actually halted execution. Useful measures include unauthorized actions blocked, legitimate tasks incorrectly interrupted, response time, investigation effort and cost per completed task. Isolation and granular permissions can add administration, latency and infrastructure expense, so performance should be measured under the bank’s own workload. A successful demonstration on a vendor-selected task is insufficient evidence for access to live payment, servicing or underwriting systems.

What remains uncertain

NVIDIA’s security and speed claims, and IBM’s integration descriptions, are company-authored evidence. The reviewed releases do not provide independent bank-level loss reduction, comprehensive attack-test results or comparable total deployment costs. Availability differs between released software, preview services and a hardware reference design; none should be described as a guarantee against agent escape.

Sources

Flag an error or suggest a correction →Public corrections log →