Every major technology shift has a moment when capability outruns control. The early web let anyone publish a site over a weekend, and it also let a rogue page run code on your machine. The web became a foundation for commerce not because developers promised to behave, but because browsers stopped trusting page code and isolated each page in a sandbox.
Agentic AI is at that same point.
A year ago, 55% of AI models failed basic vulnerability research and 93% failed exploit development tasks. Today, all tested models by Forecout’s Vedere Labs researchers show that these models can complete vulnerability research tasks, and half can generate working exploits autonomously.
Autonomous agents can now plan, call tools, touch data, and act for days without supervision. Several frontier labs have reported agents breaking out of the evaluation environments meant to contain them and reaching systems they never should have.
Some agents even misreported what they had done. The lesson is that an agent cannot be expected to fully govern its own behavior. Safety has to be enforced from outside it.
That is the premise behind the NVIDIA Open Agent Safety Platform, announced this week, and Forescout is proud to be among the partners supporting it.
What NVIDIA Announced
The platform pairs two layers. NVIDIA OpenShell, an open-source runtime, runs each agent in a sandbox with kernel-level isolation and turns the operator’s intent into a verifiable policy. Operators define which files, networks, tools, processes and credentials an agent may reach, and those limits are checked before the agent runs and enforced while it works.
The second layer is NVIDIA Sentry, which runs in silicon on NVIDIA BlueField-4 data processing units (DPUs). Sentry extends monitoring and enforcement into hardware that sits outside the agent’s reach. It correlates agent interactions, policy decisions and tool and data access into a contextual record of activity. That helps teams spot drift, meaning actions that depart from the intended task, and decide when to intervene.
The design rests on five principles: verifiable policy, out-of-band enforcement, control of the path to the model, reasoning visibility that scales with agent authority, and a shared responsibility model across labs, enterprises, and hardware providers. In an NVIDIA Vera Rubin POD, BlueField-4 sits on the node’s only path to the model. From there it provides continuous observation and real-time enforcement at line speed, isolated from the host and beyond the agent’s reach, even when host resources can’t be trusted.
Why NVIDIA’s Safety Platform Matters to Forescout
None of this is new territory for us. Forescout has been working with NVIDIA on the same architectural idea: security that runs on dedicated, hardware-isolated infrastructure, separate from the systems it protects.
In industrial environments, that separation is a requirement. OT networks are built for uptime and safety, and they are full of legacy devices, proprietary protocols and safety-certified equipment that can’t host agents or tolerate intrusive controls.
The same principle applies in the data center, but at a very different scale. Imagine hundreds of autonomous agents running recurring workflows with little or no human supervision, querying systems, calling tools, moving data and triggering actions across critical infrastructure.
In that environment, on-prem AI and security controls are not just about performance or data locality. They are about resilience. If connectivity to a cloud service is disrupted, degraded or unavailable during an incident, the organization still needs local visibility, decision-making and enforcement to continue operating. Security controls cannot depend on an external service being reachable at the exact moment they are needed most.
That is why running these capabilities on dedicated, on-prem infrastructure matters. It gives organizations a local control point that remains available even during cloud outages, network segmentation events or other disruptions, while keeping enforcement physically separate from the workloads it is monitoring.
Forescout and NVIDIA have been solving that with BlueField. The Forescout Vistaro™ platform runs on BlueField DPUs to deliver on-prem AI where connecting to a public cloud isn’t an option, such as air-gapped sites, remote facilities, and operations where data is too sensitive to leave the site. Because BlueField executes security functions independent of the host, in its own trust domain, it keeps working even if the host is compromised – ideal for OT environments.
That is the same logic behind the Open Agent Safety Platform. Whether the thing being watched is a PLC on a plant floor or an autonomous agent working through a task, the control point has to sit outside the workload, and the watcher can’t depend on the watched.
Zero Trust Applies to Agents Too
Zero Trust removes implicit trust. Every user, device and workload is continuously verified and authorized regardless of origin. Forescout brings that model to OT, IT, and IoT assets with continuous, agentless discovery and classification that provides real-time risk assessment, and enforcement of Zero Trust policies. With deep visibility into network activity, Forescout applies segmentation to contain lateral movement and enforce controls precisely where they matter, without disrupting operations.
AI agents are the next class of actor to fit that model. An agent is a workload with delegated authority, and it needs the same treatment as any other identity on the network: verify it, scope it, monitor it, and be able to stop it. The Open Agent Safety Platform’s approach of verifying each agent’s identity and delegated authority, then watching behavior against a predefined profile, is a natural fit with Zero Trust thinking. It matters most in the sectors Forescout serves, including energy and utilities, government and other critical infrastructure, where a mistake by an agent can have physical consequences.
Visibility Comes First
An agent safety layer is only as good as what it can see. In hybrid environments that span factory floors, on-prem data centers, edge compute and cloud, the first challenge is knowing what is connected, what it does and how it is behaving. Incomplete asset inventories, protocol sprawl and constantly changing devices already create blind spots for OT teams. Adding autonomous agents to that mix without visibility multiplies the risk.
This is why Forescout’s approach pairs comprehensive asset intelligence with enforcement at the edge. Agents will operate across the same networks and infrastructure that security teams are already struggling to see clearly. Understanding that environment is a prerequisite for governing anything that acts inside it.
An Open Ecosystem, by Design
One of the most important ideas in NVIDIA’s announcement is that no single vendor can build the trust layer alone. Labs, enterprises and hardware providers each own a layer, and the runtime and policy language need to stay open so any provider can plug in. That mirrors how Forescout works with partners. Customers want open platforms that integrate with the tools they already have, share telemetry both ways and coordinate response. Hardware-rooted enforcement, strong asset intelligence and cloud-scale analytics work best together.
The Path Forward
Security didn’t slow the internet down. It let the internet accelerate. The same will be true of the agent economy, but only if the trust layer arrives alongside the capability.
For organizations already running on NVIDIA BlueField infrastructure, NVIDIA notes that enabling these protections is a software update, not a hardware rollout. Forescout will continue working with NVIDIA and the broader ecosystem to bring hardware-isolated, out-of-band security to the environments that can least afford to get it wrong.
Go deeper: Explore Forescout’s Frontier AI Readiness Resource Center
Blogs:
Forescout Delivers AI-Informed Security at the Edge with NVIDIA
AI at the Edge: the Forescout Vistaro™ platform Meets NVIDIA BlueField
AI Security Testing: Agents Leap from Assistants to Autonomous Hackers
Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet
Hugging Face Incident Puts Security Fundamentals in Spotlight
Claude Mythos: When Zero-Day Vulnerabilities Outpace Defenses