Safe Autonomous Security: Armadin Joins NVIDIA Agent Safety Platform

28 Sep 2026
WRITTEN BY
Trevor Wise, Craig Wright, Travis Lanham
Safe Autonomous Security: Armadin Joins NVIDIA Agent Safety Platform
Attackers no longer move at human speed. AI agents can now scan, chain exploits, and pivot across an environment in minutes, and they can do it against thousands of targets at once. Machine-speed, machine-scale attacks are becoming the norm, and defenses built around human response times are falling behind.
Contents

Two Defining Challenges of the AI Era

Every security leader we talk to is working on two problems at once:

  1. Hardening against AI attacks. Machine-speed, machine-scale attacks are becoming the default, and organizations need to find and close exposures before an adversary's agent does.
  2. Securing their own use of AI. Organizations are deploying agents to transform how they work. Those agents need real access to real systems, and that access has to be governed.

These are not separate problems. The same agent capabilities that make AI attacks dangerous also make enterprise agents powerful. Solving one issue without the other leaves a gap.

Autonomous Security: AI on Offense Training AI on Defense

To meet both challenges, organizations need to move toward an architecture of Autonomous Security. Offensive AI agents continuously probe the environment the way a real adversary would. What they find trains and tunes defensive AI, so defenses improve at the same speed attacks do.

Safe AI Attacks

Every organization needs to understand its exposure to AI attacks in its production environment, safely. Staging environments and point-in-time assessments miss how an autonomous adversary would actually move through live systems.

Running offensive agents against production environments raises the same question every enterprise now asks about its own agents: how do you let an autonomous system act with real capability while guaranteeing it stays inside the lines?

Safety Starts with Systems

Asking a model to behave is not a control. Safety has to be enforced by systems outside the model and the agent harness.

Armadin takes a multilayer approach:

  • Hardened sandbox images. Every offensive agent runs in a minimal, locked-down environment with least-privilege access to credentials, files, and network by default.
  • Deterministic control proxies. Every action an agent takes toward a target passes through a policy proxy that enforces scope, rate, and technique limits in code, not in a prompt. Out-of-scope actions are blocked before they leave the sandbox.
  • Behavioral monitoring and observability. Agent actions and reasoning are logged and watched in real time, so unsafe behavior is caught and the agent is stopped or quarantined.

No single layer is trusted on its own. Each one assumes the layer above it can fail.

Tapping the NVIDIA Open Agent Safety Platform

We're excited to be among the organizations working with NVIDIA to deploy NVIDIA Open Agent Safety Platform technologies. NVIDIA OpenShell open source software provides a secure runtime boundary that governs agent actions. NVIDIA Sentry reference system design uses NVIDIA DOCA on NVIDIA BlueField-4 DPUs for hardware-isolated, out-of-band monitoring and policy enforcement. The platform is built similar to the way autonomous vehicles are built: layered controls with redundancy at every level, and a shared-responsibility model across software, hardware, and compute. That is the same architecture Armadin already uses to keep offensive agents safe.

This means the safety guarantees behind Armadin's AI attacks can extend from our software layer down to the infrastructure, with controls an agent cannot see or bypass.

Contributing to OpenShell

Armadin is contributing to NVIDIA OpenShell, the open source runtime at the center of the platform. Offensive agents are a demanding test of any runtime boundary: they are designed to find and use every opening. What we learn keeping our own agents contained is exactly what makes a boundary stronger for everyone else's.

What's Next

Autonomous Security only works if autonomy is safe. Armadin will keep building offensive AI that runs against production with enforceable limits, and we'll keep contributing what we learn to the open tools the industry depends on.

Read more from nVidia >>

Continue reading
Kill Chains and Coffee Episode 5: Why AI Beats Human Pentesting
Blog
Podcast
Video
9.3.26
Kill Chains and Coffee Episode 5: Why AI Beats Human Pentesting
Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution
Blog
9.2.26
Compromising Cleo Harmony: A SAML Bypass Chain to Arbitrary Code Execution
Human Tradecraft Training Machine-Speed AI: Inside Armadin Episode 4
News
Podcast
Video
9.1.26
Human Tradecraft Training Machine-Speed AI: Inside Armadin Episode 4