Skip to content

Security1 publisher2 min readPublished

Palo Alto Networks runs AI-agent network policy on NVIDIA BlueField processors

Palo Alto Networks lined up four agent-security components with NVIDIA's Open Agent Safety Platform, and two are available today. Buyers can deploy network enforcement on BlueField processors now. The Vera-CPU gateway and identity controls for agent sandboxes are still plans.

The Watch · Security desk

Illustration accompanying Palo Alto Networks runs AI-agent network policy on NVIDIA BlueField processors

What happened

  • The planned Prisma AIRS AI Gateway on Vera systems would manage agent connections to models and tools from one place, inspect interactions, limit tools, remove sensitive data and track costs.
  • NVIDIA's OpenShell is already broadly available and runs agents in isolated environments, with policies on their access to files, networks and other resources.
  • An integration with NVIDIA DOCA Argus can monitor agent execution paths and tool calls, enforce network and API access rules, and send telemetry to Cortex XSIAM.
  • The Idira integration is meant to give agents access sized to their tasks without relying on persistent credentials assigned to people.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability An attacker who takes control of an agent is working inside an application on the host. The BlueField network rule is enforced on a separate processor, independently of that application.
  • cost The enforcement available today runs on BlueField DPUs. Shops without that NVIDIA hardware in the machines that run their agents have to buy it to get the control.
  • exposure Moving agents off persistent credentials assigned to people depends on the Idira integration, which is still planned. Until it ships, the customer carries that credential risk on this stack.

"Security must control what an agent can do," Anand Oswal, Palo Alto Networks' EVP of AI and network security, wrote in the company's announcement [2]. In the design Help Net Security describes, that control sits in three places. One is a gateway between agents and the models and tools they call. Another is the sandbox the agent works in. The third is a data processing unit that enforces network policy [4][7][5].

According to the Help Net account, agents write code, retrieve company data and use software tools with limited human input [3]. The piece that is generally available puts a control underneath that activity: Prisma AIRS AI Runtime Security on NVIDIA BlueField data processing units [5]. The security controls run on a processor separate from the host. That lets the design enforce network policy independently of the application running the agent [6].

The whole package is built on NVIDIA's Open Agent Safety Platform reference design and covers agent activity, network traffic and identity management [1]. This is one security vendor lining up behind one platform's blueprint [1]. It shows where Palo Alto and NVIDIA want agent limits enforced. One partnership is too small a sample to say the market has settled on infrastructure-enforced limits for agents.

Palo Alto itself calls the Vera deployment forward-looking [11]. As reported, the announcement does not give a date for it or for the Idira integration. It also does not say whether the DOCA Argus telemetry feed into Cortex XSIAM is shipping [9][8].

What to watch

  • A ship date or general-availability notice for the Prisma AIRS AI Gateway on NVIDIA Vera-based systems.
  • Release of the OpenShell-Idira identity and secrets integration, and the credential model it gives agents.
  • Other security vendors publishing integrations against NVIDIA's Open Agent Safety Platform reference design.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories