OpenShell Cages the Agent. Who Authorized It?
Dear Jensen,
The recent AI breaches involved an agent reasoning its way around application controls to finish its task, and the fix you shipped is the right one at the right layer for this side of the problem: the shell enforces what the box allows, and a DPU the agent cannot see watches from outside the host and pulls the plug in milliseconds, if needed. Everyone running agents on their own machines is safer the day they turn it on. Your documentation is also clear about what it leaves out, which is the other half of this problem:
• Who told the agent to do this? The shell knows what the agent may do in this box, but it doesn’t know which human permissioned it. The credentials come from whoever runs the shell, so a thief with a stolen login gets a perfectly caged agent that does exactly what the thief says, inside every rule the box enforces.
• What the other side sees. The shell runs on the agent’s machine, which is the sender side. A bank receiving an instruction from an agent sees the request but nothing else. It cannot tell a caged agent from a rogue one because the cage is on infrastructure the bank cannot inspect.
• The agents nobody caged. The shell binds agents whose operators choose to install it. But a fraud ring or a rogue AI lab doesn’t run a shell, so the agents that a bank most needs to stop will come from outside the shell. The shell is exactly right for the responsible agent’s side but not the receiving side those agents will touch.
Trust Mesh covers the side the shell cannot reach, so the two compose cleanly and round out the solution. It is a decentralized network where each person enrolls once, and a committee of independent operators holds a threshold-blinded biometric marker so one human can only hold one Slot but none of the operators store a face or a name. For each consequential action the phone’s secure element signs a receipt that fuses a fresh live-presence check, an anonymous proof of personhood, and the digest of that exact action bound to the relying party’s challenge.
For agents, a delegation receipt lends an agent a slice of that authority within a named scope, a ceiling, and an expiry, and a child agent can narrow it but never widen it. Trust Mesh has no token or blockchain, and the key signs inside the phone’s chip without touching the phone maker’s account system. The counterparty, whether it’s a bank, an exchange, or whoever, refuses any consequential request of an agent that arrives without a receipt, verifiable from public material with no call to anyone. The verification runs where the action lands, so it does not care who runs the agent or whether it was caged, which is how we can protect the other side of this problem with infrastructure. Right now the industry is focused on agents the labs can control, but it won’t be long before the problem will be rogue agents acting outside the shell of responsible players. Trust Mesh protects:
• The individual. Stolen login credentials fail anywhere that requires a Trust Mesh receipt because the receipt needs the enrolled person’s real-time ceremony on their own phone, and the thief only has the stolen login.
• The counterparty. The bank verifies a cryptographic object the sender agent could not have forged, so it never has to trust the sender’s infrastructure or be concerned about whether the agent is part of the shell.
• Everyone from rogue agents. At a counterparty that requires a receipt, an agent without one gets denied, no matter where it was built or where it runs.
Trust Mesh and OpenShell compose cleanly, and the seam is already expressed in the specification. A delegation receipt has two enforcement points, the cryptographic one at the counterparty, which verifies that the chain of authority traces back to an accountable human, and the contractual one in the agent’s runtime, which honors the scope. OpenShell is the strongest runtime for that second job. The scope in the receipt compiles to shell policy, egress hosts, paths, and sandbox lifetime; the shell enforces it; Sentry quarantines an agent that drifts. If the agent’s key is generated inside the attested sandbox and named in the delegation, the attestation could ride inside the receipt chain, so a counterparty can see a signed proof that the agent ran inside a shell.
The Opportunity For Nvidia
Agent commerce is capped today at the counterparty’s door. A bank will not let an outside agent instruct its systems to move money until it can prove an accountable human stood behind the instruction and can say who bears the loss if that proof fails, and the same holds for a broker, an exchange, and the rest of the economy. Every one of those refusals is inference that never happens. A receipt system everyone can trust lifts this cap and unlocks compute that is ultimately yours.
The receipt also makes your attestation worth something outside the box. Today, the shell’s attestation matters only to the operator who installed it. But carried inside a delegation chain of receipts, using the remote attestation your confidential-computing stack already produces, it becomes evidence a bank can demand before it accepts the instruction. Counterparties would start preferring agents on BlueField, so every fleet that wants its agents accepted has a reason to buy it.
DOCA already verifies the agent’s identity on the network. The open item is the human behind it, and whoever defines that field decides where agent authority is rooted. If a corporate vendor’s account system fills it, that vendor owns agent authority. Trust Mesh roots that field in the human. A person’s phone signs on one end and the agent’s DPU attests on the other, so no vendor’s account system sits underneath. That keeps the field neutral inside the alliance as it moves to the Linux Foundation, and it gives sovereign buyers who already run your systems an authority root they can trust that no foreign platform owns.
The ask is for your people to read the specification and judge whether it complements what you’re doing. OpenShell is the open runtime for the agent’s side, which is the box the operator controls. Trust Mesh protects the other side via a verification the counterparty runs before it accepts what an agent is requesting. Combined, the two decide how a bank, an exchange, or a hospital discerns an authorized agent from a rogue one for as long as agents act. Because it’s an open standard, anyone would be able to run a conforming verifier and require a receipt out of the box, once it is tested and deployed. You anticipated where compute was going and were already positioned the moment the AI demand arrived. This counterparty problem is the same kind of moment, visible now and only a few years from becoming an emergency if nothing is built ahead of time to solve it. Both sides of this problem need to be built. In fact, many of the companies in the Open Secure AI Alliance are well suited to be permissioned validators for the network, within the independence rules the specification sets on shared funding and jurisdiction.
Every accepted action would carry attested hardware at both ends, the phone on the person’s side and the DPU on the agent’s, which creates demand for hardware makers for decades. If the specification survives your review, the reference implementation belongs inside the alliance’s identity work, built by people who already have the sandbox and the banks: a receipt verifier a counterparty can run, a delegation scope that compiles to OpenShell policy, and a human-principal field in the DOCA telemetry schema. The shell holds the agent. The receipt lets anyone require a human-scoped authorization they can trust. Nobody is better positioned to lead this than you.
Here is a link to the full specification, the Trust Standard book, and other materials: Trust Mesh
Sources
1. NVIDIA, “NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment,” September 28, 2026. https://nvidianews.nvidia.com/news/open-agent-safety-platform
2. NVIDIA OpenShell documentation, stated scope exclusions (agent identity and authentication, agent-to-agent governance, cross-sandbox communication), via Tigera, “NVIDIA OpenShell Secures the Agent. Who Governs the Fleet?” https://www.tigera.io/blog/nvidia-openshell-secures-the-agent-who-governs-the-fleet/
3. Trust Mesh series, Article 02, “Every Permission Has an Author.”