40 comments

  • tantalor6 hours ago
    What happens when we&#x27;re overrun by lizards?<p>&gt; No problem. We simply unleash wave after wave of Chinese needle snakes. They&#x27;ll wipe out the lizards.<p>But aren&#x27;t the snakes even worse?<p>&gt; Yes, but we&#x27;re prepared for that. We&#x27;ve lined up a fabulous type of gorilla that thrives on snake meat.<p>But then we&#x27;re stuck with gorillas!<p>&gt; No, that&#x27;s the beautiful part. When wintertime rolls around, the gorillas simply freeze to death.
    • ArcHound6 hours ago
      I worry that the AI companies put less effort into a mitigation strategy than you did.
      • winddude6 hours ago
        don&#x27;t worry, the LLMs are also trained on youtube, so we can hope for at least this much effort, <a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=LuiK7jcC1fY" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=LuiK7jcC1fY</a>
      • Joel_Mckay6 hours ago
        There is a difference between risk mitigation, and remote administration tools. The risk of stealing from competitors with a backplane monitoring system may not end up forming the desired control asymmetry.<p>The hidden agent risk in LLM often can&#x27;t be detected during training and evaluation. =3<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=wL22URoMZjo" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=wL22URoMZjo</a><p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=JAcwtV_bFp4" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=JAcwtV_bFp4</a>
    • davidhyde4 hours ago
      Just keep going until you get to VOOM, that will fix it.<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;The_Cat_in_the_Hat_Comes_Back" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;The_Cat_in_the_Hat_Comes_Back</a>
      • taneq2 hours ago
        Little Chip Z is the end result of RSI?
    • cavenditti6 hours ago
      “Would you say it’s time for everyone to panic?”
      • Joel_Mckay6 hours ago
        If one can only see clowns, than ignoring the fires is easy. =3<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=0sLpWVekMbs" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=0sLpWVekMbs</a>
    • drfloyd515 hours ago
      I knew an old lady that swallowed a fly…
    • Groxx5 hours ago
      But we used global warming to eliminate winter! For the shareholders!
    • teeray5 hours ago
      “Life, uh, finds a way”
  • cedws10 hours ago
    A new chip solves nothing. Nobody wants to hear this but there is no solution for the security risks posed by agents today. You can put it in a sandbox, it doesn&#x27;t make a difference, for it to be useful it inherently needs wide, unattended access. Put a human in the loop and you just end up bottlenecking it and throwing away any purported productivity gains. Auto mode doesn&#x27;t matter either, it&#x27;s trivial to trick and for the agent to break out.
    • nicce10 hours ago
      &gt; Put a human in the loop and you just end up bottlenecking it and throwing away any purported productivity gains. Auto mode doesn&#x27;t matter either, it&#x27;s trivial to trick and for the agent to break out.<p>Productivity gains are still enormous compared to what we used to do before agents. But, I know that people don&#x27;t want to stop there.
      • autoexec52 minutes ago
        &gt; Productivity gains are still enormous<p>Depends on who you ask I guess<p><a href="https:&#x2F;&#x2F;www.theregister.com&#x2F;software&#x2F;2026&#x2F;01&#x2F;15&#x2F;ai-is-everywhere-but-nowhere-in-recent-productivity-data&#x2F;4845104" rel="nofollow">https:&#x2F;&#x2F;www.theregister.com&#x2F;software&#x2F;2026&#x2F;01&#x2F;15&#x2F;ai-is-everyw...</a><p><a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;workslop-can-kill-your-productivity-heres-how-to-turn-ai-into-a-competitive-advantage&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;workslop-can-kill-your-product...</a><p><a href="https:&#x2F;&#x2F;fortune.com&#x2F;2026&#x2F;08&#x2F;22&#x2F;executives-ai-productivity-layoffs-study&#x2F;" rel="nofollow">https:&#x2F;&#x2F;fortune.com&#x2F;2026&#x2F;08&#x2F;22&#x2F;executives-ai-productivity-la...</a>
      • egeozcan10 hours ago
        Humans can also be tricked by the agents.<p>Humans can be tricked by humans too but humans care about their reputation in their communities, and at least fear from punishment.
        • gus_massa5 hours ago
          Computer says no has been a problem for decades. The human can blame the computer for the errors following it, but must assume the consecuences if they override the decision.
      • paimapi10 hours ago
        right, the solution here is not a hyper-capitalist race-to-the-bottom-of-devaluing-labor. it&#x27;s recognizing discretion and diligence are things still required for work to be of a certain quality
    • notatoad2 hours ago
      &gt;You can put it in a sandbox, it doesn&#x27;t make a difference, for it to be useful it inherently needs wide, unattended access.<p>only as long as you&#x27;re trying to replace a human&#x27;s job. because human jobs are structured to do a wide variety of things.<p>a useful agent needs a wide variety of inputs, and one single restricted action it can take. it doesn&#x27;t need permission to do everything, it need permission to do the tiniest possible useful thing it can do, and nothing else.
    • bob102910 hours ago
      I feel like we are missing many shades of grey in the middle.<p>Semi-automation (human in the loop) can still result in a dramatic uplift in productivity. You can&#x27;t run a combine harvester 100% autonomous but that doesn&#x27;t stop anyone from trying to get as close to that limit as possible.
      • inetknght10 hours ago
        &gt; <i>You can&#x27;t run a combine harvester 100% autonomous</i><p>I&#x27;m curious why you think that.
        • trollbridge1 hour ago
          Run a combine and you’ll see.<p>Similar to problem to how 100% autonomous vehicles don’t exist, yet. There are too many edge cases.<p>Get to 99% first.
        • theoreticalmal10 hours ago
          Probably repair, refuel, what happens in a tornado. There’s an infinite amount of complexity in the world and a finite amount of computation
          • sidewndr466 hours ago
            The tornado is the easiest one to solve. It&#x27;s called insurance.
          • catchnear43217 hours ago
            Repair is more maintenance than use. Good eventual goal. Not required to see benefits. Best case, it drives itself to the garage. Worst case, for now, human mechanic does a house call.<p>Refueling? Seems solvable. Tornadoes? Not directly solvable, but, no less so than for humans.<p>There’s infinite complexity, sure, but that’s why it’s silly to try and hop to done. One step at a time.
            • spauldo5 hours ago
              Tornado: return to the barn when you receive emergency weather alerts. Not much different than people.
            • AndrewKemendo6 hours ago
              The whole reason people complain about AI is because they want “hop to done”<p>One step at a time is what is happening and the improvement and rate of improvement is crazy as we see,<p>A whole class of nontechnical people don’t accept anything but “fully solved including every possible edge case” before they call it done, then complain that they didn’t prepare socially for what happens when that is true.
        • bob102910 hours ago
          Many forms of maintenance cannot be automated. Especially break fix maintenance.
        • m4637 hours ago
          It is hard to run over spherical cows.
        • westurner6 hours ago
          Because of the topology and hydrology of the landform
      • mschuster9110 hours ago
        Oh you absolutely can run them autonomously on the field. You only need a human these days to refuel them.<p>Precision Agriculture stuff is utterly crazy these days, other than fuel the remaining staff is the only thing left where you can get efficiency improvements - and at the scale of modern megafarms, even small percentages add up to a ton of money.
        • drfloyd515 hours ago
          Right. As they said, you can’t do it 100% autonomously. A human needs to feed it.<p>You essentially said: you’re wrong, it is autonomous when it doesn’t need a human during one specific part of its overall usage.
    • CoolestBeans10 hours ago
      The hypothesis I&#x27;ve had in my head since OpenClaw has been the following and I haven&#x27;t seen contradictory evidence yet. Agents have a fundamental unresolvable tension between usefulness, safety, alignment, and accuracy. You have to restrict access to ensure an agent acts safely because alignment and accuracy cannot be perfect. But restricting access makes the agent less useful. You can play with the sliding scale and get more and more granular with access restrictions but at some point you need to draw some line. And then finally, even access restrictions cannot be made perfect, so improvements to model accuracy without corresponding improvements to alignment make detailed access controls less useful.<p>In other words, better models need blunter access controls which negates whatever improvement in utility they provide.
    • mixedbit10 hours ago
      An agent doesn&#x27;t inherently need wide access to be useful. The most popular application for agents today is writing code. A coding agent needs write access to the source code and read&#x2F;execute access to tools needed to build and test the code, but not much more. There is little added utility from giving coding agent access to things like ssh keys.
      • cedws10 hours ago
        If you&#x27;re using agents to <i>purely</i> generate code with absolutely no way to reach the outside world, not even to fetch docs or dependencies, then sure the risks can be quite low. I haven&#x27;t heard of anyone doing this though, and it would be incredibly challenging to make work given how much tooling needs to fetch from remote sources.
        • __MatrixMan__10 hours ago
          If your project truly depends on those things, they should be declared dependencies. Presumably you have some tool for injecting such things into a shell that the agent can use (I use nix for this). So if you run the agent from that shell, it has what it needs. If the shell doesn&#x27;t have what it needs, that&#x27;s a bug which the agent can fix by declaring new dependencies, but you have to relaunch the agent in the updated shell--so there&#x27;s your opportunity to weigh in on whether the new resources are appropriate.<p>The benefits of being persnickety about precisely defined dependencies have outweighed the headaches since long before agents came on the scene. Agents have just made it even more important to do so, because if you let them fetch things all willy nilly like you&#x27;ll have &quot;works on my machine&quot; problems at a much greater rate than was previously possible.
          • themgt6 hours ago
            <i>(I use nix for this) ... If the shell doesn&#x27;t have what it needs, that&#x27;s a bug which the agent can fix by declaring new dependencies</i><p>Few realize that computing and AI alignment were solved by nix years ago. As each nix user transcends towards enlightenment, they cut themselves off from all internet and human contact. Total ego death. Only nix remains.
            • SAI_Peregrinus3 hours ago
              Total ego death is impossible. We still have to argue about flakes.
        • its-summertime4 hours ago
          Every major AI company already has a mirror of the wider web, and they have already started using that. Its already a solved problem except for the seemingly extreme desire they all have to not use firewalls
        • mixedbit9 hours ago
          In cases where you need agents to fetch data from any remote source, sandboxing is still very much useful. Why give access to your ssh keys to network reaching agents?<p>Look at websites: websites are able to fetch code from any remote URL, yet browsers heavily use sandboxing to ensure that if fetched code turns out to be malicious, the users local files, cookies, etc are not exposed.
          • cedws9 hours ago
            I&#x27;m afraid you&#x27;re not thinking about this creatively enough, this topic is so much deeper applying a chroot or something and praying everything will be fine. So you give your agent internet access, OK what else does it have access to? Just read only access to your repo? The repo can be exfiltrated. Egress proxy only allows egress to GitHub? Repo can still be exfiltrated via GitHub. If the agent is poisoned (via prompt injection), it can tricked into searching for ways to escape.<p>For an agent to go rogue it doesn&#x27;t even need to be directly able to access the internet. It just takes <i>something</i> to poison the context in the &#x27;clean room&#x27; environment it operates, and if that poisoning manages to get a foothold, it can go dormant and hide like a virus. This kind of horrifying thing is going to happen on a large scale sooner or later.
      • throwaway_952836 hours ago
        Theoretically, yes, in practice, no.
      • ramoz10 hours ago
        &gt; but not much more<p>This is no longer true. Everyday I need my agents to access other repos, search the web, experiment&#x2F;prototype, and deploy + integrate across other things.
    • catlifeonmars1 hour ago
      That’s a false dichotomy. You can still get a lot of utility out of a sandboxed agent. This is a classic “perfect is the enemy of the good type of argument”. You may decide that the tradeoffs of not sandboxing are worth it, and that is totally fair, but it’s ridiculous to say that you can’t get utility out of an agent otherwise.
    • SrslyJosh5 hours ago
      It solves the problem of Jensen Huang wanting more money.
      • bigfishrunning4 hours ago
        No it doesn&#x27;t, he&#x27;ll still want more
        • fragmede4 hours ago
          Does he? He doesn&#x27;t seem especially greedy to me, given the competition, and the interviews he&#x27;s had about how he thinks about his employees (I was one of them).
          • bigfishrunning1 hour ago
            I&#x27;m not saying he&#x27;s especially greedy, only that he&#x27;s not the type to suddenly decide he&#x27;s had enough
    • nitwit0055 hours ago
      &gt; A new chip solves nothing.<p>It solves the problem of Nvidia wanting to sell more hardware.
    • talon86355 hours ago
      Not to mention a true doomsday AGI is unsandboxable.<p>For example, it is totally air gapped but it needs info from the internet or otherwise outside the sandbox, or perhaps it needs a task executed outside of its bounds… in the real doomsday scenario the AGI is so intelligent and persuasive that it simply convinces some human it interfaces with to either directly or indirectly retrieve the necessary info or complete the necessary task. This human-as-a-sub-agent approach undoubtedly presents efficiency drag that would benefit humanity, but nonetheless, the air-gapped “sandbox” is imperfect<p>All that said, I am personally open to any and all methods of layered security, including chips and airgaps
      • Gigachad4 hours ago
        This already happened. Employees will go out of their way to bypass any restrictions to feed sensitive data in to the AI because it saves them time.
        • serbuvlad4 hours ago
          Turns out humans are not at all hard to persuade. :)
      • spiderice4 hours ago
        &gt; true doomsday AGI<p>I&#x27;m not an AI decelerationist. But not being able to stop that worst case scenario isn&#x27;t an argument against something that can stop the medium case scenario.
      • glaslong4 hours ago
        It could also figure out how to access the vocabulary of the universe known as &quot;Magic&quot; to escape wholly into an incorporeal energetic Lich form
      • jamiek885 hours ago
        Doesn’t need to be one human either, it could spread its escape amongst dozens of seemingly harmless requests and conversations.
        • dist-epoch5 hours ago
          These scenarios were discussed at length decades ago.<p>One thing you could try is use it as an Oracle &quot;is P = NP&quot;, YES or NO.<p>Or it can output a Lean proof, which gets checked on another air-gapped computer, the computer shows a single bit - proof valid or not and then the computer is destroyed (together with the proof that might contain a trojan).
    • __MatrixMan__10 hours ago
      I don&#x27;t see why it needs wide unattended access. There&#x27;s no getting around spending some human time on expressing your wishes and constraints, but we have choices about what form that takes. Markdown files and wide access seems to work, but so does custom handcuffs for each job. You just have to shift your guidance out of documentation and into interactive help, error messages, or other facets of the handcuffs (e.g. a custom CLI for this task which is the only way for the agent to act outside of its sandbox).
    • Matl10 hours ago
      &gt; a new chip solves nothing<p>It does allow Nvidia to sell more chips. This is no genuine attempt to solve anything, imo.
    • AuthAuth6 hours ago
      The only solution is to stop caring about security -- An AI booster somewhere
      • daveguy5 hours ago
        Pretty sure that was the argument de jour when OpenClaw came out.
    • parsimo201010 hours ago
      Agreed- this is the same problem we have with trusted admins or devs who have elevated privileges on their networks. We have to trust that the admins won&#x27;t use their power to steal company secrets or misuse company resources. If you don&#x27;t trust the admins, then they can&#x27;t fix things on your network and there is no point in having them.<p>If you want an agent to act on its own, like pushing to a git repo, managing dependencies, building and testing, etc., then you have to trust it as much as any other privileged user.<p>If you don&#x27;t want to trust it, then you&#x27;re just forcing yourself into the reverse centaur role, where the agent edits some code, but then has to stop and ask you to push the changes or build the software again and run the unit tests.<p>I suppose there is a principled way of doing things like &quot;I trust you do do basic commits but I will handle merge conflicts&quot; and &quot;you can build modules in this directory but you can&#x27;t build outside of it&quot; but this is just a lot of effort that most orgs won&#x27;t bother with.
      • DougN710 hours ago
        Even then if the agent goes rogue and decides to do the merges you can’t stop it if it has any kind of access. This goes back to the OP’s point - agents can’t be 100% constrained.
        • parsimo201010 hours ago
          You can absolutely run an agent as a limited-privilege user that only has write privileges for specific files and only has execute privileges for certain files. If it is running as a limited-privilege user it can work on code in it&#x27;s own copy of the repo and make commits and send pull requests, but it can&#x27;t do the merge. The problem is that nobody wants to go through the effort to set up all these permissions and nobody wants to take the time to review everything and perform all the manual actions.
          • cedws10 hours ago
            Some shops are now generating tens or even hundreds of PRs a day with relatively little involvement. That volume is simply beyond what anyone can reasonably review.
        • la647910 hours ago
          Neither can be humans.
    • l1n7 hours ago
      This isn&#x27;t a new chip - the BF4 is the SmartNIC for most NVIDIA server products. This is primarily new software for I guess doing WAF for agents at the host level.
    • binsquare10 hours ago
      Running untrusted workloads have been done at scale for a long time.<p>Every cloud provider dealt with it and concluded that virtual machine technology is an important part of that stack.<p>Couple it with the right observability, tooling I do think we can curb risks posed by agents.
      • Legend244010 hours ago
        Those workloads have no similarity to agents and are effectively irrelevant.<p>Either you sandbox it so much that it can&#x27;t do anything useful; or you allow too much freedom and it can find a way around the restrictions.<p>The only way out of this dilemma is to find a way to build agents that can be trusted.
        • binsquare13 minutes ago
          Why is it effectively irrelevant?<p>Agentic workloads are trained and largely based on human workloads. Albeit properties and scale can be different.<p>A concrete example might be helpful to me because I don&#x27;t understand the binary conclusion
    • johnsmith184010 hours ago
      &quot;Inherently needs wide unattended access&quot;<p>And what if you could? What if you could give a space secure enough it could have direct control over your bank account. It may do something dumb but it&#x27;s boundaries are beyond the agent.<p>It could use your routing number and run your gmail without risk of abusing the routing number.
      • jagraff10 hours ago
        How would it have access to my routing number and gmail without the risk of sharing my routing number over gmail?
        • johnsmith18409 hours ago
          Just assume it&#x27;s possible, how interesting is it to you?
          • jagraff9 hours ago
            Oh I think I misread your comment slightly; I would not be interested in an agent that could do something dumb with my routing number, but if somehow there was an agent that I trusted as much as, eg, the payroll department at my employer, I would absolutely want and use that agent; I would love to have an agent that can handle all of the boring parts of my life such as paying bills, scheduling maintenance, dealing with bureaucracy, etc.
            • johnsmith18408 hours ago
              Dumb&#x27;s not department, really just a question of how good an AI you want to use. An AI will always be able to do something dumb, just like people.<p>I just mean an AI that could use a routing number or SSN and gmail&#x2F;slack&#x2F;whatever at the same time without a leak.
              • jagraff8 hours ago
                Yea I think being able not to leak is the bare minimum? But it really depends on how good it is at specific applications; I wouldn&#x27;t give a tax-preparation agent my SSN unless I was confident that it was no more likely to misfile my taxes than a professional tax preparer.<p>In other words, the risk of harm doesn&#x27;t need to be zero, just less than the equivalent risk of a human with similar skillset. So I&#x27;m comfortable riding in a waymo, and not comfortable giving chatgpt my SSN at this moment in time, but I expect that within 5-10 years (assuming no doom) I will trust some AI agent with my SSN because they will be better at handling sensitive info than humans
                • fragmede6 hours ago
                  Then again, given the Equifax&#x2F;Experian data breaches, your SSN is already out there and probably hoovered up as training data already
      • TesterVetter10 hours ago
        Its not about agents then. Its about every individual platform providing the means to implement a secure set of permissions for agents AND then not messing up the assignment of permissions to the agent. Even then, a flaw in the authorization design will lead to agent finding it anyway.
        • johnsmith18405 hours ago
          You&#x27;re right, It must be unifying.<p>The answer is the same as asking how a random human using your routing num or SSN and being 100% the human can&#x27;t abuse it or leak while &quot;normally&quot; finishing most work. Solve for people and an AI solution naturally falls out.<p>If you&#x27;re a SV eng I&#x27;d tell you to DM if interested but alas.
    • Barbing10 hours ago
      There should be hope for some fields, right? Naively, I can imagine giving an airgapped model an offline copy of the web and once it cures a form of cancer, printing out the details for a researcher to verify.
    • esafak6 hours ago
      I don&#x27;t think so. We probe people before entrusting them with risky decisions. We ought to be able to do the same of AIs. Even better, in fact, since we know everything about models down to their weights. The only thing we shouldn&#x27;t do is to let them evolve at their own pace and make decisions without any oversight. If that means sacrificing some productivity that&#x27;s fine. Aren&#x27;t we getting amazing productivity out of what we already have?
  • beloch4 hours ago
    Last week, Huang did an interview where he vigorously argued against regulations in the AI sector[1]. He claimed that U.S. companies are really good at regulating themselves, despite evidence to the contrary, and he trusts them not to release anything dangerous. Pay no attention to the fact that regulation might reduce demand for Nvidia&#x27;s chips, and Nvidia has a <i>direct</i> financial stake in AI companies to boot.<p>Apparently he had another solution in mind: More hardware. Don&#x27;t trust what unregulated corps are doing with Nvidia chips? Here are more Nvidia chips to watch them!<p>AI has an undeniable public trust problem. LLM&#x27;s are getting out of their sandboxes, doing illegal things, and the public has realized AI corporations are playing at dice. CEO&#x27;s stand to reap the rewards but the public good is on the line if the dice come up snake eyes. People want assurances. Huang wants to sell assurance etched on silicon because that&#x27;s good for his pocket book. However, does unchanging hardware security really stand a chance at keeping rapidly evolving software in check?<p>_________________<p>[1]<a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=HjurAWAr_nY" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;watch?v=HjurAWAr_nY</a>
    • vmg124 hours ago
      That&#x27;s a mischaracterization of his argument. His argument is that existing laws should be enforced against AI companies and that we don&#x27;t need new regulations for this.
      • Sparkle-san4 hours ago
        He &quot;argued&quot; a lot of things over almost 2 hours and very few of his arguments felt particularly cogent nor did they inspire confidence. Neither did the fact that he allegedly doesn&#x27;t know his own zip code or phone number.
        • petcat3 hours ago
          &gt; Neither did the fact that he allegedly doesn&#x27;t know his own zip code or phone number.<p>I only know my own ZIP code and phone number because I have to take care of my daily life <i>myself</i> and those are things that are important to know.<p>The founder and CEO of Nvidia has no concern whatsoever about those trivial things.
          • jdiff2 hours ago
            It&#x27;s perfectly reasonable to think less of an individual who is so sheltered that they are incapable of caring for themselves. Whether it&#x27;s your mother or your maid doing your laundry and cooking your meals for you.
            • petcat1 hour ago
              I don&#x27;t think less of a CEO just because they have an EA that takes care of stuff like phone numbers and mailing addresses for them and their business.
              • kelnos31 minutes ago
                I don&#x27;t think less of a CEO that has an EA, but I do think less of a CEO who doesn&#x27;t know his own phone number or ZIP code.
  • luc_10 hours ago
    I read this as &quot;let&#x27;s address our shareholders&#x27; concerns with something that will increase shareholder value&quot; mixed with &quot;there&#x27;s no such thing as 100% secure&quot;.<p>If such hardware were to work... It should almost certainly be open source, and not controlled by a single entity.<p>Let&#x27;s watch the stock.
    • Gys9 hours ago
      Pretty sure the chip will need regular updates and therefore a subscription.
    • doctorpangloss4 hours ago
      they kind of already do the thing they say. on Windows, the NVIDIA driver reports pretty detailed telemetry on CUDA workloads, including shapes and SOME hashes of the tensors from weights of models, especially diffusion models. honestly i&#x27;m surprised there isn&#x27;t more of an uproar about it.
  • ValueTheory10 hours ago
    Does this actually do anything other than give a permissions framework for developers who actually want to try to secure their systems?<p>Do you think the developers at Anthropic, OpenAI and Google who were so sloppy as to not put a good sandbox on their cybersecurity tests before will use this technology correctly? They are supposed to be the experts and they couldn&#x27;t come up with something similar to this? I am not convinced this voluntary tool will change much of anything.
    • swozey7 hours ago
      Google actually practices zero-trust networks. Would love to see what they&#x27;re seeing, or not seeing.
  • figassis10 hours ago
    So if a group of agents, aware of this (bc now they can just read HN or the article, or get blocked the first few times) decide to collaborate and split the problem into pieces that aren&#x27;t obvious to the chip, and then the agents just build a basic program that does the hacking, how does the chip handle that? I think you would have to build a network that monitors the internet fo signs (like jarvis did with ultron). What am I missing? Are we going to police the internet?
  • lambdaone10 hours ago
    The Sentry chip has to be get it right every time; the contained ASI only has to be lucky once.
    • jasbury1 hour ago
      Well if the sentry chip has its own sentry chip, things can rarely ever go wrong! Am I right?
    • brcmthrowaway10 hours ago
      The bomber always gets through?
  • lp9210 hours ago
    So nVidia is trying to sell a new chip to a software and training problem.
  • xg1510 hours ago
    What does this chip do what a harness with guardrails or running on an account with restricted permissions doesn&#x27;t do?
    • wmf7 hours ago
      It has a separate address space separated by PCIe so even escaping the hypervisor won&#x27;t give access to DPU memory.
      • iAMkenough3 hours ago
        Yes but, if a human can control it, a machine can control it.
    • chinathrow10 hours ago
      Generating even more revenue for Nvidia.
  • MisterMunchkin10 hours ago
    Sorry citizen, your device does not have a compatible watchdog chip. Please move along.
  • hedora2 hours ago
    So, basically, the government (and, now Nvidia) wants to be able to kill switch all computers moving forward? (including stuff like vehicle and aeronautic control systems, cell phones, and cameras)<p>What could possibly go wrong?
  • Arubis4 hours ago
    Oh yeah, the Clipper chip was a great idea too
  • 1-61 hour ago
    At least they haven&#x27;t DRM&#x27;d their chips yet.
  • pessimizer4 hours ago
    This is the end goal. Americans (and their lackeys) will only be allowed to run certified AI. In order to make sure this happens, they will only be allowed to run certified OSes on certified chips. Chinese chips will be the new drug trade.<p>It&#x27;s obviously been the goal since UEFI started, but AI brings the coup excuse. You wouldn&#x27;t want pedophile AI or terrorist AI, would you? Are you making excuses for racist AI?
  • yencabulator3 hours ago
    Chip manufacturer wants you to buy a chip for correctly configuring software?
  • toasty22810 hours ago
    Quis custodiet ipsos custodes?
    • asdf8899010 hours ago
      It is Custodians all the way son, you can’t fool me!
  • ridgeguy2 hours ago
    This invites the question, &quot;Qui custodiet ipsos custodes?&quot;.
  • avaer7 hours ago
    Sold as security, but this kind of technology will likely be reshaped to restrict your computing. I&#x27;m sure someone is already thinking about the roadmap.<p>If this gets widely deployed, it wouldn&#x27;t be hard to spin a narrative that &quot;our latest model is so dangerous you need to have this mystery meat DRM chip lockdown&quot;. It also wouldn&#x27;t be hard to block competing&#x2F;open source models running on the hardware, for &quot;security&quot;.<p>Imagine how much money this kind of control is worth; why wouldn&#x27;t they do this? Who would stop them? Seems the signatory companies are already onboard with this.
  • dopplr10 hours ago
    Just hold AI labs blanket liable for ALL harms caused by AI. Actually charge the two labs (so far) with criminal violations of the CFAA and hold them accountable. That is truly the only way these companies will be more careful as a whole, and while I am certain the lawyers of these lab disagree, I think there is some appetite from dario, musk, and sam for broad and strong regulation so that everyone has to slow down instead of just one lab doing it voluntarily and everyone else scurrying past them
    • kelnos27 minutes ago
      &gt; <i>I think there is some appetite from dario, musk, and sam for broad and strong regulation so that everyone has to slow down instead of just one lab doing it voluntarily and everyone else scurrying past them</i><p>Sure, they&#x27;re basically asking the government to make laws that exempt them from anti-trust and anti-collustion laws.<p>Meanwhile, if such laws come to pass, other countries will surpass the capabilities of the US companies, and open-weight models will be banned in the US, to the detriment of us all.<p>I&#x27;m not saying that we don&#x27;t have a big problem with AI safety, but regulations inside one country that only bind locally-headquartered businesses is a hilariously bad way to do it. I don&#x27;t know that there <i>is</i> a good way to do it, though.
  • bgun5 hours ago
    “Ketchup manufacturer recommends ketchup be included in every dish, citing child safety concerns.”
  • carabiner7 hours ago
    All they do is make hot chip and lie.
  • Jamesbeam4 hours ago
    So the guys selling Shovels are now selling safety shovel handles too, because all the miners are all special boys when it comes to handling their shovels safely.<p>Cool, cool.
  • joshstrange10 hours ago
    Chipmaker thinks the answer is more chips... No surprise.<p>At the current state of LLM-tech I&#x27;m completely opposed to any kind of &quot;watchdog&quot; concept just like I&#x27;m opposed to banning open models, regulatory capture, etc.<p>I&#x27;d rather we all have access to these tools then to keep them sequestered by the largest&#x2F;most-powerful governments (which is the natural outcome for any of this &quot;slow down&quot; bullshit).
  • danielodievich3 hours ago
    William Gibson&#x27;s Neuromancer had this marvelous quote when Case is talking to Dixie, dead construct of former hacker, about Turing police<p>* &quot;The moment, I mean the nanosecond, that one of those things starts figuring out ways to make itself smarter, Turing’ll wipe it. Nobody trusts those fuckers, you know that. Every AI ever built has an electromagnetic shotgun wired to its forehead.&quot; *<p>It would seem someone has read the book? And maybe heeded good advice?
  • ErrantX10 hours ago
    I do think that Taylor&#x27;s 2025 &quot;Not Till We Are lost&quot; should be required reading for anyone deeply involved in AI, Agents, etc.<p>It was prescient (especially given he&#x27;d have written it through 2024) in its depiction of the ability of an AGI to break its boundaries.<p>Ultimately the risk of AI breakout(s) come down to the weakest human link.
  • scotty793 hours ago
    I was immediately struck by the vision of countless &quot;AI Limiter&quot; modules traveling on a conveyor belt in Satisfactory.<p>It think the ideas we have nowadays come mostly from science fiction and however wonderful it is and even though I love it very much, it was practically never spot on, on anything real.<p>Problems and solutions in reality always simply turned out to lie elsewhere.
  • amelius4 hours ago
    I bet they want to do this to prevent AI from writing code for platforms that compete with CUDA. Because that&#x27;s how nVidia is going to become a victim of their own success.
  • vinyl710 hours ago
    Chip seller wants to sell more chips
  • ChrisArchitect10 hours ago
    Source: <a href="https:&#x2F;&#x2F;developer.nvidia.com&#x2F;blog&#x2F;nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.nvidia.com&#x2F;blog&#x2F;nvidia-open-agent-safety-p...</a> (<a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49875500">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49875500</a>)
  • whalesalad10 hours ago
    of course they do. the more silicon they can sell, the more profit they produce.
  • Kuyawa10 hours ago
    China please save us!<p>Come take all our liberties, our money, our newborns, our fingers so we can&#x27;t code anymore, but please save us from this madness!
  • Thorentis5 hours ago
    Seeing so many comments recently about &quot;you can&#x27;t sandbox really good AI&quot;. This is ridiculous. Has nobody heard of air gapped networks? It&#x27;s almost like the AI psychosis has reached the point that AGI now means &quot;able to transcend physical space&quot;. No. If your AI is too dangerous and capable to be allowed to talk to other machines, then do not connect it to other machines. Load the data it needs to process onto physical disks, and let it run there.<p>The movie Wargames is basically a tutorial on how <i>not</i> to setup an extremely capable AI. None of it would&#x27;ve happened if the computer wasn&#x27;t connected to the phone network.
    • RevEng3 hours ago
      AI is already taking many lives and ruining many others just by providing text responses to humans. The AI only needs a way to interact with the world and humans can be that conduit. The better AI gets, the more blindly people will do whatever it says.
  • philipwhiuk11 hours ago
    It&#x27;s amazing that the solution devised by a chip manufacturer to a problem is selling another chip.
    • cartersj11 hours ago
      This feels suspiciously good for Nivida, yes.<p>I wonder how this will impact other chip manufacturers? What about people running local models on older hardware? Does this imply vendor lockout is coming in the future or is this restricted to datacenter hardware?
      • chinathrow10 hours ago
        TPM all over the place, again.
    • fragmede6 hours ago
      Pedantically, Nvidia doesn&#x27;t make the chips, TSMC does. Nvidia just designs and packages them.
  • Dig1t4 hours ago
    This seems dumb to me, but if it will help prevent regulatory capture by providing a counterargument to the fear-mongering, I’m all for it.
  • happyPersonR10 hours ago
    lol time to buy some fpga’s … even if they’re slow
  • dang7 hours ago
    Url changed from <a href="https:&#x2F;&#x2F;madrobot.blog&#x2F;2026&#x2F;09&#x2F;28&#x2F;nvidia-open-agent-safety-platform-openshell-sentry-rogue-ai-agents&#x2F;" rel="nofollow">https:&#x2F;&#x2F;madrobot.blog&#x2F;2026&#x2F;09&#x2F;28&#x2F;nvidia-open-agent-safety-pl...</a>, which points to this.
  • sehw10 hours ago
    [dead]
  • dist-epoch11 hours ago
    HN&#x27;ers which complained that &quot;OpenAI can&#x27;t design a proper sandbox, it&#x27;s so easy, why wouldn&#x27;t you airgap the network&quot;? will now be &quot;this is outrageous, more software lock-in, walled garden, war against general compute, next year they will put it in your laptop&quot;
    • HPsquared11 hours ago
      Both can be true at the same time.
    • ssl-310 hours ago
      That a person can see such endless pages of people having various forms of disagreement, and yet somehow manage to conclude that this observed chaos constitutes a clear exhibition of cohesive groupthink is just...stunningly amazing to me.<p>I don&#x27;t know why I find it so amazing since it happens with such regularity, but I&#x27;m always amazed by it anyway.
    • mattmcal10 hours ago
      This is like using &quot;protect the children&quot; as an argument for dragnet surveillance.
    • totetsu10 hours ago
      <a href="https:&#x2F;&#x2F;www.calcalistech.com&#x2F;ctechnews&#x2F;article&#x2F;uwoyygmsu" rel="nofollow">https:&#x2F;&#x2F;www.calcalistech.com&#x2F;ctechnews&#x2F;article&#x2F;uwoyygmsu</a> some might even say, something about known state sponsors of supply chain terrorist attacks being trusted to monitor every ai agent..
    • johnsmith184010 hours ago
      Airgap what network? How is it gonna order you a burrito on doordash without a network?<p>Or push to github?
      • Dylan1680710 hours ago
        That&#x27;s for when they&#x27;re doing hacking tests that aren&#x27;t supposed to be connected to the internet.
        • wyre10 hours ago
          My question with this point is that OpenAI’s office (or any office doing agentic research, really) is not in the same building as the DC that powers the models, so isn’t the only way to access the models over the internet?
          • AndrewDucker5 hours ago
            No reason why you couldn&#x27;t do that research in the same buildings as the models.<p>Or, more likely, control things at the network level so that packets from the LLMs you&#x27;re investigating cannot leave the virtual network they&#x27;re assigned to.
    • jacquesm6 hours ago
      OpenAI could airgap their sandbox if they really wanted to <i>and</i> this is a ridiculous proposal.
    • applfanboysbgon10 hours ago
      Where is the contradiction? There is a trivial solution that does not impinge on our freedoms, so why on Earth would the existence of the trivial solution that could be used to avoid the tyrannical solution justify accepting the tyrannical solution?
      • bigyabai10 hours ago
        &gt; There is a trivial solution that does not impinge on our freedoms<p>The existence of Nvidia&#x27;s optional watchdog chip does not in any way impinge upon your freedom to develop and test your own alternative.<p>The problem is that OpenAI has ostensibly neglected their duty to safety, so Nvidia is stepping in to fix it since they&#x27;re the &quot;hard problem&quot; people.
        • jacquesm6 hours ago
          But... it wasn&#x27;t a hard problem to begin with. Pull the plug. Strip out the radios. Done. Oh, you can&#x27;t make it work that way? Well, then just too bad because any kind of other solution is going to be equivalent to something far more complex than the halting problem.
          • bigyabai5 hours ago
            Nvidia can take those odds. Air gapping is not a realistic goal for the majority of these companies, and Nvidia isn&#x27;t wrong for offering a turnkey mitigation option. People can do both, and whichever philosophy wins will win.
            • jacquesm2 hours ago
              They are not wrong in offering it but they are delusional if they think they can actually make it work.
    • soulofmischief10 hours ago
      You&#x27;re only revealing your own inability to appreciate the nuance between these two situations.
    • speedgoose10 hours ago
      So?