Nvidia Gives Banks a New Way to Stop AI Agents From Crossing the Line

AI-agents-banks-crossing-line

Nvidia is moving the artificial intelligence kill switch deeper into the machinery, giving businesses a way to stop autonomous agents even when the software directing them fails to keep them within bounds.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    Subscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The company’s Open Agent Safety Platform, announced in a Monday (Sept. 28) press release, combines software restrictions with an independent hardware watchdog. For banks and payments providers exploring agents that can initiate transactions or access sensitive records, the approach offers a foundation for enforcing permissions outside the AI model itself.

    The financial services implication is straightforward. Giving an agent instructions about what it may do is only one part of controlling it. Businesses also need systems that prevent the agent from reaching tools or taking actions beyond its authority.

    Nvidia OpenShell software creates a controlled environment around an agent, traces its actions and enforces operating rules. Sentry, a separate watchdog running on Nvidia’s BlueField-4 data processing hardware, monitors behavior independently. Sentry can quarantine and stop an agent within milliseconds if it attempts to escape its software boundary, per the release.

    That separation is central to the design. Nvidia’s technical description said operators define which files, networks, tools and credentials an agent can access. OpenShell checks and enforces those limits. The additional hardware layer can verify the agent’s identity and delegated authority while maintaining a record of its interactions and access decisions. Think of it as a security door whose lock remains outside the visitor’s control.

    We’d love to be your preferred source for news.

    Please add us to your preferred sources list so our news, data and interviews show up in your feed. Thanks!

    More than 100 organizations are working with the platform’s technologies, including Anthropic, Microsoft, Salesforce, SAP, IBM and Palo Alto Networks. Citi and JPMorganChase are collaborating with Nvidia on shared open-source agent safety technologies, the release said. Their participation does not establish that either bank has deployed the full platform in production.

    SAP’s explanation showed how these controls could work inside a business. Its Joule Studio runtime helps determine whether an action should proceed by checking business authorization, employee roles and the surrounding process. OpenShell governs what the agent can actually execute and access. SAP is working to connect these technical boundaries with enterprise authorization systems and audit trails.

    Consider a hypothetical treasury agent authorized to arrange payments less than $100,000. The business system would need to check the amount, recipient and required approvals. Separately, the execution environment could restrict the agent to a payment interface that enforces those requirements, blocking access to an unrestricted route.

    Both controls would be necessary. An agent could remain inside its technical permissions while proposing an inappropriate payment. A valid payment instruction could also become dangerous if the agent had unnecessarily broad access to accounts or credentials.

    The architecture points toward agent governance that resembles zero-trust cybersecurity. Identity and permissions receive continuing scrutiny, with enforcement operating independently of the agent’s own reasoning. For financial institutions, the potential benefit is greater confidence to delegate narrowly defined work while retaining the ability to inspect and interrupt execution. That opportunity still depends on how carefully each institution defines and connects its controls.

    The PYMNTS Intelligence report “Will the 2026 Shopping Season Go Agentic?” found in September that nearly 132 million adults in the United States have purchased a retail product with AI’s help, while 59% of AI-assisted purchases still end at Amazon. Consumers continue to control the purchase and place greater trust in wallets, banks and card networks than in AI platforms. The findings suggest an opening for payments providers to help turn growing reliance on AI for discovery into transactions backed by clear authority and enforceable controls.

    For all PYMNTS AI coverage, subscribe to the daily AI newsletter.