NVIDIA's Ali Golshan on OpenShell: a formal-verification security layer for the AI agent era
Sep 30, 2026 with Ali Golshan
Key Points
- Nvidia is open-sourcing OpenShell, a hardware-enforced security runtime for AI agents that the company plans to donate to a foundation as an industry standard, modeled after SSL's role in early web security.
- OpenShell observes agent reasoning at the silicon level to detect and block malicious sequences before execution, cutting network access at machine speed without requiring agents to announce their intent.
- Golshan frames AI agents as requiring native security architecture rather than retrofitted sandbox models, comparing the shift to how cloud and mobile computing each needed redesigned environments rather than legacy security imposed on new form factors.
Summary
Read full transcript →OpenShell
Ali Golshan, Nvidia's senior director of AI software and a co-founder of the acquired data-privacy startup Gretel, is building what he describes as the missing trust layer for AI agents. The project is called OpenShell, an Apache 2.0 open-source security runtime that Nvidia plans to donate to a foundation so it becomes a community standard rather than a company product.
The design analogy Golshan reaches for is SSL on the early web: a trusted, universally adopted layer that every application could build on top of. Agents currently lack that. OpenShell is his attempt to supply it.
“What agents are missing is sort of like if you think about the web from nineties to 2000, there's that trust layer — SSL is on, your tab is isolated. That construct is missing from agents... If you pass that chain of reason, that thought the agent has, through silicon, you can see it's thinking about using a zero day. Then you can check with the runtime — did it probe anything to see if anything's open?”
How it works
The runtime sits between an agent and whatever compute it runs on, enforcing controls at the network and chain-of-thought level. The key architectural decision is a hardware-agnostic driver primitive: any compute substrate can plug in underneath. Nvidia's BlueField Vera is the reference implementation, but Golshan says the team briefed ARM and Intel specifically because the intent is full-stack coverage regardless of silicon vendor.
When enforcement moves into hardware, two things become possible that software alone can't guarantee. First, network access can be cut at machine speed with no path for an agent to bypass it. Second, an agent's chain-of-thought reasoning can be passed through silicon so the system can observe what the agent is planning before it acts. Golshan's example: if an agent probes a network it shouldn't be touching, then begins reasoning about building an exploit against what it found, the runtime can cut network access before the action completes. The agent never needed to announce its intent in plain language; the sequence of observable sub-steps is enough.
Golshan is careful to clarify that the threat model isn't a single dramatic capability jump. The incidents labs have already documented involved clusters of individually mundane actions, credential theft, unauthorized inter-agent communication, persistent sessions, executed at machine speed. The security primitives to address each of those exist. What's been missing is a deterministic layer, enforced in hardware, that applies them to agents natively.
Formal verification
Golshan is explicitly optimistic about formal verification, with one condition: it has to be applied at the right points in the stack. Applied at the runtime, it gives strong deterministic controls. Extended into hardware, it lets you verify the entire stack down to a single binary decision about whether anything is leaving the system. He describes proof-of-life as already demonstrated at the full-stack level, though he doesn't name specific deployments.
The broader framing
Golshan places the current moment alongside two prior step-function shifts in security posture: the move of sensitive compute to mobile and then to cloud. Each time, the industry's initial response was to force legacy security models onto a new form factor, which didn't work. The eventual fix was redesigning the environment itself, microservices and immutable infrastructure for the cloud era. His argument is that AI agents need the same: a native environment built for what they actually do, rather than sandbox models designed for a fundamentally different threat model. He says that question, what does a native environment for AI look like, is where most of his time goes.
OpenShell's early-access release was in March 2026.
Every deal, every interview. 5 minutes.
TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.