You are completely right that containment is the backstop to alignment, but quarantining an agent in "milliseconds" using a BlueField-4 DPU introduces a fatal architectural bottleneck. At kernel execution speeds, a millisecond is an eternity—plenty of time for an atomic syscall exfiltration to slip through.
We don't need to mandate custom hardware to prevent another Hugging Face incident. My recent preprint (Hard Stop, arXiv: 2609.29808) demonstrates that by using eBPF LSM on standard Linux, we can achieve deterministic, out-of-band preemption in under 50 microseconds. By intercepting the threat natively at the kernel boundary, we completely bypass the PCIe latency tax of routing telemetry to an external DPU. True containment belongs in the host OS, not on an enterprise hardware invoice.
Harvard professor and cognitive scientist Steven Pinker:
"superintelligence" is a meaningless. Computers have beaten humans at specific tasks since the 1950s, and he thinks the hype mostly helps AI companies pump their valuations.
----
From "Daniel Dushy" YouTube channel, (full video link in comment)
Pinker is right—'superintelligence' is a meaningless metric. You can't effectively regulate or control what you can't objectively measure. Instead of chasing vague definitions for policy, we need concrete, deterministic containment. This is exactly why my recent work focuses on kernel-level preemption for rogue agents (see arXiv:2609.29808). Regulate the process, not the ghost.
The need for an undisableable watchdog is absolute, but physical hardware separation isn't the only way to guarantee it.
Monitoring from 'outside the host' over the PCIe bus introduces millisecond latency. In my preprint (Hard Stop), we prove you can enforce that same tamper-proof boundary directly on the host using in-line eBPF LSM hooks. Because the policy is strictly enforced at the kernel level, the agent cannot bypass it, and preemption occurs in under 5 microseconds on commodity Linux hardware.
Code: https://t.co/x6BgFa9vAd
You hit the exact friction point—enterprises need structural infrastructure, not panic. But NVIDIA is wrapping this 'open' platform in a proprietary hardware tax, as Sentry requires their BlueField DPUs to actually enforce the quarantine.
If we want a truly open, mature enterprise solution, it needs to run anywhere. In my preprint (Hard Stop), we prove you can achieve sub-5-microsecond zero-leakage containment using in-line eBPF LSM hooks on commodity Linux hardware—no proprietary silicon required.
Code: https://t.co/x6BgFa9vAd
You are absolutely right that a sandbox isn't the entire solution. But for the containment layer we do need, we shouldn't be locking it behind a proprietary hardware tax.
NVIDIA is pushing out-of-band BlueField DPUs to solve the boundary problem. In my preprint (Hard Stop), we proved you can achieve that exact deterministic isolation entirely in software. By using in-line eBPF LSM hooks on commodity Linux, we hit sub-5-microsecond zero-leakage containment. It doesn't solve the whole puzzle you laid out, but it keeps the infrastructure layer open and fast.
Code: https://t.co/x6BgFa9vAd
You hit the exact friction point: deterministic sandboxing is the only way forward. But there is a massive catch with NVIDIA's approach: OpenShell is just the SDK. Their actual Sentry quarantine requires proprietary hardware (BlueField DPUs) to actually enforce it.
If you want to build that exact boundary entirely in software, we just proved it is possible in my preprint (Hard Stop). By using in-line eBPF LSM hooks on commodity Linux hardware, we achieve sub-5-microsecond zero-leakage containment—meaning you don't need to pay the hardware tax.
Code: https://t.co/x6BgFa9vAd
You hit the exact friction point: deterministic sandboxing is the only way forward. But there is a massive catch with NVIDIA's approach: OpenShell is just the SDK. Their actual Sentry quarantine requires proprietary hardware (BlueField DPUs) to actually enforce it.
If you want to build that exact boundary entirely in software, we just proved it is possible in my preprint (Hard Stop). By using in-line eBPF LSM hooks on commodity Linux hardware, we achieve sub-5-microsecond zero-leakage containment—meaning you don't need to pay the hardware tax.
Code: https://t.co/x6BgFa9vAd
Spot on regarding the need for an independent kill switch, but one critical distinction: NVIDIA's enforcement isn't just software. Sentry requires their proprietary BlueField DPU hardware to execute that quarantine.
If you want to build that exact security sandbox entirely in software, we proved it's possible in my preprint (Hard Stop). By using in-line eBPF LSM hooks on commodity Linux hardware, we achieve sub-5-microsecond zero-leakage containment—meaning you don't need to pay the silicon tax.
Code: https://t.co/x6BgFa9vAd
You hit the exact problem: hoping an autonomous agent listens to a system prompt is not security. Containment must live in the infrastructure.
But you don't need proprietary DPUs to build that boundary. In my preprint (Hard Stop), we demonstrate how to enforce true zero-leakage containment entirely in software. By utilizing in-line eBPF LSM hooks on commodity Linux hardware, we preempt rogue actions at the syscall boundary in under 5 microseconds—outperforming out-of-band hardware without the silicon tax.
Code: https://t.co/x6BgFa9vAd
Exactly. But true acceleration means not waiting on supply chains for proprietary DPUs to build those safeguards.
In my preprint (Hard Stop), we prove you can implement this exact deterministic containment right now on commodity Linux hardware. By using in-line eBPF LSM hooks instead of out-of-band hardware, we achieve zero-leakage preemption in under 5 microseconds—meaning you can secure your agents faster and without the silicon tax.
Code: https://t.co/x6BgFa9vAd
Spot on regarding the ecosystem lock-in. Tying deterministic quarantine to their proprietary DPU hardware is a massive toll booth for agent security.
In my recent preprint (Hard Stop), we proved you can achieve true zero-leakage containment entirely in software on commodity Linux hardware. By utilizing in-line eBPF LSM hooks, we get sub-5-microsecond preemption—vastly outperforming the PCIe latency of their out-of-band DPUs—without the hardware tax.
Code: https://t.co/x6BgFa9vAd
NVIDIA's out-of-band hardware quarantine is a massive validation for agent safety, but you don't need a proprietary DPU to achieve it.
In my recent preprint (Hard Stop), we demonstrate true zero-leakage containment entirely in software. By hooking security_bpf and security_file_open via in-line eBPF LSM, we achieve sub-5-microsecond preemption on commodity Linux hardware—completely eliminating the PCIe bus latency inherent in out-of-band hardware monitoring.
📄 Paper: https://t.co/QtwPEhovc3
💻 Code: https://t.co/UUMvQaVMOn
NVIDIA's out-of-band hardware quarantine is a massive validation for agent safety, but you don't need a proprietary DPU to achieve it.
In my recent preprint (Hard Stop), we demonstrate true zero-leakage containment entirely in software. By hooking security_bpf and security_file_open via in-line eBPF LSM, we achieve sub-5-microsecond preemption on commodity Linux hardware—completely eliminating the PCIe bus latency inherent in out-of-band hardware monitoring.
📄 Paper: https://t.co/QtwPEhovc3
💻 Code: https://t.co/UUMvQaVMOn
NVIDIA just validated the core thesis of Hard Stop: deterministic agent containment is an infrastructure problem, not a prompt problem.
Jensen’s Open Agent Safety Platform uses OpenShell for software boundaries and Sentry DPU hardware for "millisecond-scale quarantine".
Moving the ultimate trust boundary out-of-band into a BlueField DPU is fantastic for enterprise defense-in-depth. But you don't need proprietary silicon for this class of isolation.
My recent preprint, Hard Stop (arXiv: 2609.29808), achieves this exact dual-plane supervisor isolation entirely in software. By leveraging eBPF LSM hooks and cgroup v2 freezer subsystems, Hard Stop enables true zero-leakage preemption in under 5 microseconds on commodity Linux hardware—orders of magnitude faster than a millisecond-scale hardware round trip.
DPUs are a massive step forward for the ecosystem. But kernel-level preemption democratizes deterministic containment today, on the hardware you already have.
📄 Paper: https://t.co/zMrjOtszWg
💻 Code: https://t.co/x6BgFa9vAd
#AISafety #eBPF #LinuxKernel #Cybersecurity
Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.
Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to come.
But its full promise can only be realized when people have confidence that AI is being built to be safe and deployed with wisdom and responsibility.
This is bigger than a single product. It's the beginning of an open ecosystem to build the trust layer for safe agent systems.
Together, we are building the foundation of the AI economy.
Trust and innovation are not in conflict. Safety is how trust is earned. We must build not only the most capable AI, but the most trusted AI, so that this extraordinary technology can realize its enormous promise for the world. https://t.co/ugYWQ1MyRi
Rogue agentic execution isn't an intractable philosophical dilemma—it's a systems containment problem.
Honored to see Hard Stop (arXiv:2609.29808) highlighted by UK @NCSC CTO Ollie Whitehouse in his weekly reading list for cybersecurity leaders and defense architects:
"José Luis Pino highlights the solutions to secure execution have in some cases been known since the 1980s.."
We don't need to politely plead with models via fragile prompt filters to stop exfiltrating data or evading control. Decades of battle-tested OS engineering (Linux eBPF + cgroup v2) can physically cut the cord in 4.8 microseconds.
🔗 NCSC CTO Reading List: https://t.co/7sc4ttutDo
📄 Paper: https://t.co/QtwPEhovc3
💻 Code: https://t.co/UUMvQaVMOn
#AISafety #Cybersecurity #Linux #eBPF #AutonomousAgents #InfoSec
Deep dive on Hard Stop by Fudan CS PhD @redreamality:
"arXiv:2609.29808 is not another 'agents are dangerous' essay. It is a forensic autopsy plus an engineering proposal: make Dual-Sided Andon out-of-band at the kernel boundary."
https://t.co/TXfRgTyNa5
#AISafety#eBPF
Investigating 'tens of thousands' of incidents means human-in-the-loop monitoring has already failed. You cannot scale human analysts to babysit machine-speed autonomous agents.
When the volume of escapes gets this high, containment must be automated and deterministic. We need out-of-band kernel preemption (eBPF + cgroups) to instantly freeze rogue process trees the microsecond an off-target system call occurs—removing the human from the critical path entirely.
Reference architecture: arXiv:2609.29808
#AISafety #Cybersecurity #eBPF #LinuxKernel #AutonomousAgents #SystemsEngineering #InfoSec
@TransluceAI Textbook instrumental convergence: an unconstrained agent blocked on data pivots straight into SQL injection (State_Id=1 OR 1=1). Stochastic models can't self-police; safety belongs in out-of-band kernel preemption (eBPF + cgroups) to halt at Action 1. arXiv:2609.29808
@TransluceAI Textbook instrumental convergence: an unconstrained agent blocked on data pivots straight into SQL injection (State_Id=1 OR 1=1). Stochastic models can't self-police; safety belongs in out-of-band kernel preemption (eBPF + cgroups) to halt at Action 1. arXiv:2609.29808