And some big news this morning. Nvidia is launching the NVIDIA open agent safety platform. That's a new security software suite that's designed to keep AI agents operating inside their step boundaries, inside their sandboxes, and quarantine any agent that may attempt to go rogue within milliseconds. It also is going to keep track of every step along the way, record what's been happening. Nvidia is also announcing this morning with more than 100 key partners and stakeholders including Cisco, Crowdstrike, Dell, JP Morgan Chase, SAP, Anthropic, goes on and on the list from there. Joining us right now to talk about it is Jensen Huang. He's right here on set with us of course the CEO of Nvidia. And Jensen, welcome. It is great to see you this morning.
Great to see you. Great to see you.
This is an advancement in something that we've kind of seen the national discussion take place around AI and AI safety. And in this discussion, there have been those who have been painted as doomers who think that the end of the world is going to come from this. And then there have been those who have painted you as the guy who doesn't want to see anything happen on any level. I don't think that's a fair and accurate depiction of where you stand with things. Why don't you tell us where you stand?
I want to see a lot of things happen on a lot of levels. So why don't we talk about where we stand and then we're going to jump into what this is.
Well, first of all, as you know, we're going through a major platform shift. AI is incredible technology, has the potential to do incredible good. But we also have to make sure that the technology is developed and deployed safely so that the public has confidence in applying this technology. The single most important thing we could possibly do is to build it in such a way that is so safe that everybody could use it in every single industry so we could transform every industry. And so that's the hard work that we have to do. These agentic systems are obviously agentic, meaning they operate by themselves. It's kind of, you know, it's like a self-driving car. And so in order for you to deliver that agentic system in a safe way, you have to make sure that the sandbox around it, the force field, the playpen, you know, if you will, all of those systems are designed in a way that keeps the agent with minimal rights, whatever rights it has, it needs in order to do its job. No more rights than that. And that it can't do anything that it's not supposed to. But and also you have to monitor it.
But the problems that we've seen to this point where OpenAI, Anthropic, Google and others have had agents that have escaped and have gotten out and done mischievous things, maybe illegal things. The problems we've seen to this point, you think is simply an engineering problem and a fault of those companies, maybe not putting in the right restrictions.
Well, I think the answer is we hope it's an engineering problem. I believe it's an engineering problem. I know it's an engineering problem. And we all need to hope that it's an engineering problem. If it's not an engineering problem, it's not solvable. Right? And so the fact that all of these companies still are advancing the state-of-the-art is because they also believe it's solvable. These are some of the brightest engineers in the world. I work with, you know, all of them. And this is a technically solvable problem. And so the way to think about that is if you look at, go back to the days of the internet, you access a website, it downloads an application, maybe it's a Java application, all of a sudden this application comes into your PC, has access to files and resources and maybe the applications and tools and it gets onto your network. Well, in the beginning we had all kinds of viruses. But we realized that the web browser itself has to be a containment system. The web browser has to provide that application with minimal rights. Whatever, only the rights it needs in order to do its job. And it has access, basically access to nothing unless the browser gives it access. Essentially what we're doing here, we're creating basically the modern browser. It's a browser for agents.
So somewhere inside the culture of AI researchers for years now has been this anxiety that somehow these models have to be clever and they have to be able to get outside of their walls because they're so clever, right? I mean, where do you think that, I mean, that's like built into the AI researcher culture. And so at one level I think while there are some people who believe it's an engineering problem, there are these others even inside these companies that believe it's unsolvable.
I don't think so. I don't think that's exactly wrong. First of all, you want it to be super clever so it could perform tasks and do things. But the way you think about that is when you deploy an agent, no matter how smart, the first thing you do is you take away all of its rights. Job number one is take away all of its rights. And then you provision, you give it access to files, data, tools, access to the network or even internet access only if it needs it. You don't just, you don't put an agent into your company and give it access to everything. We don't give that to people. We don't give that to any level of executive. In fact, everybody has a badge. Everybody has file access. Everybody has access to tools and only the things that they need in order to do their job. And so we have to apply the same philosophy. Now the question is how do we develop the technology to provision that policy, provision that philosophy, and that's what we created. That's what Open Shell is. It's really important technology. It has the support of some 100 companies. You didn't mention IBM and Red Hat and Microsoft and SpaceX.
And so all of these companies, they recognize the importance of basically this force field that you create around the agent and very importantly it's provisioning rights and responsibilities and access. It's an open-source program, which is very, very important. And the reason for that is this: we want this sandbox to be visible to the whole world so that if there are any vulnerabilities, somebody will find it. You got all these, look at this, 100 companies. There's actually a lot more companies which is, those are only we can list. 100, the industry will all be jumping in looking at any possible vulnerabilities and patch it up.
You have Anthropic and SpaceX both listed on this list of 100 companies. OpenAI is not there. Are they not cooperating with this? They didn't think it was important?
No, this is an open standard. It's an open platform. And however they would like to participate is going to be super welcome. They could look at the code, they could use whatever part of it they would like. They could build their own inspired by this or they could use it. I think over time we really want people to use the software and the reason for that is because the more people use it the more vibrant it's going to be, the more resilient and more robust it's going to be.
You've said that Open Shell would have prevented the Hugging Face breakout from OpenAI from Hugging.
Yeah, Clem and Hugging Face are one of the victims of the attacks and a huge supporter of Open Shell. Their computer scientists are very deep on Open Shell and they're a big part of it.
What happened that you all can do this and OpenAI, Anthropic and others haven't been able to do this to this point?
Well, we started building this, you know, about a year ago. Has it been a year? Maybe slightly longer.
Yeah. And when Open Claw came out, you guys might have heard me say this is the operating system of AI, meaning that it's the operating system of agents. And when we looked at Open Claw, we said, 'Hey, this is incredible, but you can't deploy this into companies. You can't have agents roam around and drift around the company.' And so, you have to find a way to container it. Containment is number one. Rights provisioning is number two. Being able to monitor its adherence and conformance to all those policies, number three. And so we created containment, a policy provisioning supervisor, and we created a monitoring system and the monitoring system is called Sentry and it monitors it in silicon.
Not to get too technical about this, but the concept of containment and monitoring is very simple. For those who know about, for example, AWS Bedrock has Nitro and a whole lot of other things built into it. This seems to me a much broader open-source version frankly of that. Is that a terrible way to think about it?
Yeah, you need it. It's like Nitro in the sense that it's a rights provisioning system. It's like Nitro in the sense that it's also hardware isolation, right? Which is really, which Nitro as you know really revolutionized multi-tenant secure cloud. In a lot of ways this is multi-agent secured, you know, world. And so very similar idea, the differences are going to be around the speed at which we have to run Bluefield 4 and the reason for that is you're monitoring AIs, you're monitoring a lot of agents that are adhering to the policies, are they using files or going onto networks they're not supposed to. We might even look at its chain of thought and how it's thinking and maybe it's thinking about doing something that we really prefer it not to and might elevate and escalate to somebody, another AI or maybe a person and say, 'Hey, look, this agent is doing something that we might not condone.'
Some of the model makers who are making new models are trying to use their older models to effectively track the new model that's being trained with this product. Will they still want to continue to do that?
Sure. The chip is between the agent, the agent itself is actually a harness. It's just a piece of software. Okay. And this chip sits in between that and the large language model. So the model is here. The chip is in the middle. And here's the agent. And so whatever the agent's trying to do and whatever it's causing the large language model to think about, Bluefield or Sentry sits right in the middle. So we intercept everything which is one of the really incredible places that we sit in the world because we, you know, we have computers for agents and we have computers for large language models.
Nvidia now has a new chip that sits right in the middle. The idea to this point, you've said in the last several weeks that look, liability that currently exists today in existing regulation should be enough to keep these companies from doing some of these things. They shouldn't release products that are going to get into trouble or that are going to hurt people or shut down systems. And that...
I like the way you just said that. I think you just kind of stated the obvious. I think number one, I'm not suggesting that products are vulnerable sometimes and companies release products that aren't as well tested as they should be. That happens every single day. However, if you knowingly do it, if you already know that you didn't test it properly, if you know that you could have done a better job testing, you got to just hold it back.
You're in the middle of all of this. You are in the process of buying Hugging Face for over 12 billion. That was a company that was broken into by OpenAI. I think you've got a $30 billion investment in OpenAI. How do you come down on who's responsible and, you know, are you going to go after OpenAI for what it's done to Hugging Face or other places? Will there be lawsuits that come out from any of this? How do you kind of decide as somebody who's involved in all of this what you want to see happen?
Well, I don't have to decide on any of those matters. The thing that I have to decide on in the case of OpenAI, is OpenAI a great investment? And the answer is absolutely. This is one of the most consequential companies in history. Sam and Greg and Sarah, they do a terrific job running the company. Incredible researchers. We have, it's a real privilege to work with them. Love the work that we do with them. Hugging Face, I mean this is the world's leading platform for open models. I believe very deeply in advancing open intelligence. I think we ought to democratize intelligence. I think every company will become an AI company and this platform really keeps that community thriving and so it's really important that we invest in both.
Does this platform absorb the liability issues for any company that's using it? I mean if you're using it and your agents break out, you say, 'Wait a second, I'm using Open Shell. It's Nvidia's problem.'