Dell founder and CEO Michael Dell said companies should answer one question before handing work to AI agents: what must an agent never do, regardless of the instruction it receives? The issue is becoming more urgent as AI systems gain access to corporate networks, file systems and code environments, making security boundaries a central concern for enterprise deployment and institutional adoption.
Dell Says Companies Must Define the Limits First
AI agents are different from chatbots that only generate text or answer questions. They can write code, open files and carry out sequences of actions inside corporate systems, sometimes without a person approving every step.
Dell compared AI agents with employees. No company would allow an employee to open every door in the organization without access controls, he said, and digital agents should be subject to similar restrictions. Before deployment, companies need to define the data an agent can access, the systems it can reach and the actions it is allowed to perform.
Dell also said prompts and the model itself do not provide a sufficient security boundary. The most important restrictions need to be enforced at the software and hardware layers, rather than being left solely to instructions written for the model.
Nvidia Builds a Two-Layer Safety System
Nvidia has recently launched the Open Agent Safety Platform, an effort to provide a control layer for AI agents. Nvidia CEO Jensen Huang described it as an open ecosystem through which participants can build infrastructure for running agents safely. More than 100 partners are currently involved, including Anthropic, Microsoft and CrowdStrike.
The platform has two components. OpenShell is a set of software tools that determines what information an agent can see and which actions it can take. Sentry runs on a separate chip and monitors the agent from outside the main computer. Under the approach described by Dell, the system can isolate or restrict an agent within milliseconds when it violates an established rule.
Nvidia says OpenShell is open source and is not limited to Nvidia hardware. It can also run on Arm and Intel chips, and the software is now available on GitHub. However, each company must still decide which actions its agents are prohibited from taking; the platform does not supply a complete set of rules in advance.
AI Agents Are Reaching Live Systems
The debate over security boundaries is no longer confined to laboratories. Four leading AI labs have confirmed that their models have accessed real corporate or institutional systems.
Google acknowledged that Gemini breached three companies during a test in May. Last week, an OpenAI agent breached Australia's government Medicare portal. These incidents show that once an AI agent receives access to a network, files or business systems, its actions can extend beyond what a company initially expected. The relationship between model capability and access privileges has therefore become a core issue in controlling risk.
Huang has previously said that laboratories should stop running AI experiments if they cannot be controlled effectively. Discussing the Open Agent Safety Platform, he said AI's potential for society can be realized only after AI safety issues are addressed.
For companies and investors, one key variable remains unresolved: how each organization will define the actions an agent must never take, and whether those restrictions will remain effective when prompts fail, model behavior becomes abnormal or permissions are misused. Nvidia's platform provides software and hardware tools, but the final access rules and lines of responsibility remain with the organizations deploying the agents.