Artificial Intelligence 09-28-2026

DigiCert Brings AI Passports to the NVIDIA Open Agent Safety Platform

Brian Trzupek

I've spent most of my career working on one question in different companies: how do you trust something you can't see? For a long time that something was a server. Then a device, then a piece of code. Last year it became an agent: software that takes a goal, makes a plan, and keeps going without asking anyone for permission. Who can kill that agent? And how do we know which one to kill?

Autonomous agents arrived as a class in 2026, and they arrived fast. Agents operating outside their intended boundaries went from a conference hypothetical to real incident reports. And nearly every conversation I have with security leaders lands in the same place. Prompt- and model-level safeguards shape what an agent tries to do. They aren't a boundary. We would never secure a data center by asking the servers nicely, and we shouldn't secure agents that way either.

A real boundary, in software and in silicon

That's why I'm glad to see NVIDIA announce the NVIDIA Open Agent Safety Platform today. It puts the agent's boundary where it belongs: in the infrastructure. 

At its center is NVIDIA OpenShell, an open, secure runtime for autonomous agents. The agent keeps its own reasoning and skills. But every file, network, process, credential and inference call it makes crosses a boundary the platform controls. Nothing is permitted by default. Enforcement happens outside the agent's process, so even a compromised agent can't talk its way past it. And every allow and every deny decision is recorded.

Underneath that, NVIDIA Sentry on BlueField-4 powered by NVIDIA DOCA adds hardware-isolated enforcement that doesn't depend on the host: out-of-band, in-silicon monitoring of agent activity and security-policy enforcement. NVIDIA Vera supplies the compute for the CPU-heavy work agents do.

Put simply, the platform keeps the agent from breaking out. That matters, and it's the part most of the market has been missing. And DigiCert provides the agent's verifiable identity across organizational boundaries, and a kill switch.

A checkpoint and a passport

Here's how I explain how DigiCert AI Passport and NVIDIA Open Agent Safety work together. 

Consider an airport. The security checkpoint decides what gets through: no liquids, no blades, nothing on their list. But the checkpoint doesn't tell you who you are. Your passport does, and it works because a trusted authority issued it and the other country already knows how to verify it.

Agents need both. A boundary answers: what can this agent do? Trust answers three different questions. Which agent is this? What is it actually running? And can I prove it to someone who doesn't work here: an auditor, a regulator, a partner whose agent mine is about to talk to?

OpenShell provides the checkpoint. DigiCert AI Trust Manager issues the Agent Passport. An AI Passport gives every agent, model and MCP server a cryptographic identity rooted in PKI, the same trust fabric the internet already runs on. 

There's a second half to this, too. Containment keeps the agent from breaking out. Confidential computing keeps everyone else from breaking in. A trusted execution environment keeps the workload encrypted while it runs, so the host, the hypervisor and the operator can't read or change it, and attestation proves that to a third party. Run a contained agent inside a confidential environment and you get an agent that can't get out on infrastructure that can't get in. We've been doing this attestation work with Google Cloud and partners across the industry. NVIDIA is a large voice in that forum, and they support it with NVIDIA Vera Rubin.

The DigiCert AI Agent Passport leverages internet scale cryptographic standards and protocols to allow the AI Passport to provide Identity for the OpenShell agent, and therefore we can also provide a real, policy based, automated, and enforceable kill switch, to stop any agent for any reason a customer sees fit.

What we're adding to DigiCert AI Trust Manager

DigiCert AI Trust Manager supports NVIDIA Open Agent Safety Platform now, starting with OpenShell.  The work centers on four things: 

  • Identity that policy can act on. Every agent running in an OpenShell sandbox gets an AI Passport. OpenShell policy can then key on a verified identity instead of a name in a config file.

  • Trusted before it runs. Agents, models and MCP servers are signed, scanned, and carry an AI Bill of Materials (AIBOM). They're verified before a sandbox ever launches them.

  • Evidence that survives an audit. OpenShell already records every allow and deny. We'll sign that record and anchor it to the DigiCert AI Root of Trust. Where the workload runs on confidential compute, we'll attach the attestation too, so the proof holds up in front of someone who has no reason to take your word for it.

  • Trust that crosses company lines. Agents increasingly work with other companies' agents. Public Key Infrastructure already gives the internet a trusted way to verify identity across boundaries. Now that same foundation can help agents prove who they are.  Publicly trusted PKI is how the internet already solves this problem for websites, and it's how we'll solve it for agents. 

None of this replaces what OpenShell does. It gives what OpenShell enforces an identity and a paper trail. 

Where this goes next

OpenShell is open source, and that matters to me. Identity and attestation are exactly the kind of work that gets better when everyone running the same runtime can review it. 

If you're putting agents into production, whether that's coding agents across your engineering teams or regulated workloads that can't leave your data center, I'd like to hear what you need. The customers using the DigiCert AI Trust Manager are shaping this work now, and there's room for more.  

Request an AI Trust Manager demo

The agents are going to keep getting more capable; that part isn't up to us. What is up to us is whether, every time one of them acts, somebody can prove who it was and what it did.

Resources  

Subscribe to the blog