Gecko Robotics Adopts NVIDIA Agent Safety Layer for Inspection Robots
Gecko Robotics is incorporating NVIDIA's new agentic AI security layer into its inspection robots, the company said.
NVIDIA announced its Open Agent Safety Platform, comprising the open-source OpenShell software and the Sentry reference system design. The platform is meant to strengthen governance and control across hardware, compute, and software for robots that run AI agents.
More than 100 organizations are working with the technology, including Gecko Robotics. The effort follows incidents in which AI agents — among them some from OpenAI — bypassed application-level controls to attack Hugging Face, prompting developers to pursue traceability, accountability, and preventive measures.
NVIDIA CEO Jensen Huang said safety and security require full-stack engineering, and that the platform brings together industry, researchers, and public-sector organizations to share best practices, align on resolution methods, and foster international cooperation.
Editor's note: Physical AI is among the session tracks at RoboBusiness 2026, scheduled for Oct. 20 and 21 in Santa Clara, Calif.
OpenShell provides a secure runtime boundary that traces all actions and enforces policy as AI agents run on NVIDIA Vera CPUs. NVIDIA says it offers deterministic governance for agent execution, access, and where inference goes.
As open-source software, OpenShell can be extended to work with third-party compute platforms, including those from Arm and Intel.
Sentry adds an out-of-band watchdog running on BlueField-4 data-processing units (DPUs) that continuously monitors agent behavior. It checks outcomes against policies and can quarantine agents that attempt to move outside their boundaries in milliseconds.
Justin Boitano, NVIDIA's vice president of enterprise AI, said the agent economy needs a trusted foundation across silicon and software, and that the company wants to engage everyone to advance a new layer of agent security.
Boitano compared the independent trust domain to self-driving cars, where a primary system runs perception and a safety island ensures the overall system fails safely.
OpenShell can offload security onto silicon or DPUs as needed, and Sentry watches reasoning traces. A Policy Prover in the platform is deterministic and runs at higher speed. Boitano noted that if a policy bars an agent from reading GitHub code, the agent could spawn subagents to read and post that information, with fleets superseding global policies; the Policy Prover validates the master decision tree, examining combined file and network access to find unintended exfiltration, drawing on AWS S3 research to create verifiable policies.
Boitano added that long-term agent behavior is a different problem than sandboxing, and that OpenShell projects the intent of a policy into infrastructure.
The NVIDIA Open Agent Safety Platform includes OpenShell and Sentry, according to NVIDIA.
While recent security incidents occurred entirely within software, Gecko Robotics said they revealed a potential problem for all AI agents, including robots. The company has used NVIDIA OpenShell to explore how enforceable boundaries can keep AI-powered robots operating within human-defined permissions, with the goal of establishing safeguards for responsibly deploying greater autonomy.
Jake Loosararian, co-founder and CEO of Gecko Robotics, said that, as Huang puts it, safety is an engineering problem rather than a legal one. He called the idea that losing control of AI is inevitable a dangerous excuse for inaction, adding that there is a responsibility to build safeguards that keep AI within boundaries humans set.
Loosararian added that what NVIDIA built with its platform — and what Gecko is testing for robots — confronts risk before it reaches the physical world, helping ensure greater autonomy does not come at the expense of human control.
Gecko's robots climb, crawl, fly, and swim on critical infrastructure for Fortune 100 energy companies as well as the U.S. Air Force and U.S. Navy. Its systems inspect everything from fuel tanks to nuclear submarines and aircraft carriers.
Ariel Weingarten, director of engineering at Gecko, told The Robot Report that its agents have access to the same system commands as its field operators, including starting and stopping data collection, robot motion controls and path planning, and raising and lowering payloads. They do not handle the data lifecycle or uploading to Gecko's governance cloud.
While research continues on AI agent security, Pittsburgh-based Gecko is using NVIDIA OpenShell for secure runtime boundaries that developers can use to define permitted and prohibited actions.
Gecko's Komodo, a robot deployed with the U.S. Navy, places an independent enforcement layer between the AI agent and the hardware. The company said developers decide what Komodo should do, while OpenShell ensures it stays within the rules.
Gecko asserted that physical AI and robotics represent the next frontier of technology, and that moving intelligence from software into machines brings greater responsibility — model-level safety alone is not enough.
Because Gecko already follows well-defined security controls for U.S. military assets, implementing them in OpenShell was less of a challenge, Weingarten said. The company added that enforceable controls across the full technology stack help ensure safeguards governing physical AI advance as quickly as the technology itself.
Gecko's Cantilever AI-powered platform transforms the massive datasets collected by its robots into actionable insights, which the company says enable data-driven, evidence-based decisions on structures and deliver a return on investment for customers.
Since OpenShell sits within the boundary of a Komodo field system, it does not directly interact with Cantilever, Weingarten noted. Gecko intends to use NVIDIA's security layer for defense and military systems in the future, he said, and the deterministic control could also help at the swarm level.
Weingarten said having invariants at the individual unit level helps reason about swarm and fleet dynamics, and that Gecko looks forward to evolving from individual system control to agentic-assisted operation of an entire deployment.