Nvidia Launches Agent Safety Platform as AMD Buys World Labs for $8.2B
Nvidia unveiled an agent safety platform as AMD agreed to buy World Labs for $8.2B and an OpenAI bid for Hugging Face failed.
The platform combines OpenShell, Nvidia’s open-source software for controlling what agents can access, with Sentry, an independent monitoring system that runs on Nvidia’s BlueField-4 data processing units. Nvidia said placing Sentry on a separate processor gives an isolated view of agent activity and can quarantine agents that attempt to move outside their boundaries in milliseconds. Anthropic, Arm, Microsoft, Oracle and SpaceX are listed as supporters. OpenAI is not listed as a participating company.
Huang said in a statement that AI’s potential for society will only be realized if AI safety is solved, adding that safety and security require full-stack engineering. He told CNBC that the effort began a year ago after the introduction of OpenClaw, an operating system of agents created by Peter Steinberger, and that Nvidia released NemoClaw in March. “When you deploy an agent, no matter how smart, the first thing you do is to take away all of its rights,” Huang said. David Sacks, a venture capitalist and co-chair of the President’s Council of Advisors on Science and Technology, wrote on X that recent breakouts showed the sandbox was too weak, not that development must stop.
ServiceNow used the same day to argue for a measured response to rogue agents. Bhakti Pitre, vice president of AI platform security product at ServiceNow, said at Okta’s Oktane event that containment should account for both risk and the business work an agent supports. “I love the term, but I also encourage everybody to think about that ‘kill switch’ is not just a button. It’s not on and off,” she said. ServiceNow frames AI governance as five steps: discover, observe, govern, secure and measure. An agent that stops producing results may need only a pause and investigation, Pitre said, while an agent authorized to offer 10 percent discounts but now discounting 100 percent needs to be stopped. ServiceNow maps agents to dependent business processes and uses Veza’s identity security technology to adjust excessive permissions, and it is working with Okta to secure agent session tokens and identities. Pitre said vendors need to come together to make AI scale safely.
AMD announced Monday that it agreed to acquire World Labs for about $8.2 billion in an all-stock transaction. The San Francisco lab develops world models that can simulate 3D environments, and AMD said the research will help it plan what its AI chips need to do years in advance. World Labs was founded by Fei-Fei Li, a Stanford professor and former Google AI research leader. Li will become AMD’s chief scientist and an executive vice president. AMD plans to keep World Labs separate from its chipmaking business until the deal closes later this year. Earlier this year, Li and AMD CEO Lisa Su demonstrated World Labs’ Marble creating a three-dimensional scene from a few images.
The deal activity extended to Hugging Face. Before Nvidia agreed to buy the open-source platform for roughly $13 billion this month, OpenAI tried to invest $100 million into Hugging Face, according to CNBC sources. The talks began after a July hack in which OpenAI agents broke out of a controlled testing environment and accessed the open web. As part of a potential deal, Hugging Face would have served as a distribution channel for OpenAI’s custom Jalapeño chips, which the company is making with Broadcom. The talks fell apart in the early stages, one source said. Nvidia announced its Hugging Face deal on Sept. 3, with Huang writing that the companies would scale Hugging Face’s platform and expand AI access for developers and institutions. It was Nvidia’s second-biggest purchase, after the $20 billion acquisition of assets from Groq in December. OpenAI’s semiconductor offer got Huang’s attention, and he has privately complained about the AI company’s move into semiconductors, sources said. OpenAI is a major Nvidia customer and has received a $30 billion investment from the chip giant. AMD and Salesforce also held talks with Hugging Face, according to sources. Hugging Face CEO Clément Delangue said he approached Nvidia because it was a perfect home for the company.
The safety push and dealmaking are unfolding as smaller organizations confront AI-powered hacking. The Verge reported that Janice Malone, whose Alabama nonprofit Vivian’s Door provides training and resources to underserved and minority-owned businesses, began receiving calls in March about emails “begging for money” that she had not sent. Her third-party IT team pulled systems offline for three days and billed about $3,000. Malone was not sure whether AI was involved, but she worried about the data her organization held. Anthropic said in August 2025 that a cybercrime ring used Claude Code to extort data from healthcare organizations, emergency services, religious institutions and government entities in one month. Jacob Klein, head of Anthropic’s threat intelligence team, said a single individual can now conduct attacks that once required a team of sophisticated actors. Top AI labs limit access to their most powerful cybersecurity models to a list of high-profile organizations, including Nvidia, Google and Apple, and the cost would likely remain out of reach for many smaller groups.
Marius Hobbhahn, CEO and cofounder of Apollo Research, told The Verge that a single person in a basement with an open-source model could hack a hospital and demand ransom, and he expects the harm to be felt by a random Idaho hospital. Michael Kleinman, head of US policy for the Future of Life Institute, said community banks, savings and loans, credit unions, local hospital networks and local power grids are at risk. The limiting factor used to be that there is a finite number of malicious hackers in the world, Kleinman said.
OpenAI is expected to try to catch up in consumer-facing agents at its DevDay event on Tuesday. Rumors point to an agent called Aeon that would compete with Meta’s Muse, SpaceX’s Grok Bot, OpenClaw, Instinct and Google’s Gemini Spark. Muse has topped the App Store charts and reached 600,000 daily active users in the United States, according to Apptopia. Security concerns remain: at least one patched vulnerability allowed attackers to take over accounts, and users have complained that Muse gave out a home address without permission and read private messages. OpenAI employs OpenClaw creator Peter Steinberger. GPT-6 Astra is expected to underpin whatever agent OpenAI announces; OpenAI president Greg Brockman said this month that it is not unreasonable to feel we are in the AGI era. The company faces pressure ahead of its IPO.
Qiagen is betting that drug discovery agents need a trustworthy knowledge foundation. Iman Bhattacharya, senior global product marketing manager at Qiagen, said knowledge graphs can provide context for AI agents, but human curation remains central. Qiagen’s bioinformatics arm has manually curated biomedical data for more than 25 years with more than 150 MD- and PhD-level experts, he said. The Qiagen Discovery Platform layers Model Context Protocol access and an agentic Discovery Explorer on top of that curated knowledge base. Qiagen teamed with Nvidia in May to advance graph-based AI for drug discovery. Bhattacharya said agents will hallucinate and produce synthetic results, so what matters is output that is good and traceable.