‹ BackHN Continuity

Thread

Nvidia wants to put a watchdog chip next to every AI agent

230 points · 299 comments · jonbaer

  1. nrouter_ai · · focus · HN ↗
    The hardware watchdog framing misses how operators actually do this. Nobody audits agents with a chip; they put the enforcement in the request path.

    In practice it's four things, all software: (1) deny-by-default tool allowlists — the agent declares capabilities per run and anything else is a hard reject; (2) per-request and per-run cost budgets with automatic kill when token burn goes sideways; (3) an immutable audit log of every tool call with inputs, so incidents are reconstructible after the fact; (4) policy checks on outputs, not just inputs — injection payloads ride in tool results far more often than in prompts.

    The reason this lives in software is that the policy changes per workload. A coding agent and a support agent have totally different risk profiles; a chip can't know that. And accountability still lands on whoever signed off on the capability set.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.