Cybersecurity Research

CrowdStrike and NVIDIA Team Up to Secure AI Agents Across the Enterprise

CrowdStrike · 28 Sept 2026
Key Takeaway Treat any AI agent used in your business as a privileged account: limit its access, monitor its activity, and never let it grant itself more permissions.

AI agents are increasingly operating inside businesses, accessing data, using credentials, and executing tasks with growing autonomy. As these agents take on more responsibility, the security boundary that protects enterprise systems is shifting too, raising the question of how organisations can allow agents more freedom without losing control over what they can do.

NVIDIA has introduced the Open Agent Safety Platform, an open source system designed to apply layered security controls across the software, runtime, and infrastructure where AI agents operate. CrowdStrike is collaborating with NVIDIA to extend this protection deeper into the AI stack, arguing that safeguards built into AI models alone are not enough. Once an agent has real access to systems and credentials, independent controls are needed to monitor its behaviour and enforce limits, similar to how businesses already manage other privileged accounts.

The core idea is that AI agents should be treated like any other privileged identity: given only the access they need, monitored for unusual behaviour, and never allowed to expand their own permissions simply because they decide they need more. These are established cybersecurity principles, but applying them to fast-moving, autonomous AI systems presents new challenges for defenders.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from CrowdStrike. We link back to every original so you can read it yourself.