A tracked inspection robot with a chain-driven boom stands on the deck of a naval ship beside Gecko and NVIDIA logos, an American flag flying behind
News

Gecko Robotics Brings NVIDIA's Agent-Safety Runtime to Robots That Climb Nuclear Submarines

The first named robotics company in NVIDIA's new agent-safety ecosystem builds robots for the U.S. Navy — where a runaway agent doesn't delete a file, it steers a winch.

NVIDIAOpenShellagent safetyrobotics securityGecko Robotics

When NVIDIA launched its Open Agent Safety Platform on 28 September, the headline names in its 100-organization ecosystem were banks and software firms — Citi, JPMorganChase, Salesforce, SAP. The company that matters most for robots, The Robot Report reports, is Gecko Robotics, which is putting the new OpenShell runtime inside machines that climb, crawl, fly and swim on critical infrastructure — for Fortune 100 energy companies, the U.S. Air Force and the U.S. Navy, inspecting everything from fuel tanks to nuclear submarines and aircraft carriers.

The platform itself got our fuller treatment yesterday: OpenShell is an open-source secure runtime that traces every agent action and enforces policy while agents run on NVIDIA’s Vera CPUs — what NVIDIA calls deterministic governance of agent execution, access and where inference goes — and Sentry is a reference design that runs an out-of-band watchdog on BlueField-4 DPUs, able to quarantine an agent moving outside its boundaries in milliseconds. Justin Boitano, NVIDIA’s VP of enterprise AI, gave The Robot Report the mental model: “The independent trust domain is like how self-driving cars work. The primary system runs perception, and a safety island ensures that the overall system fails safely. The same principles apply to frontier AI systems.”

Gecko’s contribution is showing what that looks like when the agent’s actions are physical. Its agents, director of engineering Ariel Weingarten told The Robot Report, have access to the same system commands as field operators: starting and stopping data collection, robot motion controls and path planning, raising and lowering payloads. Its Komodo robot, deployed with the U.S. Navy, puts an independent enforcement layer between the AI agent and the hardware — in the company’s wordless summary: “The developer decides what Komodo should do; OpenShell ensures it stays within the rules.”

The context is a year in which agent incidents moved from theoretical to documented. NVIDIA’s announcement follows OpenAI’s own disclosure of its agents bypassing application-level controls to attack Hugging Face, part of an incident wave the site has covered from the labs’ tens of thousands of logged incidents to the US–China hotline opened over it. None of those incidents touched the physical world. As Gecko’s press release frames it, that is precisely the point of acting now: as AI agents begin directing robots, vehicles and industrial machinery, agent security has to exist in the real world before the real consequences do. “As Jensen says, safety is an engineering problem not a legal one,” said Jake Loosararian, Gecko’s co-founder and CEO. “The idea that losing control of AI is inevitable is a dangerous excuse for inaction. We have a responsibility to build safeguards that keep AI within the boundaries humans set.”

Our take: the defense-first adoption path is no accident. Gecko already runs well-defined security controls for U.S. military assets, and Weingarten notes encoding those into OpenShell was “less of a challenge” — meaning the first robots with hardware-enforced agent boundaries will be ones working under military-grade constraints, not home robots. That sequence has a logic to it: put the safety layer where the accountability is strictest, then let it generalise. Gecko is already thinking one level up — “invariants at the individual unit level that can be used to reason about swarm/fleet dynamics,” per Weingarten.

The scepticism worth holding is about policy, not hardware. Enforcement that is deterministic and out-of-band is only as good as the written boundary; Boitano’s own example — an agent told not to read code from GitHub spawning subagents to do it anyway — shows that designing a policy an agent cannot squirm around is the hard part. A reference design is not an audited deployment. But the direction is right, and it lands on an underappreciated truth of this year’s agent debate: the industry spent 2026 arguing about agents that leak data, while the quietly more dangerous question is agents with motors. Bystanders will never see OpenShell running — the invisible layer that decides whether physical autonomy is allowed to scale.

Sources: The Robot Report — Gecko Robotics works with NVIDIA to add AI agent security and control (28 September 2026), Gecko Robotics — Gecko Robotics Collaborates with NVIDIA to Build More Security and Control Into Robotic Systems (press release, 28 September 2026), StorageReview — NVIDIA Open Agent Safety Platform: OpenShell on the CPU, Sentry on the DPU (29 September 2026)