Published on

Figure Joins NVIDIA’s Open Agent Safety Platform as Humanoid Deployment Approaches

Get your news fromHumanoids Daily

One tap, and our reporting appears more often in your Google Top Stories. It makes a real difference to a small newsroom.

P.A.
Written byP.A.

Supported by RoboStrategy

Sponsored

Investing involves risk, including possible loss of principal. Read the prospectus before investing.

Figure has joined NVIDIA’s Open Agent Safety Platform initiative, bringing a humanoid robotics developer into an effort to put enforceable boundaries around increasingly capable AI agents.

NVIDIA CEO Jensen Huang announced the platform on September 28, saying more than 100 industry partners were involved. Figure CEO Brett Adcock linked the collaboration directly to robots operating around people: “Humanoid robots will soon be in the home and workplace. They have to be safe and trusted.”

  • NVIDIA’s initiative combines the OpenShell agent runtime with Sentry, an optional hardware-isolated monitoring and enforcement layer.
  • Brett Adcock confirmed Figure’s participation and connected it to safety in homes and workplaces.
  • Figure appears to be the only dedicated humanoid manufacturer in the published partner graphic; Gecko Robotics and Skild AI are also represented.
  • Gecko’s CEO described inspection-path planning and data collection within human-set boundaries; Figure has not disclosed its integration details.
Grid of logos representing NVIDIA Open Agent Safety Platform supporters, including Figure, Gecko Robotics and Skild AI.
NVIDIA’s published supporter graphic for the Open Agent Safety Platform includes Figure, Gecko Robotics and Skild AI. Image: NVIDIA.

Figure brings a humanoid perspective

Adcock’s public endorsement confirms more than the appearance of a logo. It establishes that Figure considers the initiative relevant to its own work, although his post does not explain what the company will contribute or which systems will use it.

In NVIDIA’s published ecosystem graphic, Figure appears to be the only dedicated humanoid manufacturer shown. That observation applies to the graphic, rather than establishing an exclusive relationship or a complete list of future participants. Gecko Robotics and Skild AI also appear, extending the robotics representation beyond humanoid hardware.

The weekly humanoid robotics briefing

One email a week: the launches, funding and research that mattered, with context from Humanoids Daily.

Read recent issues

Huang framed the effort as the beginning of a shared foundation for trustworthy agent systems. His argument was that confidence in how AI is deployed will help unlock its economic potential.

What OpenShell and Sentry do

An AI agent can use tools, read files or call external services to carry out a task. The practical security question is how to constrain those actions even when the model makes a poor decision.

The OpenShell repository describes an open-source runtime that applies controls outside the agent itself. Each agent runs in an isolated sandbox, with restrictions on file access, system calls and network connections. Credentials can be added to approved outgoing requests without exposing the underlying secrets to the agent.

OpenShell also checks proposed policy changes before they are applied, flagging newly permitted access for review. This is verification of the access policy; it should not be read as a proof that every decision the model makes will be safe.

NVIDIA’s platform overview distinguishes those runtime controls from model safeguards: a prompt or trained behavior influences what the model attempts, while the runtime restricts what it can actually do.

Sentry adds an optional layer on separate BlueField hardware, intended to keep monitoring and enforcement beyond the reach of the agent and its host software. NVIDIA says it can quarantine agents in milliseconds. OpenShell itself does not require BlueField-4 and can run on supported local, cloud and on-premises infrastructure.

The technical announcement describes a reference architecture using Vera CPUs and BlueField-4 data processing units. One control point is the connection to the model: observing or interrupting that connection provides a way to monitor an agent’s activity and restrict its continuation.

Gecko outlines an industrial use case

Gecko Robotics CEO Jake Loosararian gave a more concrete account of the robotics connection in a September 28 CNBC interview. He described using AI agents for inspection-path planning and diagnostics, including deciding where robots should gather additional information from the surfaces they examine.

As an example, he pointed to Gecko’s military work supporting efforts to get ships out of dry docks faster. In his account, agents could help determine inspection routes and data-collection priorities while remaining within parameters established by people.

Loosararian said the arrangement should also allow operators to rein in planned paths and actions. That gives the phrase “humans in control” a practical meaning: people define operating boundaries and retain the ability to intervene as agents plan work.

His comments frame the partnership around industrial inspection and maintenance. They do not establish autonomous weapons use, nor do they describe a humanoid deployment. The interview also does not specify how interventions are implemented, which safeguards have already been deployed, or measured safety outcomes.

For the wider initiative, Gecko supplies an application-level example of what enforceable agent limits could govern. Figure has so far offered a broader endorsement tied to homes and workplaces, without comparable implementation detail.

What this means for a robot

For humanoids, the architectural principle is relevant: the system responsible for choosing an action should not be the only system responsible for policing it. But applying that principle to machinery requires more than placing a software agent in a sandbox.

For example, restricting access to a robot-control interface could prevent an unauthorized command. It would not, by itself, establish that an authorized grasp uses an appropriate force, or that interrupting a model leaves a walking robot in a stable state. Those are additional physical-control questions that an implementation would have to address.

Our recent coverage of RoboHarm’s unsafe-command tests explored a related distinction: a model’s ability to execute a task and its willingness to refuse an unsafe instruction are separate properties. That study did not evaluate NVIDIA’s new platform, so it provides context rather than evidence of the platform’s effectiveness.

The immediate news is Figure’s participation in a broader effort to enforce limits around AI agents. The next meaningful detail will be how that work connects to Figure’s actual systems—and which risks it can measurably reduce when software decisions become physical actions.

Share this article

The weekly humanoid robotics briefing

One email a week: the launches, funding and research that mattered, with context from Humanoids Daily.

Read recent issues