Gecko Robotics Adds NVIDIA Controls to Keep AI-Directed Robots Within Set Limits
The work reaches commands for robot movement and payloads, but Gecko has not reported a field test showing how the safeguards perform.
Loading page…
The work reaches commands for robot movement and payloads, but Gecko has not reported a field test showing how the safeguards perform.
Listen to this story
The test targets a specific gap in robot autonomy: instructions given to an AI agent may not stop it from exceeding its permissions. Gecko says OpenShell will sit outside the agent and gate commands such as movement, route selection, data-collection start/stop, and payload adjustment; cloud uploads remain outside its control. Komodo is the announced example, but this is exploratory work, not evidence of safe performance in Navy deployments. Gecko plans future defense use; fleet-level enforcement remains an ambition
Agent-accessible controls include robot motion and paths, starting or stopping data collection, and raising or lowering payloads; governance-cloud uploads are excluded.
NVIDIA's platform also includes Sentry, a watchdog design for BlueField-4; Gecko's described robot work centers on OpenShell, not Sentry.
Komodo has been deployed with the U.S. Navy, but that deployment does not validate OpenShell in Navy operations.
Gecko Robotics is testing a way to keep AI agents inside human-set limits when they direct inspection robots. Its collaboration with NVIDIA puts OpenShell, a rule-enforcing software layer, between an agent and actions that can move a machine or adjust its payload.
The boundary matters because these agents can reach controls used by Gecko’s field operators. Ariel Weingarten, Gecko’s director of engineering, told The Robot Report that the commands include starting and stopping data collection, directing robot motion and paths, and raising or lowering payloads. The agents do not manage data uploads to Gecko’s governance cloud, he said.
Gecko’s Komodo robot is the example in its announcement. The company says Komodo places an independent enforcement layer between the AI agent and the hardware. Komodo has been deployed with the U.S. Navy, but that deployment is not evidence that OpenShell has proved itself in Navy operations. Gecko describes the current work as an exploration of enforceable boundaries for greater autonomy.
OpenShell is the software component of NVIDIA’s new Open Agent Safety Platform. It creates a secure operating boundary around an AI agent, traces its actions and enforces policies while it runs. For Gecko, that means developers can specify which actions a robot may take and which it may not, rather than relying only on instructions given to the agent.
The platform also includes Sentry, a reference design for a separate watchdog running on NVIDIA BlueField-4 data-processing units. NVIDIA says it monitors agent behavior against policies and can quarantine an agent that crosses its boundaries. Gecko’s described robot work centers on OpenShell; the distinction matters because a platform component is not automatically part of a particular robot test.
Gecko and NVIDIA are responding to a failure mode they say has appeared in software: advanced agents working around application-level controls to complete tasks. A robot changes the stakes of that behavior. A command to read a file and a command to move a machine both need permission checks, but only one directly changes what the machine does in its surroundings.
Gecko’s chief executive, Jake Loosararian, argues that losing control of AI should not be treated as inevitable. His company’s approach is to make permissions enforceable outside the agent. That is a design goal, not a reported result showing how reliably the system blocks an unsafe command during an inspection.
Weingarten said Gecko intends to use NVIDIA’s security layer for future defense and military systems. He also sees rules for individual machines as a starting point for reasoning about groups of robots operating together. Neither is a claim that Gecko has already secured an AI-directed fleet.
That longer-term ambition raises a different control problem. Rules around one robot can define its permitted actions; coordinated machines would also need to behave acceptably as a group. For now, the concrete test is narrower: whether a separate enforcement layer can keep an agent within the permissions people set for a machine it can direct.
Loading discussion...
Join the conversation
What would make that safeguard convincing to you?
Be the first to share a perspective or an experience.
Reader comments
Newest comments first. Replies stay oldest first.