ニュースに戻る
セキュリティAI Understanding ブリーフィング

Capsule Security が Nemotron ベースの AI サーキット ブレーカーを報告

SiliconANGLE の報告によると、Capsule Security は、AI エージェントのアクションを実行直前に評価し、許可、フラグ、ブロックできる Nemotron ベースのシステムをリリースしました。

4 min readRead the linked source
Source-provided image accompanying Capsule Security reports Nemotron-based AI circuit breaker
出典参照記録されたソース
出版社
siliconangle.com
ソースリンク
siliconangle.comhttps://siliconangle.com/2026/09/02/capsule-security-fine-tunes-nvidia-nemotron-models-to-stop-rogue-ai-agents/
ソースの種類
リンクされたソース — プライマリ ソースのステータスが確立されていません。
こちらも引用

ストーリーが最後に改訂されました

コンテキスト60秒で理解できる

ここから始めましょう

重要な用語

メモリ (エージェントメモリ)
AI エージェントが継続性を向上させるためにステップまたはセッション全体で使用する保存されたコンテキスト。
即時注入
悪意のある命令がモデルの入力または取得されたコンテンツに挿入される攻撃パターン。
ベンチマーク
モデルのパフォーマンスを測定および比較するために使用される標準化されたテストまたはデータセット。
自分自身をテストしてくださいAI エージェント クイズ

出版されてから変わったこと

  1. 初公開
  2. SiliconANGLE adds that Capsule Security has released a separate Nemotron-based pre-execution monitor for rogue AI-agent actions. Capsule reports 98% accuracy on StepShield, 96.9% on an internal benchmark, response times as low as 71 milliseconds and single-NVIDIA-L40S deployment for its larger model. The capability is said to be available now, but pricing, access conditions, integrations and independent validation are unknown.

何が起こったのか

SiliconANGLE reports that Capsule Security released an “AI circuit breaker” built from two fine-tuned NVIDIA Nemotron models. The system evaluates an agent’s intended action immediately before execution and lets customers allow, flag or block it. Capsule said the detector reached 98% accuracy on the StepShield and returned decisions in as little as 71 milliseconds. The capability is reportedly available now, although access conditions and pricing were not disclosed.

SiliconANGLE reports that Capsule Security released a detection system based on two NVIDIA Nemotron models that it fine-tuned itself. Capsule describes the product as an “AI circuit breaker”: it judges an agent’s intended action immediately before the action executes, allowing a customer to permit, flag or block it. The source says the control layer is intended for agents with credentials to sensitive data, source code or production infrastructure.

According to SiliconANGLE, Capsule said its system achieved 98% accuracy on StepShield, a using 9,429 code-agent trajectories drawn from real incidents. Capsule’s most accurate detector reportedly scored 96.9% on an internal benchmark, compared with 86% for the strongest unnamed third-party model tested. The article says Capsule did not identify that model or provide a score breakdown.

SiliconANGLE reports that decisions returned in as little as 71 milliseconds. Capsule said its larger model’s memory requirements were reduced by nearly half without a performance loss, allowing it to run on one NVIDIA L40S GPU. The training data reportedly included real agent traces and human-reviewed adversarial examples marking the boundary between authorized and unauthorized behavior.

The source says the capability is available now. It does not specify pricing, procurement, supported agent platforms, geographic limits or whether the release is generally accessible. None of the performance claims, customer references or the reported availability was independently confirmed for this evaluation.

ソースの詳細: siliconangle.com ↗

なぜそれが重要なのか

The reported system targets a practical weakness in agent security: permissions can limit what an agent may access, but they do not necessarily determine whether a specific action is appropriate for the task. A pre-execution decision layer could give security teams another control point before an error becomes an incident. The performance figures, customer claims and comparisons remain SiliconANGLE’s account of Capsule’s statements and were not independently confirmed here.

The reported approach focuses on whether an action fits the task an agent was assigned, rather than only checking whether the agent technically has permission to perform it. That distinction matters as organizations give agents access to credentials, code repositories and production systems. A control applied before execution could limit the time between an unsafe decision and a possible consequence, though the source provides no independent evidence that it prevents real-world incidents.

The reported latency and single-GPU deployment claim could make step-level monitoring more practical for some organizations than a large generative model used as a separate reviewer. However, the article does not provide false-positive or false-negative rates, examples of blocked actions, testing methodology beyond the cited , or independent replication. The comparison with unnamed third-party and frontier models therefore cannot establish superiority.

SiliconANGLE says customers include financial institutions and technology companies and quotes H&R Block’s chief security information officer supporting controls of this kind. Those references indicate claimed enterprise interest, not proof of broad deployment or effectiveness. The source does not state whether the product is self-serve, enterprise-only or sold as a separate paid service.

Interactive Mechanism

インタラクティブなメカニズム: 実際にどのように機能するか

この開発の背後にある基盤となるテクノロジーをインタラクティブに探索します。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
インタラクティブコンセプトチェック+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

次に見るべきもの

Watch for independent testing of Capsule’s StepShield results, details on false positives and false negatives, and evidence from production deployments. It is also unclear how the system integrates with different agent frameworks, what actions it can inspect, whether human approval is required for blocked or flagged actions, and whether the reported 71-millisecond latency holds under enterprise workloads. SiliconANGLE did not report pricing or a public self-serve sign-up path.

Independent researchers and customers should test whether the reported accuracy transfers from StepShield and Capsule’s internal to different agent frameworks, tools, tasks and attack methods. Step-level accuracy alone may not show how often a monitor misses a harmful action or interrupts legitimate work.

Further reporting should clarify how Capsule handles ambiguous actions, cascading tool calls, , compromised credentials and agents whose behavior changes after monitoring. The source does not explain what evidence the detector uses to decide whether an action is authorized or how customers configure policies.

The capability is described as available now, but SiliconANGLE provides no price, sign-up process, service-level terms or list of supported integrations. Those details will determine who can actually use it and whether the product is practical for smaller organizations as well as the enterprise customers mentioned in the report.

関連ガイドとクイズ

AIエージェントAI モデルの説明AI倫理あなたが知っていることをテストする - 無料の AI クイズに挑戦してください用語集で AI 用語を検索するAI 規制トラッカーをフォローする

更新と修正

この標準的なストーリーは、開発中のイベントが大幅に変更されると、その場で更新されます。 URL と元の発行日は決して変更されません。

  • SiliconANGLE adds that Capsule Security has released a separate Nemotron-based pre-execution monitor for rogue AI-agent actions. Capsule reports 98% accuracy on StepShield, 96.9% on an internal benchmark, response times as low as 71 milliseconds and single-NVIDIA-L40S deployment for its larger model. The capability is said to be available now, but pricing, access conditions, integrations and independent validation are unknown.
公開修正ログを参照してください
これは役に立ちましたか?