返回新闻
安全AI Understanding 简报

Capsule Security 报告基于 Nemotron 的 AI 断路器

SiliconANGLE 报道称,Capsule Security 发布了一个基于 Nemotron 的系统,该系统在执行之前立即评估 AI 代理的操作,并可以允许、标记或阻止它们。

4 min readRead the linked source
Source-provided image accompanying Capsule Security reports Nemotron-based AI circuit breaker
来源参考来源记录
出版商
siliconangle.com
来源链接
siliconangle.comhttps://siliconangle.com/2026/09/02/capsule-security-fine-tunes-nvidia-nemotron-models-to-stop-rogue-ai-agents/
来源类型
链接来源——主要来源状态尚未确定。
还引用了

故事最后修订

背景60 秒内了解这一点

从这里开始

关键术语

内存(代理内存)
AI 代理跨步骤或会话使用存储的上下文来提高连续性。
及时注射
一种攻击模式,其中恶意指令被插入到模型输入或检索的内容中。
基准测试
用于测量和比较模型性能的标准化测试或数据集。
测试一下自己AI 代理测验

自发布以来发生了什么变化

  1. 首次发表
  2. SiliconANGLE adds that Capsule Security has released a separate Nemotron-based pre-execution monitor for rogue AI-agent actions. Capsule reports 98% accuracy on StepShield, 96.9% on an internal benchmark, response times as low as 71 milliseconds and single-NVIDIA-L40S deployment for its larger model. The capability is said to be available now, but pricing, access conditions, integrations and independent validation are unknown.

发生了什么

SiliconANGLE reports that Capsule Security released an “AI circuit breaker” built from two fine-tuned NVIDIA Nemotron models. The system evaluates an agent’s intended action immediately before execution and lets customers allow, flag or block it. Capsule said the detector reached 98% accuracy on the StepShield and returned decisions in as little as 71 milliseconds. The capability is reportedly available now, although access conditions and pricing were not disclosed.

SiliconANGLE reports that Capsule Security released a detection system based on two NVIDIA Nemotron models that it fine-tuned itself. Capsule describes the product as an “AI circuit breaker”: it judges an agent’s intended action immediately before the action executes, allowing a customer to permit, flag or block it. The source says the control layer is intended for agents with credentials to sensitive data, source code or production infrastructure.

According to SiliconANGLE, Capsule said its system achieved 98% accuracy on StepShield, a using 9,429 code-agent trajectories drawn from real incidents. Capsule’s most accurate detector reportedly scored 96.9% on an internal benchmark, compared with 86% for the strongest unnamed third-party model tested. The article says Capsule did not identify that model or provide a score breakdown.

SiliconANGLE reports that decisions returned in as little as 71 milliseconds. Capsule said its larger model’s memory requirements were reduced by nearly half without a performance loss, allowing it to run on one NVIDIA L40S GPU. The training data reportedly included real agent traces and human-reviewed adversarial examples marking the boundary between authorized and unauthorized behavior.

The source says the capability is available now. It does not specify pricing, procurement, supported agent platforms, geographic limits or whether the release is generally accessible. None of the performance claims, customer references or the reported availability was independently confirmed for this evaluation.

来源详情: siliconangle.com ↗

为什么这很重要

The reported system targets a practical weakness in agent security: permissions can limit what an agent may access, but they do not necessarily determine whether a specific action is appropriate for the task. A pre-execution decision layer could give security teams another control point before an error becomes an incident. The performance figures, customer claims and comparisons remain SiliconANGLE’s account of Capsule’s statements and were not independently confirmed here.

The reported approach focuses on whether an action fits the task an agent was assigned, rather than only checking whether the agent technically has permission to perform it. That distinction matters as organizations give agents access to credentials, code repositories and production systems. A control applied before execution could limit the time between an unsafe decision and a possible consequence, though the source provides no independent evidence that it prevents real-world incidents.

The reported latency and single-GPU deployment claim could make step-level monitoring more practical for some organizations than a large generative model used as a separate reviewer. However, the article does not provide false-positive or false-negative rates, examples of blocked actions, testing methodology beyond the cited , or independent replication. The comparison with unnamed third-party and frontier models therefore cannot establish superiority.

SiliconANGLE says customers include financial institutions and technology companies and quotes H&R Block’s chief security information officer supporting controls of this kind. Those references indicate claimed enterprise interest, not proof of broad deployment or effectiveness. The source does not state whether the product is self-serve, enterprise-only or sold as a separate paid service.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
交互式概念检查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下来看什么

Watch for independent testing of Capsule’s StepShield results, details on false positives and false negatives, and evidence from production deployments. It is also unclear how the system integrates with different agent frameworks, what actions it can inspect, whether human approval is required for blocked or flagged actions, and whether the reported 71-millisecond latency holds under enterprise workloads. SiliconANGLE did not report pricing or a public self-serve sign-up path.

Independent researchers and customers should test whether the reported accuracy transfers from StepShield and Capsule’s internal to different agent frameworks, tools, tasks and attack methods. Step-level accuracy alone may not show how often a monitor misses a harmful action or interrupts legitimate work.

Further reporting should clarify how Capsule handles ambiguous actions, cascading tool calls, , compromised credentials and agents whose behavior changes after monitoring. The source does not explain what evidence the detector uses to decide whether an action is authorized or how customers configure policies.

The capability is described as available now, but SiliconANGLE provides no price, sign-up process, service-level terms or list of supported integrations. Those details will determine who can actually use it and whether the product is practical for smaller organizations as well as the enterprise customers mentioned in the report.

相关指南和测验

人工智能代理人工智能模型解释AI 伦理测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注AI监管追踪器

更新和更正

当正在发生的事件发生重大变化时,这个典型的故事就会被更新。它的 URL 和原始发布日期永远不会改变。

  • SiliconANGLE adds that Capsule Security has released a separate Nemotron-based pre-execution monitor for rogue AI-agent actions. Capsule reports 98% accuracy on StepShield, 96.9% on an internal benchmark, response times as low as 71 milliseconds and single-NVIDIA-L40S deployment for its larger model. The capability is said to be available now, but pricing, access conditions, integrations and independent validation are unknown.
查看公开更正日志
觉得这有用吗?