AI's missing paper trail, in two minutes. Watch on YouTube · Skip to the text

What NVIDIA announced, and what it leaves out

NVIDIA just made AI agents safe to run. Now they have to be safe to rely on.

Logs are for IT. Receipts are for AI.

On 28 September 2026 NVIDIA launched the Open Agent Safety Platform, backed by more than a hundred companies. It keeps AI agents inside the limits their operators set. It does not give the people who receive an agent's work any proof of how that work was made.

Two different questions
The operator asks

"Did the agent stay inside its limits?"

OpenShell answers this
The customer, auditor or regulator asks

"Can I rely on this result? Who authorized it, and under what rules?"

Nothing in the platform answers this

AI watermarks tell you a machine made it. Logs tell the operator what happened. Neither tells your customer who authorised it, under what controls, or what it was made from. Rootz Receipts puts that on the result.

What NVIDIA announced

A locked room for every AI agent.

AI agents no longer just answer questions. They read files, call systems, use credentials and act on their own. NVIDIA's platform is built to keep them from going where they shouldn't.

Software · free and open source

OpenShell

Runs each agent in a sandbox that denies everything by default. The agent can reach only the files, networks and credentials its policy allows, and the policy is enforced from outside the agent, so the agent can't switch it off.

Hardware · NVIDIA's newest data centers

Sentry

A hardware watchdog that monitors agents independently and can quarantine one that misbehaves within milliseconds.

This is real progress, and it is the right foundation. It protects the company running the agents: an agent in OpenShell can't wander off with data it was never meant to touch. What it records stays with the operator, in the operator's own systems.

What it leaves out

"Our agents run in a sandbox" is not proof that this result is sound.

The person who relies on an agent's work isn't asking whether your agents are generally well behaved. They are asking about one result: where it came from, who allowed it, and what rules applied when it was made.

What the platform gives the operator

Containment

Answers
Could the agent escape its limits?
Evidence
Policies and logs, inside the operator's systems.
Who can check
The operator's own engineers.
What a relying party needs

Proof about this result

Answers
Who authorized it, what was asked, what was used, and which controls were in force at that moment?
Evidence
Attached to the result itself, signed when the work happened.
Who can check
Anyone who receives the work, without access to your systems.

We have seen this before

"Our laptops are encrypted" never got anyone off the hook.

When a company lost a laptop full of customer records, the law excused it only if that data was encrypted. Saying "we encrypt our laptops" wasn't enough. Breach announcements from that era often admitted the company could not say whether the lost laptop had been encrypted. What actually protected a company was proof that this laptop was encrypted at the moment it was lost.

Rootz's founders built that proof for self-encrypting drives at Wave Systems. The people who bought it were the lawyers, not the IT department.

AI agents are at the same point. "Our agents run in OpenShell" is the new "our laptops are encrypted".

The question that decides liability, acceptance and payment is narrower: was this result produced by an agent running under approved controls, at the moment it was produced? Rootz Receipts answers it, with proof attached to every result.

Who will ask

The question arrives after the work ships.

Nobody asks how an AI result was made until it matters: a disputed number, an audit, a customer who has to rely on it.

Your customer

"Where did this number come from?"

Today
An engineer searches the logs and writes an explanation.
With a paper trail
The trail arrives with the work. They check it themselves in seconds, without access to your systems.
Your auditor or regulator

"Who authorized this, under what rules, on that day?"

Today
Screenshots, a meeting, and a promise that nothing changed.
With a paper trail
The officer's signed approval and the exact rules in force at that moment, attached to the result.
Your own board

"Can we let the agents do more?"

Today
Nobody can say for certain what the agents did last quarter.
With a paper trail
Every request and response the agent makes through OpenShell is on the record, so the agents' scope can grow with evidence instead of hope.

What Rootz Receipts adds

A paper trail for every piece of agent work, built on OpenShell.

Rootz Receipts installs into OpenShell's published extension points. Your agents don't change. Three things happen that didn't before.

  1. Approvebefore any work

    An officer of your company signs the rules the agents run under. OpenShell installs nothing else, and a change that widens what an agent may do needs a new approval.

  2. Recordwhile the work happens

    Every request and response an agent makes through OpenShell is recorded exactly as it happened. (Local file and process activity is a later phase.) If the controls drift from what was approved, the agent is stopped and the stop is on the record.

  3. Provewith every result

    Each result leaves with its own paper trail: who authorized it, what it was asked, what it used and the controls in force. Change one number and the trail breaks where anyone can see it.

Who reads it

Logs are for IT. Receipts are for AI.

People won't check a paper trail. Their AI will. Your customers want the answer, not the evidence behind it. But an AI checks a trail in a second, every time, and flags the one that doesn't hold up. Hand an AI only the answer, and it can find the trail and check it. When one agent's work feeds the next, the trail follows, so months later you can still answer "how did we get here?"

Three ways in

Where do you sit?

Go deeper

The detail, when you want it.