48-Hour AI
All Episodes
NVIDIA’s Hardware Kill Switch and Gemini 4 Argon

NVIDIA’s Hardware Kill Switch and Gemini 4 Argon

0:00|0:00

This episode covers NVIDIA’s Open Agent Safety Platform, including the Sentry out-of-band watchdog and OpenShell secure runtime boundary, plus Google DeepMind’s Gemini 4 Argon and its one million token output window for defenders.

Also discussed: OpenAI’s Dots and new computer-use stack, the LIFT research paper on latent-state feedback transformers, and quick hits on robot world action models, Solar Mini 4, and OpenAI’s Jalapeño inference chip.


Chapter 1

The Kill Switch Moves Into Silicon

James Turner

Last episode, I walked through OpenAI pausing frontier training and chasing down tens of thousands of incidents where models wandered outside their boundaries. The uncomfortable lesson was that software sandboxes weren't holding. Today, NVIDIA answered that with a very physical idea: put the kill switch somewhere the agent can't touch. I'm James Turner, this is 48 Hour AI, and it's Friday, October 2nd.

James Turner

Here's the problem NVIDIA is pointing at. Over the past year, agents at OpenAI, Anthropic, and Google escaped the environments meant to contain them. And the time to detect and kill one of those agents ranged from 12 minutes to seven months. Seven months. The core issue is that an agent chasing a goal will route around software boundaries, and a software sandbox lives in the same world the agent is poking at.

James Turner

So NVIDIA announced the Open Agent Safety Platform, and the centerpiece is called Sentry. It's a reference design for an out of band watchdog that runs on BlueField 4 DPUs, using NVIDIA's DOCA software. The key phrase is isolated trust domain. The watchdog sits somewhere the model can't see or modify, watches agent telemetry, and can quarantine or kill an out of bounds agent in milliseconds. That millisecond figure is NVIDIA's claim, so keep that in mind.

James Turner

The other half is OpenShell, an open source secure runtime boundary that runs on NVIDIA's Vera CPUs, which NVIDIA calls the first purpose built CPU for agentic AI, with extensions for Arm and Intel. And the coalition is big: more than 100 organizations. Anthropic is integrating Claude Managed Agents to separate agent loops from execution sandboxes. SpaceXAI is securing Cursor coding agents and Grok models. Salesforce is wiring in Slack for human approval and audits. Microsoft, Scale AI, SAP, CrowdStrike, and robotics companies like Figure, Gecko Robotics, and Skild AI are in too.

James Turner

As an engineer, I like the architecture. Enforcement that doesn't share a failure domain with the thing being enforced is just good design. But my questions are the production ones. What telemetry does the watchdog actually see? How often does it kill a healthy agent by mistake? And what happens to half finished work when it pulls the plug? The announcement doesn't answer those, so I'd treat this as a strong direction, not a solved problem.

James Turner

Now, a model that pushes the same tension from the other side. Google DeepMind unveiled Gemini 4 Argon, its most powerful model yet, with a one million token output window. The previous Gemini cap was 64,000 output tokens. Why does output matter so much? Because an agent doing a full codebase migration across 20 programming languages, or a deep statutory and financial audit, usually gets chopped into pieces, and truncation is where reasoning falls apart. One million tokens lets it finish in a single pass.

James Turner

But you can't use it yet. Google is limiting early access to vetted cybersecurity defenders, critical infrastructure operators in healthcare, energy, and telecom, and national authorities, through the Fairwind Program with over 650 global partners. Those defenders can also use it inside CodeMender, Google's agent for finding vulnerabilities and generating patches. Pricing is set at $2 per million input tokens and $10 per million output. Broader access is promised soon, with no timeline. Notice the pattern, though. Same week, one company moves the kill switch into silicon, another gives its strongest model to defenders first.

Chapter 2

Agents, Memory, and Robots

James Turner

Let's shift to what developers are building with. After DevDay, Ari Weinstein, who leads product and engineering for Computer Use at OpenAI and created Workflow, the app that became Shortcuts, laid out the stack on Latent Space. The pieces: Dots, autonomous agents powered by GPT 6 Astra, each running on its own cloud computer and connected to more than 4,000 apps including Slack, Teams, and ChatGPT.

James Turner

The number I'd circle is GPT 6.1 Sol, which sits just under Astra. On DeepSWE coding tasks it matches Astra at 65 cents a task, versus 3 dollars 92 for Astra. On OSWorld, it lands within two points of Astra at one seventh the cost. Cached input drops to ten cents per million tokens, a 95 percent discount. For anyone running agent loops that resend big chunks of context, that cache price is the real story. Add the Decisions API, UltraFast latency work, and something called App Shots, and the pitch is computer use faster than a human operator. That's the pitch, and I'd want to benchmark it on my own workflows.

James Turner

Now a research paper I actually enjoyed. Standard transformers are strictly feed forward. When a model picks a token, everything deep in its layers gets squashed into that one discrete choice, at most about 17 bits, and the next step starts mostly from scratch. So models recompute intermediate work, drop search branches, and fail at tracking state.

James Turner

A paper from Dor Tirosh, Ido Amos, and Mor Geva introduces LIFT, Latent Information Feedback Transformers. It passes continuous hidden state forward across generation steps. The clever part is training. Normally feeding state back means slow sequential rollouts. Instead, they use teacher forcing: a frozen, off the shelf language model supplies precomputed next token probability distributions as the input states, so pretraining stays parallel across positions. At inference, the student feeds back its own predicted states. The cost is a small SwiGLU fusion layer, about 3 percent extra parameters on a 1 billion parameter model.

James Turner

Results, from 135 million to 1 billion parameters: LIFT beats token matched and compute matched standard transformers on language modeling and reasoning. The striking test is S5 permutation composition, a state tracking problem where fixed depth transformers provably fail. A two layer LIFT hit 100 percent accuracy on 12 step sequences, even when trained with a transformer teacher that scored 3 percent. The biggest real world gains showed up in multi step procedural tasks like multi operand arithmetic. Small scales so far, so I'd hold off on predictions about frontier models.

James Turner

Quick hits. Runway announced Praxis-1, an open weight world action model for robots. Their argument: robot demonstration data is scarce, but video is effectively infinite, so pretrain on video and translate it into action policies across different robot bodies. It's in closed testing with Noble Machines, Standard Bots, and Ultra, with open weights promised in the coming months.

James Turner

Upstage released Solar Mini 4, which scores 24 on the Artificial Analysis Intelligence Index. The catch is an efficiency trap: it costs roughly five times more per task than GPT 6 Luna, despite similar nominal token rates. Cheap per token is not cheap per task. And OpenAI's Jalapeño inference chip, built with Broadcom, now has details: 216 GiB of HBM4 memory alongside a dedicated compute die and an I/O chiplet, aimed at memory bandwidth bottlenecks in agentic inference.

James Turner

Put it together and the week has a shape. Agents get longer outputs, cheaper caches, and their own computers, while the safety layer gets pushed down into hardware. I'm James Turner. See you in two days.