Trend Micro's AI-security business unit TrendAI has thrown its weight behind the NVIDIA Agent Safety Platform, pairing its Vision One platform with hardware-level detection and Zero Day Initiative threat intelligence to help enterprises move autonomous agent fleets from pilot to production. The announcement, issued on September 29 and reported by Media OutReach Newswire, positions AI agent security as a layered discipline — one that has to live everywhere the agent does, not in a single control plane, according to TrendAI.

At the heart of the announcement is a shared principle both companies keep repeating: no single control makes an agent secure. Security must be built into every layer the agent depends on. As organizations shift from a handful of agent pilots to fleets spanning teams and business units, the pitch is that governance — not raw capability — is now the deciding factor in whether agentic AI reaches production at all.

Why AI Agent Security Can't Sit in One Place

TrendAI's case starts with the anatomy of an AI agent. It breaks an agent into three core components: the model that reasons, the harness that orchestrates the agent and its sub-agents, and the tools and data the agent can reach. Together, that combination lets an agent hold credentials, remember context across sessions, and act on production systems without a human approving each step.

That is exactly what makes these systems useful — and exactly what makes them risky. A chatbot waits for a prompt and returns an answer. An agent with persistent memory, live credentials, and tool access keeps working across systems, and every one of those powers is a surface an attacker or a misbehaving model can reach.

The market is waking up to the same problem. Startups are racing to make agent activity visible to the security teams that are supposed to govern it — Reco just raised $55M to secure the AI agents enterprises can't see — and the TrendAI announcement lands squarely in that wave: security tooling that treats agent fleets as infrastructure to be monitored, not demos to be admired.

According to the company's announcement, Rachel Jin, Chief Platform and Business Officer and Head of TrendAI, framed the move as a generational one: "Agentic AI is the most significant shift in enterprise technology in a generation, and security needs and guardrails are in place to keep the agents aligned with the intentions of the organization." Jin added: "Security can't sit in one place. It has to cover the model, the harness, and every tool and data source an agent touches."

What the NVIDIA Agent Safety Platform Actually Enforces

The NVIDIA Agent Safety Platform, per NVIDIA's description, places authority in the infrastructure beneath the agent rather than inside it. Its OpenShell layer enforces policy outside the agent's execution environment — a deliberate placement, so the policy cannot be prompted away or bypassed by the very model it constrains.

Below that sits a host-independent security layer in silicon. NVIDIA BlueField-4 DPUs and NVIDIA DOCA give the platform enforcement that lives apart from the host operating system, so a compromised host does not automatically mean a compromised policy. The design assumes the adversary can reach the machine and still should not be able to reach the controls.

That architecture matters because the most direct attacks on agents are prompt-layer attacks: instructions smuggled into tool output, documents, or web pages that redirect the agent's goals. Keeping policy enforcement outside the model's execution environment is the industry's emerging answer — the control point the agent cannot negotiate with.

What TrendAI Adds to the Stack

TrendAI positions its contribution as the intelligence that sits above that enforcement layer. NVIDIA supplies the control points; TrendAI supplies the knowledge of what the policy should be, the visibility to see what agents are doing, and the threat detection and response to act on it.

The centerpiece is TrendAI Vision One, which pairs hardware-level detection on NVIDIA BlueField DPUs and network security with Zero Day Initiative threat intelligence. ZDI's vulnerability research feeds directly into the detection layer, which is a notable pairing: agent-specific exploits are exactly the kind of emerging attack class a threat-intelligence pipeline is built to track before they become commoditized.

The announcement also promises "full AI Factory security" — extending the protection beyond individual agents to the whole inference and orchestration pipeline that produces them. As agents grow more autonomous, the attack surface keeps widening. Google's open-source RRSI framework even lets agents rewrite their own harnesses — which means the thing being secured can change its own behavior while the security team watches.

TrendAI is a business unit of Trend Micro Incorporated, which trades on the Tokyo Stock Exchange under 4704. The company has been repositioning itself around AI security as its core identity, and the NVIDIA partnership is its clearest bid yet to own the agent-security lane rather than just the endpoint lane.

What It Means for Agent Deployments

For enterprises, the practical takeaway is that agent security is converging on the same model as cloud security: defense in depth, policy outside the workload, and continuous visibility. The era of "the model is the product and the wrapper handles security" is ending.

Whether this particular partnership becomes the standard stack is an open question. NVIDIA's platform is vendor-locked by design — silicon-level enforcement means NVIDIA hardware. TrendAI's play is to be the intelligence layer on top regardless. Either way, the direction is set: the agent economy is getting its own AI agent security infrastructure, and the companies building it intend for it to look a lot like the infrastructure under everything else.

Source: TrendAI announcement via Trend Micro newsroom and Media OutReach Newswire.