Capsule Uses Nvidia Nemotron Models To Block Rogue AI Agent Actions
SiliconANGLE reports that Capsule Security released a real-time detection layer for agentic AI, using fine-tuned Nvidia Nemotron models to judge and block risky agent actions before execution.

Capsule Security released a real-time control layer for agentic AI systems, SiliconANGLE reported, using fine-tuned Nvidia Nemotron models to judge an agent’s next action before it reaches sensitive data, source code or production infrastructure.
The startup describes the system as an AI circuit breaker.
It sits outside the agent, evaluates the intended action, and lets customers allow, flag or block the step while the workflow is still running.
That timing is the product’s core claim.
Permissions and approval workflows can limit what an agent may access, but they do not decide whether a specific action fits the task an agent was assigned.
Monitoring after execution can also arrive too late for systems that hold credentials or can change production environments.
Capsule used StepShield as the public evidence point for the release.
That academic test measures whether monitors can spot rogue agent behavior at an individual workflow step.
Capsule put its result at 98% accuracy, with violations identified at the moment they happened, across a benchmark built from 9,429 real-incident code-agent trajectories.
The benchmark comparison also shows why alert quality matters.
In the same benchmark record, a rule-based guardrail detected most harmful trajectories but generated more than 75% of its alerts on harmless code before the bad action started.
The detector is built for classification rather than text generation, which keeps the decision point inside the agent workflow.
Capsule said responses arrived in as little as 71 milliseconds.
On Capsule’s internal test, the best detector reached 96.9%, while the top outside model evaluated reached 86%; Capsule did not identify the outside model or publish a more detailed comparison.
The training run used Nemotron 3 Ultra, the biggest model in Nvidia’s open Nemotron 3 family.
The training set included real agent traces and adversarial examples intended to define the boundary of authorized behavior, with human review applied to the material.
The larger of the two models cut memory requirements by close to half without losing performance, so deployment can fit on one Nvidia L40S graphics processing unit.
Naor Paz, Capsule’s co-founder and chief executive, said the risk has moved from what people can do with agents to what autonomous agents choose to do themselves.
Capsule says the product is already processing agent traffic at large scale, including billions of tokens and millions of interactions, for customers that include financial institutions and technology companies.
Capsule entered the public market in April after raising a $7 million seed round led by Lama Partners.
The new capability is available now, following earlier company disclosures involving Microsoft Copilot Studio and Salesforce Agentforce prompt-injection flaws that were later patched.




















