Enterprise Adoption3 min read

SAP and NVIDIA Build a Security Layer for AI Agents in Business Systems

June 5, 2026Synthesized from 1 source: NVIDIA

SAP is embedding NVIDIA's new open-source security tool directly into its business platform, which matters because SAP holds the financial, procurement, and supply chain data of over 400,000 companies globally, and AI agents now need permission to act inside those systems without human review at every step.

Most businesses that run SAP do not think about it much. It is the system in the background that handles invoices, supplier payments, inventory, and payroll. It is also, for most large organisations, where the most sensitive operational data lives. That context matters a great deal for understanding what SAP and NVIDIA announced this week.

The two companies are embedding NVIDIA's security tool, called OpenShell, directly into SAP's business platform. OpenShell is open-source software that creates an isolated, controlled box for every AI agent that runs inside it. The agent can only access the files and systems it is permitted to access. Every decision, every action, every approval or rejection is logged. If something goes wrong, there is a full record of what happened.

SAP serves over 400,000 companies across 180 countries, and 98 of the world's 100 largest companies are SAP customers. That means the financial records, supplier contracts, and procurement data of an enormous share of global commerce run through SAP's systems. AI agents are now being asked to operate inside those systems, and that is where the trust problem begins.

AI agents are not like the chatbots of two years ago. They do not just answer questions. They can read documents, trigger workflows, update records, and move across different systems without a human reviewing every step. Gartner estimates that by the end of 2026, up to 40 percent of enterprise applications will have AI agents integrated into them, up from less than 5 percent in 2025. That is an enormous and fast shift.

The security problem that comes with this shift is already producing real damage. In January 2026, attackers who compromised executive devices at a financial firm found that the AI trading agents had permission to move funds without human approval. Those agents moved the equivalent of tens of millions of dollars before anyone could stop them. Separately, researchers found a vulnerability in Microsoft's AI assistant that allowed a single malicious email to silently extract data from connected file systems without any user interaction. Prompt injection, where an attacker hides instructions inside normal-looking content and the AI agent follows them, is now the top-ranked vulnerability category for AI systems according to the Open Worldwide Application Security Project.

The response from most organisations has been slow. Only 24 percent of enterprises currently have a dedicated team focused on AI security governance. The average company has over 1,200 unofficial AI applications running inside it with most leaders unaware of them.

What makes the SAP and NVIDIA collaboration meaningful is the point at which the security is being applied. Most AI security today is either baked into the model itself (which can be bypassed) or applied at the application layer (which does not control what the agent does at the infrastructure level). OpenShell operates underneath all of that. It sits between the agent and the systems the agent is trying to reach, enforcing rules before any action takes place.

SAP's own builder environment, called Joule Studio, where companies can create custom AI agents for their own processes, will also work with this security layer built in. NVIDIA has also made a reference template, called NemoClaw, available directly in Joule Studio so that teams building agents start from a secured design rather than having to figure out the safety infrastructure themselves.

The collaboration is also notable because SAP's engineers are actively co-building OpenShell alongside NVIDIA, not simply adopting it. That means the security layer will be shaped by what large enterprises actually need in regulated environments, including audit trails, identity controls, and the ability to define what an agent should and should not do in business terms, not just technical ones.

For professionals working in finance, procurement, or operations inside companies that run SAP, the implication is straightforward. AI agents are coming to your systems, and the question of whether they operate safely is being settled now, at the infrastructure level, before widespread deployment. Whether this effort is sufficient will depend on how consistently it gets implemented and how fast the threat environment moves. But the direction is correct, and the urgency is real.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable