Giving agentic systems only two of three capabilities at once
Jensen Huang describes allowing agentic systems only two of three capabilities at a time: accessing sensitive information, executing code and communicating externally. He also describes applying enterprise access controls and connecting the systems to a policy engine.
We give you two out of three rights. Agentic systems can access sensitive information, it can execute code, and it can communicate externally. We could keep things safe if we gave you two out of those three capabilities at any time, but not all three.