At Gecko, we continually innovate new technologies to improve our customers’ understanding of their assets, and that means working on the cutting edge. But, as anyone who’s deployed novel tech in field operations knows, that edge can cut both ways. Steel-toed boots and hard hats protect us when we work in industrial environments. As we introduce AI agents into those environments, we need to equip them with safeguards of their own: enforced operating boundaries that protect the people and equipment around them.
Part of the NVIDIA Open Agent Safety Platform, NVIDIA OpenShell provides guardrails so AI agents can operate responsibly in the physical world. We are working with the OpenShell team to harness the benefits of agentic robot operation. OpenShell is open source software that provides runtime mechanisms for sandboxing agents, monitoring their actions, and enforcing policies. An agent deployed to a field system lives in the OpenShell sandbox and operates on the physical context: where the robot is, what conditions it must respect, the inspection data requirements, and which decisions remain with the human operator.
Together, we’re exploring how to translate that context into enforceable operating boundaries within the Komodo field system, which is discussed below in more detail. A movement command may be mechanically valid but unsafe near a ship’s edge; a faster scan may meet a deadline but obtain insufficient inspection data. Our joint work codifies the physical realities as controls governing agent behavior. Deck inspection is our pilot for building this foundation, with the ambition to extend it across the industrial environments Gecko serves.

Autonomizing Komodo, Gecko’s EMAT Robot
Our Komodo system is used to inspect the decks of Navy ships and identify corrosion under the nonskid paint. It’s a mature robotic field system with over a dozen paid inspections under its belt and over a hundred thousand square feet of deck inspected. It consists of a custom backpack and probe mounted to a third-party crawler and raster arm. Gecko’s field software determines the robot’s position, reads thickness measurements from the custom EMAT probe, and commands the robot’s scanning to cover the deck surface. More info on the Komodo system can be found in our prior blog posts (Enter the Dragon: Building out the Komodo System, Komodo Rising: 0 to 1, Komodo Rising: Battle of the USS Barry, Komodo Rising: From 1 to N, and Komodo Rising: Taking Full Control of the Crawler)

Demand for deck inspections continues to rise, so we are investing in increasing our inspection throughput. Enabling one operator to potentially oversee multiple robots helps our team inspect more deck area simultaneously, but necessitates additional safeguards designed for that expanded scope of supervision. With an operator’s attention split, we need to optimize the system for safety. The ship deck environment is unforgiving of failures; driving off the edge of a test deck in the lab is inconsequential, but driving off a real deck could cause serious injury. As we explore agentic control of our robot to enable one operator to control multiple robots, a reliable safety system is critical.
Safe Deployment of AI through OpenShell
The NVIDIA OpenShell runtime provides exactly the reliable safety system we need. It sandboxes the agents used for autonomous control, giving them exactly the access they need to assess the state of the inspection and plan the next action, but nothing more. The agents cannot read or delete irrelevant files, modify any elements of the field software, or access network connections except for the specific interfaces it needs. Given that the agents are non-deterministic and are capable of making mistakes, these constraints are critical. While not yet deployed into production, all of these features have been implemented and tested on a live robot in our on-site testing environment in Pittsburgh.
OpenShell also enforces physical safety constraints. Our robot control interface exposes the complete capabilities of the robot. How those capabilities are constrained in a given operating environment is not naturally determined by the system. OpenShell is a useful means of providing the agent with situational awareness and known-at-inspection-time constraints and remediation techniques. For example, the bounds of the deck are determined, and OpenShell monitors all commands the agent sends to the robot. Any command that would push the robot outside its safe operating envelope is intercepted and modified to keep the robot inbounds. The agent is notified that its command caused an unsafe behavior, why, and what the modified command is so that it can replan and improve its approach, and this system allows the robot to reach the edge of its envelope without going over.


The agent’s constraints can change rapidly. “Finish the job in half the time” is the kind of instruction a sudden change to a ship’s schedule might force us to give an AI agent. The deadline is explicit, but the agent must still respect the requirements that make the inspection useful and safe. Rastering the probe faster increases system throughput at the cost of data density. Whether this trade-off is acceptable depends heavily on context that agents might not fully understand, but our field operators know intuitively. OpenShell keeps that tradeoff under human control; the agent can propose a higher raster speed, but OpenShell will intercept and escalate for human review before any changes are made. Its dynamic policy management lets us adapt to new conditions while preserving clear separation between pursuing a goal and authorizing the means to achieve it.
In a rapidly changing environment, the robot must give humans right-of-way and stop for them. The robot flags dynamic objects, and the OpenShell middleware monitors. If a person steps within a safety threshold, the OpenShell middleware stops the robot and notifies both the agent and operator. Once the operator notifies the middleware that the environment is safe again, OpenShell allows the agent to continue inspecting.
Moving Toward Safer, Faster Autonomous Inspections
Our deck inspection program is the pilot for a broader ambition: bringing agentic autonomy to our inspections in industrial sites around the world. The first milestone is one operator overseeing an inspection carried out by multiple Komodos, enabling our team to conduct more inspections. The lessons we learn on ship decks will inform how we extend autonomy across the environments Gecko already serves, from power plants to domestic oil and gas operations, boilers, and foundries. Each environment requires different equipment, operating conditions, and guardrails that our systems must respect.
NVIDIA’s work on OpenShell supports more capable autonomous agents governed by explicit policies and provides a foundation for that trajectory. By separating agent planning from enforcement of site-specific operating constraints, we can explore new capabilities while keeping authority over consequential decisions with the people who understand the work. Our ambition is to give each operator greater reach: coordinating more robots, gathering more asset data, and helping customers act on the condition of their critical infrastructure.
Achieving this will take sustained experimentation, with rigorous safeguards necessary from the first field test. Hard hats and steel toes are how our people arrive prepared for the job; enforced operating boundaries are just as fundamental for the agents working alongside them. As we take agentic robot control from ship decks to industrial sites worldwide, our responsibility grows with our capabilities, to the infrastructure entrusted to us and the people who depend on it.
_downres.jpg)