Trusted Autonomy with Cadence Super Agents & NVIDIA Open Agent Safety Platform
Cadence AI Super Agents bring engineering trusted autonomy to semiconductor workflows, enabled by NVIDIA Open Agent Safety Platform.
Autonomous engineering is no longer about whether AI can reason about chip design. The harder question is whether that reasoning can safely translate into actions inside a complex semiconductor engineering environment. The answer requires more than a capable model. It requires governance across the systems in which autonomous agents operate.
Cadence and NVIDIA are addressing this challenge with Cadence AI Super Agents operating within NVIDIA Open Agent Safety Platform. The platform provides full-stack governance and control for autonomous agents, with NVIDIA OpenShell providing the secure runtime boundary in which agents can run under defined policies, and NVIDIA Sentry, running on NVIDIA BlueField-4 and built on NVIDIA DOCA, enforcing policy outside the agent’s execution environment.
For semiconductor engineering, that distinction matters. An agent may need to access design artifacts, invoke EDA technologies, launch simulations, inspect results, modify RTL, and determine what to do next. Giving it the intelligence to perform those actions is one problem. Giving it the authority to perform them without unrestricted access to the surrounding environment is another.
An agent can determine an action without being able to grant itself permission to perform that action.
That separation is the foundation for trusted autonomous engineering.
Three Forms of Authority
Autonomous engineering requires three different forms of authority.
Reasoning authority - What should I do next?
Cadence AI Super Agents interpret engineering intent, understand workflow context, and determine the next action.
Engineering authority - Did the action produce a valid engineering result?
Cadence EDA technologies provide the domain-specific computation and evidence needed to evaluate the design and determine whether it meets the relevant requirements.
Execution authority - Am I permitted to perform that action?
The NVIDIA Agent Safety Platform provides governance and control across the agent stack, with NVIDIA OpenShell establishing the runtime boundary that governs what an agent can access and execute.
These roles are complementary but not interchangeable. An agent can determine that RTL should change without having unrestricted permission to modify files or invoke arbitrary processes. A simulation or formal engine can establish that a design change failed verification without deciding what resources the agent may access. An execution environment can enforce a policy without determining whether a particular RTL change is the right engineering decision.
Cadence makes the autonomy engineering-aware. NVIDIA provides the governance architecture that makes autonomous execution controllable.
An Architecture for Governed Autonomy
The architecture connects those forms of authority while keeping their responsibilities distinct.
|
Layer |
Role |
Technology |
|
Engineering intent |
Defines the objective, constraints, and success criteria |
Engineer |
|
Reasoning authority |
Interprets intent, plans actions, and orchestrates the workflow |
Cadence AI Super Agents |
|
Engineering authority |
Performs domain-specific analysis and establishes engineering evidence |
Cadence EDA technologies |
|
Governance and control |
Defines and enforces boundaries for autonomous execution |
NVIDIA Agent Safety Platform |
|
Runtime execution |
Provides the secure execution boundary for agents |
NVIDIA OpenShell |
|
Engineering results |
Provide evidence that informs the next action |
Cadence EDA technologies |
From Runtime Boundary to Full-Stack Agent Governance
NVIDIA OpenShell addresses the execution boundary around the agent. The NVIDIA Open Agent Safety Platform extends that governance across the broader stack that supports autonomous systems. NVIDIA Sentry adds an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs to continuously monitor agent behavior. Sentry can quarantine agents that attempt to move outside their boundaries in milliseconds.
The platform brings together agent runtime software, security enforcement, monitoring, and infrastructure controls. This includes NVIDIA OpenShell for the secure runtime boundary, NVIDIA Sentry , an out-of-band watchdog for monitoring and enforcing agent behavior and thinking on NVIDIA BlueField-4, and NVIDIA Vera CPU infrastructure for efficient agent execution.
This broader architecture is relevant as autonomous engineering moves beyond individual tool calls. An agent may interact with files and processes, consume compute resources, access network services, and coordinate work across multiple engineering technologies. Governance therefore needs to extend beyond the agent itself to the systems that enable its work.
For Cadence workflows, this provides a foundation for scaling autonomous engineering while keeping access, execution, and system-level controls governed independently of the agent's reasoning.
Separating Governance from Engineering Truth
Governance answers one question: What is the agent allowed to do?
Engineering answers another: What happened when it did it?
That distinction is critical in semiconductor design. A language model can generate RTL. But generating a plausible artifact is only the beginning. The design has to be exercised through engineering technologies that can establish whether it behaves as required.
Cadence AI Super Agents bring that engineering context into the autonomous loop. They can understand the design objective, orchestrate the workflow, invoke the appropriate Cadence technologies, interpret engineering results, and determine what to do next.
The resulting loop is:
Reason → Execute → Measure → Diagnose → Modify → Re-execute
In a digital design workflow:
RTL → Testbench → Simulation → Evidence → Diagnosis → RTL Modification → Formal Verification → Regression → Next Iteration
A failed simulation is evidence that can change the next engineering decision. A formal violation can change the design hypothesis. A successful run provides evidence that allows the workflow to advance.
The workflow responds to what it discovers.
From Architecture to Measurable Engineering Impact
The value of this architecture is ultimately measured by what it changes in an engineering workflow.
Cadence has demonstrated that impact with ChipStack AI Super Agent. At NVIDIA, engineers are using ChipStack AI Super Agent to run dynamic simulations with Cadence Xcelium Logic Simulator and Jasper Formal Verification. The resulting workflow delivers more than 40X faster RTL validation, reducing a typical five-week verification loop to less than one day.
The result provides a concrete example of the three forms of authority working together:
- Reasoning authority: ChipStack AI Super Agent determines what to do next based on the engineering objective and observed results.
- Engineering authority: Xcelium and Jasper provide the computational evidence used to evaluate the design.
- Execution authority: NVIDIA's governance and execution technologies provide the environment in which those autonomous actions can occur.
Traditionally, engineers coordinated these stages manually. ChipStack can connect them into an autonomous loop, using intermediate results to determine the next action and continue toward closure. The significance of the result is not simply the reduction in elapsed time. It demonstrates that simulation, formal analysis, debug, and RTL modification can operate as a connected autonomous process rather than a series of manually coordinated tasks.
NVIDIA is also applying ChipStack AI super Agent to the verification of its own chip designs. The collaboration therefore spans both the technology stack and its practical application: Cadence brings autonomous engineering and EDA technologies, while NVIDIA provides the accelerated infrastructure and agent safety architecture for governed execution.
From Individual Agents to Agentic Engineering

ChipStack AI Super Agent is one example of this model in digital front-end design and verification. The same approach extends across other parts of the semiconductor workflow.
Cadence AI Super Agents can specialize around different engineering domains:
- ChipStack AI Super Agent for digital front-end design and verification.
- ViraStack AI Super Agent for custom and analog design.
- InnoStack AI Super Agent for digital implementation and signoff workflows.
- AuraStack AI Super Agent for PCB design and advanced packaging.
- AgentStack for orchestration across specialized agents and engineering tasks.
As these capabilities expand, autonomous workflows can move beyond a single agent and task to coordinate specialized agents across a larger engineering flow, with the same governance principles applying across the environment.
The result is a model in which agents reason about engineering objectives. Cadence technologies establish engineering truth. The execution environment governs what agents are permitted to do.
What Changes When Engineering Becomes Autonomous?
Traditional automation executes a sequence defined in advance. Autonomous engineering starts with an engineering objective and determines the work required to move toward it.
The engineer still defines the objective, constraints, success criteria, and boundaries. What changes is how the work between those conditions is managed. Instead of specifying every transition, the engineer can allow the autonomous system to evaluate results, choose the next step, and continue until the defined conditions are met or human intervention is required.
This changes the unit of automation from an individual task to a workflow. Simulation, formal analysis, debugging, design modification, and subsequent verification can become part of one continuous engineering process rather than separate activities coordinated manually.
It also changes where engineers spend their time. The focus moves from managing routine transitions between tools toward defining objectives, reviewing results, handling exceptions, and making decisions that require engineering judgment.
As autonomous systems take on more of the workflow, the engineering environment must support that autonomy without removing human control. The objective remains defined by the engineer, while the system manages execution within the boundaries established for the work.
Why Engineering Context Matters
An agent that can call an EDA tool is not necessarily an engineering agent. Semiconductor design depends on relationships between specifications, RTL, verification environments, simulation results, formal properties, implementation constraints, and signoff requirements.
Cadence AI Super Agents are being built around these workflows and technologies. They connect engineering intent to the appropriate technologies, interpret the evidence those technologies produce, and use that evidence to determine what happens next. The agent, therefore, needs to understand not only what it can do, but what an action means in the context of the design.
The Path Forward
As autonomous workflows expand across the semiconductor design flow, the challenge shifts from making individual agents capable to making them reliable participants in real engineering environments.
Cadence AI Super Agents bring engineering intent and workflow context into that environment. Cadence technologies provide the evidence needed to evaluate each step. NVIDIA provides the infrastructure and agent safety architecture that governs autonomous execution, with OpenShell providing the runtime boundary.
Trusted autonomy does not require giving an agent unrestricted authority. It requires giving it enough authority to do meaningful work, grounding its decisions in engineering evidence, and keeping execution within explicit boundaries.
That is the foundation for autonomous engineering that can scale without requiring engineers to surrender control.
Explore trusted autonomous engineering with Cadence AI Super Agents and NVIDIA Open Agent Safety Platform technologies. See how engineering-aware AI and governed execution can work together to automate complex semiconductor design workflows.
Related Semiconductor IP
- OpenTitan-based RISC-V Secure Element
- TSMC 40nm 5V GPIO
- Low Power 32kHz Pierce Oscillator
- Time-Sensitive Networking (TSN) End Point DO-254 IP Core
- TSMC 22nm 1.0V, 1.2V & 1.8V GPIO
Related Blogs
- Reimagining Chip Design - From Spec to Signoff with Cadence AI Super Agents
- TSMC Open Innovation Platform Explained
- TSMC Extends Open Innovation Platform
- Linux-Based Audio Platform with Cadence Tensilica HiFi 5