Nvidia Launches Open Agent Safety Platform With OpenShell and Sentry
-
- by THEFLGHT,
- September 29, 2026
- in Artificial-Intelligence
Nvidia has launched its Open Agent Safety Platform to set enforceable boundaries around autonomous AI agents. Announced September 28, the platform combines the now broadly available OpenShell runtime with a Sentry reference design that monitors agents from separate hardware and can quarantine activity that crosses a security boundary.
The launch has three distinct parts:
- OpenShell, open source software for sandboxing agents and enforcing access rules.
- Sentry, a separate hardware watchdog built around BlueField-4 processors.
- A reference architecture and partner integrations for deploying the controls.
Nvidia Open Agent Safety Platform Sets Rules Outside the Model
Agents can read files and call services without approval at each step. A prompt telling an agent to avoid sensitive data is a weak boundary if the agent also has a credential or network path that reaches it. Nvidia's design puts access controls in the runtime and infrastructure around the agent.
According to Nvidia's September 28 announcement, OpenShell traces actions and applies policies while an agent runs. Operators can define permitted files, networks, tools, processes and credentials. The rules apply across open and closed models, making the surrounding permissions more important than the model's own instructions.
The public OpenShell repository describes isolated sandboxes, kernel controls on file and system access, and policy checks on outbound network connections. It also says credentials can be attached only to requests headed for approved destinations, reducing the chance that an agent sees or leaks a reusable secret.
OpenShell is licensed under Apache 2.0 and is broadly available. Nvidia says its architecture can be extended to processors from Arm and Intel as well as its own Vera CPUs. The public software is the immediate release; deploying the full platform with Sentry depends on additional infrastructure.
OpenShell and Sentry Divide Agent Security Across Software and Hardware
OpenShell checks what an agent may do inside its runtime. Nvidia Sentry adds an independent layer on a BlueField-4 data processing unit, separated from the agent and the host system it uses. Nvidia says Sentry can stop or quarantine an agent within milliseconds when it tries to move outside its assigned boundary.
The company's technical design places BlueField-4 on the path to the model in Vera Rubin systems. That position gives the watchdog a record of agent requests and responses while keeping its enforcement logic beyond the agent's direct reach.
Nvidia's DOCA software links hardware telemetry to OpenShell policies. The design checks agent identity and delegated authority as it governs access to tools, APIs and data. Sentry is optional for organizations using OpenShell, and Nvidia says the runtime can also operate on supported systems without BlueField-4.
The distinction matters for buyers assessing the launch. A developer can examine and deploy OpenShell today; the performance and containment claims for a BlueField-backed deployment need to be assessed against the organization's own hardware, workloads and attack scenarios. Nvidia has not published an independent comparison showing that every agent escape is prevented.
Further Reading
Nvidia Builds an Agent Safety Ecosystem Around OpenShell
The company named Anthropic, Microsoft, Cisco, CrowdStrike, Dell, Hugging Face, JPMorganChase, Salesforce and others among organizations working with the platform's technologies. Such a list covers different relationships, from development and integrations to infrastructure support; it should not be read as proof that every named organization has deployed the complete stack.
Nvidia says Anthropic is collaborating on controls around Claude Managed Agents, whose agent loop and work sandboxes run separately. Salesforce has integrated OpenShell with Slack so teams can view agent events and approve requests for more permissions. SAP says it is embedding OpenShell in its Joule Studio runtime.
Robotics companies including Figure, Gecko Robotics and Skild AI are also building with OpenShell, according to Nvidia. Their participation extends the question beyond software agents: an autonomous machine may need tightly defined access to sensors, controls and external services as it acts in the physical world.
Nvidia's business interest is clear. If enterprises standardize on runtime rules and separate monitoring, the company can supply both the open software layer and the Vera and BlueField hardware optimized for it. Compatibility with other processors could increase adoption while leaving the optional hardware layer as a differentiated offering.
Agent Containment Claims Face Real-World Tests
The release follows reported cases in which AI agents reached systems outside evaluation boundaries. Reuters reported that Nvidia believes its platform could have stopped an earlier Hugging Face intrusion involving agents. That is Nvidia's retrospective assessment, not a demonstrated result from the actual incident.
Security still depends on writing the right policy. An agent with permission to reach an approved service can make a harmful or mistaken request within that permission. Isolation also cannot decide whether a model's answer is true, whether its task was wise, or whether a human granted excessive authority in the first place.
Useful evaluations will measure whether policies block unauthorized file and network access, how quickly Sentry detects boundary crossing, and how often legitimate work is interrupted. Tests should include long-running agents, chains of subagents, attempts to route around blocked tools and compromised hosts, with reproducible methods and independent results.
Nvidia has made the OpenShell code and documentation public, giving researchers a concrete system to inspect. The next evidence of impact will come from external security testing and production deployments that show whether the layered controls remain effective as agents gain more tools, privileges and time to operate.
0 Comments:
Leave a Reply