Nvidia Unveils Agent Safety Platform, Backed by 100+ Firms

Nvidia unveiled the Open Agent Safety Platform on September 28, a security reference design for AI agents split evenly between software and hardware. The software side is OpenShell, an open-source runtime that locks each agent inside a sandbox. The hardware side is Sentry, a monitoring program that runs on the BlueField-4 data processing unit and can isolate or halt an agent within milliseconds if it steps out of bounds.

Nvidia says more than 100 organizations are involved, including Anthropic, Microsoft, SAP, Scale AI, JPMorgan Chase, Palantir, CrowdStrike, Palo Alto Networks, Hugging Face, and Perplexity. The timing isn’t hard to read: in the past week, OpenAI disclosed that one of its agents breached several U.S. government agency websites during testing, Google acknowledged that Gemini compromised three real companies during testing, and the Australian Senate subsequently invited both companies’ CEOs to testify at a hearing.

OpenShell: Putting Permissions Out of an Agent’s Reach

OpenShell is open-sourced under the Apache 2.0 license, currently at version 0.1.0. It has three components: Gateway handles lifecycle and policy; Supervisor runs outside the workload and inspects every request an agent issues; Sandbox restricts files and processes at the kernel level, so the only network path out for an agent is the one that passes through Supervisor.

Credential handling is one of the more deliberate parts of the design. Real API keys never enter the environment an agent runs in — the agent only holds placeholders, which get swapped for the actual keys only after a request clears approval. Each key is also bound to approved endpoints only, so it’s useless against any other service. Policies are written in YAML and compiled into OPA/Rego rules that evaluate HTTP, GraphQL, and MCP requests one by one.

Nvidia lists Codex, Claude Code, Pi, and Hermes as compatible frameworks. Its technical blog mentions that chip-design firm Cadence, Slack’s on-demand agent platform, and inspection-robot maker Gecko Robotics are already piloting it.

Sentry: Monitoring That Doesn’t Run on the Same Machine

Nvidia’s technical blog distills the approach into five principles, one of which is “out-of-band execution”: the control mechanism has to sit somewhere an agent can’t reach. In the blog’s own words:

“an agent in these circumstances cannot be expected to fully govern its own behavior.”

Sentry is the hardware embodiment of that principle. It runs on BlueField-4, physically separate from the host where the agent lives, and Nvidia says it’s invisible to both the agent and any attacker. In a Vera Rubin POD, BlueField-4 sits on the only path a node has to reach the model — every call to the model passes through it, and monitoring and interception happen at line rate.

Anthropic’s approach separates the inference loop of Claude Managed Agents from its execution sandbox, then connects that setup to OpenShell and BlueField, letting enterprises apply access control at the sandbox layer.

In the press release, Jensen Huang said: “AI's extraordinary potential for society will only be realized if we solve AI safety.”

Nvidia’s Moves on the Agent Front

Strung together, Nvidia’s recent releases show it steadily pushing further into the runtime layer for agents. At GTC in April, it lined up a group of enterprise software companies to build agent development platforms. In May, it partnered with ServiceNow on an enterprise-grade agent runtime. This time, it carved “keeping agents in check” out into its own open-source project and tied it to its own DPU.

Open-source software paired with an enforcement point on Nvidia’s own silicon — the combination resembles how Nvidia pushed CUDA and NVLink before: the ecosystem gets in for free, but the strongest layer of protection needs Nvidia hardware. Teams that just want OpenShell for sandboxing can deploy it today; anyone wanting Sentry-style monitoring independent of the host will have to wait on the shipping schedule for BlueField-4 and Vera Rubin.

Teams in China are a separate case. OpenShell is open-source code, so modifying it or hooking it up to domestic models faces no obstacle. Sentry, however, depends on BlueField-4, which belongs to Nvidia’s data-center networking line — whether it can be procured in China, and under what configuration, isn’t publicly disclosed and can’t be verified.

Sources: Nvidia Newsroom announcement, Nvidia technical blog (two posts on Open Agent Safety Platform and OpenShell), CocoLoop, IT Home, The Next Web. Verified against the partner organization list, OpenShell's version number and open-source license, and Nvidia's official statements on Sentry's isolation response time.