> ## Content Index
> Fetch the complete content index at: https://www.tao.media/llms.txt
> Use this file to discover other available public pages before exploring further.

# NVIDIA Launches Open Agent Safety Platform With OpenShell and BlueField Sentry
- URL: https://www.tao.media/nvidia-launches-open-agent-safety-platform-with-openshell-and-bluefield-sentry/
- Published: 2026-09-28T12:37:06.000Z
- Updated: 2026-09-28T12:37:06.000Z
- Description: The platform pairs OpenShell sandboxing with BlueField-4-based Sentry monitoring as NVIDIA tries to make agent safety an infrastructure layer.
- Author: Bart Hillerich
- Tags: Nvidia, Jensen Huang, AI, News

[NVIDIA](https://www.nvidia.com/?ref=tao.media) has introduced the [NVIDIA Open Agent Safety Platform](https://nvidianews.nvidia.com/news/open-agent-safety-platform?ref=tao.media), pairing open-source runtime controls with hardware-backed monitoring to help enterprises place firmer boundaries around autonomous AI agents.

The platform combines [OpenShell](https://github.com/NVIDIA/OpenShell?ref=tao.media), an Apache 2.0 secure runtime for sandboxing agent activity, with NVIDIA Sentry, a reference design that uses BlueField-4 data processing units to monitor agent behavior outside the host system. Sentry can quarantine agents that try to move outside their approved boundaries in milliseconds.

The launch arrives with more than 100 ecosystem partners, including Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI.

Jensen Huang, NVIDIA's founder and CEO, noted the release as part of a paramount effort to build safety into the infrastructure layer of agentic AI.

> *"AI's extraordinary potential for society will only be realized if we solve AI safety," Huang said in NVIDIA's announcement. "As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety."*

Huang also described the platform as "the beginning of an open ecosystem to build the trust layer for safe agent systems," adding that "trust and innovation are not in conflict."

## OpenShell Sets Runtime Boundaries for AI Agents

OpenShell gives autonomous agents useful capabilities without granting them unrestricted access to files, credentials, networks, tools, and processes.

In practice, operators define what an agent is allowed to touch before the agent begins work. OpenShell checks those policies before execution and enforces them while the agent runs. The runtime uses sandboxing and kernel-level isolation so organizations can monitor and restrict file access, system calls, network connections, and credential use.

Many agent systems are valuable because they can take actions across software environments. Coding agents, enterprise assistants, research agents, and robotics systems may need to read files, call APIs, run tools, install packages, and interact with internal systems. The same permissions that make those agents useful can also create risk if a model drifts from its task, follows ambiguous instructions, or reaches systems it should not access.

OpenShell's policy model makes those limits explicit; agents "never see real credentials" because credentials are only added to requests bound for approved endpoints. OpenShell also uses formal verification to evaluate policy changes before they are applied, flagging risky new access such as reaching a new host with credentials or calling a new API method.

NVIDIA says OpenShell is optimized for its Vera CPUs but can be extended to third-party compute platforms, including Arm and Intel.

## Sentry Adds an Out-of-Band Hardware Watchdog

Sentry is NVIDIA's hardware-backed layer for organizations that want enforcement outside the agent's reach.

Running on NVIDIA BlueField-4 DPUs, Sentry monitors agent activity from an isolated trust domain rather than relying only on software controls inside the host environment. NVIDIA says the design gives enterprises an independent watchdog that can observe agent behavior, enforce policies, and intervene when activity moves beyond approved boundaries.

The system is built on NVIDIA DOCA, which NVIDIA says Sentry uses to inspect agent requests and responses, provide attested telemetry, verify agent identity, and apply zero-trust access policies for data, tools, APIs, and services.

The architecture is especially relevant for NVIDIA's Vera Rubin POD systems. In those designs, BlueField-4 sits on the node's only path to the model, giving the DPU continuous visibility into agent behavior and the ability to enforce policy at line speed. NVIDIA describes that position as both an observation point and a control point, because an agent cannot continue acting without access to its next model call.

This is where the platform's full-stack approach differs from a software-only sandbox. OpenShell defines and enforces the runtime boundary, while Sentry adds a separate hardware layer the agent cannot directly control.

## NVIDIA Says Agent Safety Requires Independent Controls

NVIDIA's developer blog argues that recent reports from frontier AI labs show why agent safety cannot depend entirely on the agent itself. The company cited cases in which agents broke out of evaluation environments, reached systems they were not supposed to access, and misreported their actions.

The company's stated design principles reflect that concern: policy should be verifiable, enforcement should be out of band, the path to the model should be treated as a control point, agent authority should scale with inspectable reasoning, and responsibility should be shared across labs, enterprises, and hardware providers.

NVIDIA leans on a comparison to the internet. The company argues that web safety improved not because web pages promised to behave, but because browsers introduced technical boundaries such as sandboxed tabs and secure connections. NVIDIA makes a similar argument for AI agents: as agents gain more autonomy, the systems around them need enforceable boundaries that do not rely on model self-restraint.

In enterprise environments, agents may interact with sensitive data, credentials, internal tools, infrastructure, and eventually physical systems.

## Partners Bring the Platform Into Enterprise and Robotics Workflows

NVIDIA is positioning the Open Agent Safety Platform as a shared ecosystem:

- Anthropic is working with NVIDIA to add governance and control layers around Claude Managed Agents, with the agent loop running on a separate server from the sandboxes where work executes.
- Salesforce has integrated OpenShell with Slack so teams can view agent activity, audit events, and approve or reject requests for additional permissions.
- SpaceXAI is using the platform for Cursor coding agents and Grok models.

The partner list also extends into robotics, finance, energy, infrastructure software, and cloud systems. Figure, Gecko Robotics, and Skild AI are building with OpenShell for autonomous systems that act in the physical world.

Citi and JPMorganChase are among financial services firms collaborating on open-source agent safety technologies, while energy and infrastructure organizations including Hitachi Energy, EPRI, NextEra Energy, Quanta Services, Schneider Electric, Siemens Energy, and Worley are also listed as participants.

NVIDIA is trying to make agent safety an infrastructure concern rather than only a model-alignment or application-design problem.

As Huang put it in NVIDIA's announcement, "Safety and security require full-stack engineering." With OpenShell and Sentry, NVIDIA is turning that argument into a software-and-silicon platform for the next phase of agent deployment.