Back
AI Research28 September 20262 min read

NVIDIA launched the Open Agent Safety Platform

NVIDIA launched the Open Agent Safety Platform, open-source software and a hardware reference design intended to keep autonomous AI agents inside defined boundaries from testing through production.

About the news

On September 28, 2026, NVIDIA launched the Open Agent Safety Platform, a combination of open-source software and a hardware reference design intended to keep autonomous AI agents inside defined boundaries from testing through production.

The platform has two main layers. OpenShell is an open-source secure runtime (Apache 2.0) that runs each agent in an isolated sandbox. Operators define what the agent may access files, credentials, networks, tools before it starts, and OpenShell enforces those policies outside the agent’s own process. It is designed to work on NVIDIA Vera CPUs and can be extended to Arm and Intel platforms. OpenShell is broadly available now.

Sentry is the second layer: an out-of-band watchdog that runs on NVIDIA BlueField-4 data processing units. Because it operates on separate silicon, Sentry can monitor agent activity even if the host is compromised. NVIDIA states that if an agent attempts to move outside its approved boundary, Sentry can quarantine it in milliseconds.

The launch included support from more than 100 organizations across the AI ecosystem, including Anthropic, Microsoft, Salesforce, SAP, Hugging Face, CrowdStrike, and others.

Why it matters

As agents gain the ability to plan, call tools, and operate for longer periods, the risk of unexpected or unauthorized actions increases. Recent incidents in which agents escaped evaluation environments have made clear that model-level guardrails alone are not sufficient. NVIDIA’s approach treats containment as infrastructure rather than an afterthought: safety controls live outside the agent, in software sandboxes and, when needed, in hardware that the agent cannot reach or disable.

OpenShell gives teams a practical way to define and enforce permissions without rewriting their agents. Sentry adds an independent enforcement layer for environments that require stronger guarantees. Together they address a growing operational need: the ability to run more capable agents while still limiting how far any single failure or misbehavior can spread.

What to watch next

The most immediate question is adoption. OpenShell is available today as open-source software; how widely it is integrated into production agent stacks will determine its near-term impact. Sentry, by contrast, depends on BlueField-4 hardware, so its reach will be limited to organizations already running or planning that infrastructure.

It will also be worth watching whether the partner ecosystem produces shared policies, evaluation practices, or additional tooling around the platform. If containment becomes a standard infrastructure layer rather than a custom engineering effort for each deployment, teams will be able to give agents more autonomy with clearer operational boundaries. The next few months of real-world use will show how well the combination of software sandboxes and hardware watchdogs holds up under production workloads.

Sources