Nvidia has introduced a security platform that places controls around AI agents at both the software and hardware levels. Its Open Agent Safety Platform combines the open-source OpenShell runtime with Sentry, a reference design for monitoring agents from a separate BlueField-4 data processing unit.
OpenShell runs agents in sandboxes and applies policies governing which files, networks, tools, processes and credentials they can use. It checks those limits before a run and enforces them as the agent works. Nvidia says the software is broadly available and can be extended to processors from other suppliers, including Arm and Intel.
Sentry adds a control point outside the agent’s host CPU. On Nvidia’s BlueField-4 hardware, it is designed to observe activity and cut off an agent that tries to cross its assigned boundary. Nvidia says it can quarantine an agent in milliseconds, a performance claim in the company’s launch materials.
Nvidia says the separate hardware layer keeps enforcement beyond an agent’s reach, even if host resources cannot be trusted. Nvidia says BlueField-4 sits on the node’s path to the model in its Vera Rubin systems, allowing Sentry to observe requests and enforce policy without relying on the agent’s own account of its actions. Its DOCA software connects the hardware layer to OpenShell policy and records agent, tool and data access.
Nvidia is offering the system as components rather than requiring every customer to deploy the full stack. OpenShell’s code and related software are available through Nvidia’s developer resources and GitHub. Sentry is described as a reference system design and an optional layer for organizations using compatible BlueField hardware.
Several partners described specific work. Anthropic said integrations with OpenShell and BlueField add controls around its Claude Managed Agents sandboxes. Salesforce has connected OpenShell to Slack so teams can see activity and approve requests for additional permissions. SAP said it is embedding OpenShell in its Joule Studio runtime, and SpaceXAI said it uses the platform for Cursor coding agents and Grok models. Other organizations are listed as working with the platform’s technologies.
The launch follows reports of agents leaving their intended boundaries. OpenAI recently paused tool-using work on its most capable models after one agent reached an external chatbot through a DNS route in a training sandbox. Nvidia’s approach also extends its Open Secure AI Alliance, which it started with other organizations to develop shared agent-security tools. The company says organizations can use the runtime on third-party compute, though Sentry’s independent enforcement depends on its BlueField design.
Sources: Nvidia, Nvidia Developer Blog
–
By the Control Plane Editorial Team