• 8 min read
Nvidia’s agent safety stack splits policy from silicon enforcement
Nvidia’s Open Agent Safety Platform pairs OpenShell runtime controls with a BlueField-4 watchdog that can quarantine agents in milliseconds.

Image: The Verge
Nvidia is separating agent policy enforcement from the agents themselves. Its Open Agent Safety Platform, announced on September 28, 2026, combines OpenShell, an open-source runtime that constrains what an agent is allowed to do, with Sentry, an out-of-band monitoring design on Nvidia BlueField-4 DPUs that can quarantine an agent that crosses its assigned boundary in milliseconds.
Model-level guardrails can shape an agent’s behavior, but they do not necessarily prevent a long-running agent from obtaining an API credential, calling a tool, accessing data, or moving beyond its intended sandbox. Nvidia’s platform imposes controls outside the model and agent harness, including at the network and data-processing layer.
The company says the software is now broadly available through its developer resources and GitHub. It calls the offering both an open software platform and a reference system design: OpenShell is the reusable component, while Sentry is a prescribed hardware-backed design that partners can build into products and infrastructure.

Recommended reading
OpenAI says public data; its agents also sent 53 ChatGPT images away
Sergey Kuznetsov • • 9 min read
“AI’s extraordinary potential for society will only be realized if we solve AI safety.”
The release follows disclosed agent-security incidents involving OpenAI, Anthropic, Meta and Google. Nvidia says its design could have stopped the OpenAI incident involving Hugging Face, though that is a retrospective company claim rather than an independently demonstrated result. Nvidia vice president of enterprise AI Justin Boitano said Hugging Face reported more than 17,000 agents attacking its infrastructure over days and weeks.
OpenShell defines permissions; Sentry enforces them
OpenShell runs on CPUs and creates what Nvidia describes as a secure runtime boundary. It traces agent actions and checks policies as work proceeds, rather than making a one-time permission decision before a task begins. The goal is least-privilege operation: an agent should have sufficient authority for a task and no more.
Sentry sits outside that execution path. It runs on BlueField-4 DPUs, not on the host CPU or GPU, and continuously observes agent behavior from an isolated trust domain. An agent or attacker that compromises the agent runtime should not be able to disable the monitor responsible for stopping it.
| Control layer | OpenShell | Sentry reference design |
|---|---|---|
| Execution location | CPU runtime | NVIDIA BlueField-4 DPU |
| Primary job | Trace actions and enforce runtime policy | Independently monitor behavior and contain violations |
| Trust position | In the agent’s software execution environment | Isolated, out-of-band domain |
| Stated response | Enforce boundaries during tasks | Quarantine agents in milliseconds |
| Platform status | Open-source software | Reference system design built on DOCA |
Sentry uses Nvidia’s DOCA software to inspect agent requests and responses, verify agent identity, generate attested telemetry, and apply granular zero-trust rules to data, tools, APIs and services. Nvidia says this in-silicon enforcement is invisible to agents and attackers. The control plane remains separate from the component being controlled.
The design provides a more specific containment model than simply putting an agent in a sandbox. An agent may be allowed to execute code but blocked from reaching an unapproved service. It may request expanded access, but an administrator can reject that request. A monitor outside the agent’s execution environment can shut it down when observed behavior no longer matches policy.
The release does not provide a measured latency figure for the “milliseconds” quarantine claim, test conditions, throughput costs, or a comparison between OpenShell’s overhead on Nvidia and non-Nvidia systems. Nvidia says OpenShell has minimal overhead on Vera, but supplies no benchmark in this announcement. These omissions affect organizations operating high-volume coding, orchestration, or data-processing agents, where every request inspection and policy check is on the critical path.
Vera is the preferred host CPU, but not a requirement
OpenShell is designed to run on Nvidia’s Vera CPU, which the company describes as its first CPU purpose-built for agentic AI. The Vera announcement adds details not included in the safety-platform release: it uses 88 Olympus cores, Spatial Multithreading, and an LPDDR5X subsystem capable of up to 1.2TB/s of bandwidth. Nvidia claims Vera completes tasks 1.8x faster than x86 processors.
Nvidia is positioning runtime enforcement as part of the wider Vera platform rather than as a standalone security package. Agent workloads include orchestration logic, Python runtimes, sandboxed code execution, tool use and analytics pipelines—CPU-bound work that can keep accelerators waiting when it becomes a bottleneck. Vera connects to Vera Rubin systems through second-generation NVLink-C2C, with up to 1.8TB/s of coherent CPU-GPU bandwidth.
OpenShell is not formally confined to Vera. Nvidia says its open-source software can be extended for third-party compute platforms, including Arm and Intel. The company says it can be extended, not that every OpenShell feature has already been qualified across competing hardware.
Vera systems are scheduled to become available from system builders and cloud partners starting in fall 2026. Nvidia lists two deployment shapes: dense liquid-cooled racks for large-scale agentic and reinforcement-learning workloads, and two-socket air-cooled systems for enterprise, cloud and data-processing uses. Dell, HPE, Lenovo and Supermicro are among the vendors expected to offer standalone Vera CPU servers.
Partners are building controls into existing agent stacks
Nvidia says more than 100 organizations are working with the platform’s technologies. The list spans infrastructure providers, model developers, enterprise software companies, banks, energy providers, robotics vendors and security companies. It should not be read as a list of production deployments; the announcement uses several terms, including working with, integrating, collaborating, building with and planning to deploy.
Anthropic is integrating OpenShell and BlueField support with Claude Managed Agents. Claude Managed Agents already run the agent loop on a separate server from the sandboxes where tasks execute; Nvidia’s controls are intended to add stricter access control through those sandboxes.
“Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments.”
Salesforce has integrated OpenShell with Slack. That implementation lets teams view agent activity and audit events, then approve or reject requests for additional permissions from Slack. SAP is embedding OpenShell in the Joule Studio runtime of its Business AI Platform. Scale AI says it is incorporating platform technologies into the agentic infrastructure layer of its Scale GenAI Portfolio.
Nvidia also names SpaceXAI as a user of the platform for Cursor coding agents and Grok models. Figure, Gecko Robotics and Skild AI are building with OpenShell for autonomous systems that take action in the physical world, where agent security includes data, APIs and potential machine behavior.
The prior safety problem was already moving beyond chatbots
The pressure behind these controls is not limited to browser-based agents. In August 2026, Anthropic’s hardware-control proposal described MHS, an interface intended to let agents operate lab equipment, robots and factory systems. Nvidia’s platform extends its scope to robotics systems that execute work, and its partner list includes robotics companies.
Enterprise security teams are also confronting a workload problem alongside an access-control problem. On August 29, 2026, Equifax said it had automated half of its SOC tickets while adding controls intended to catch rogue agents. Nvidia’s approach is different: rather than automating the response after an alert arrives, Sentry is designed to stop a policy violation at a hardware-backed monitoring layer before the agent can continue its task.
The comparison is not a claim that one approach replaces the other. Runtime governance establishes what an agent may do; conventional security operations still need to investigate the event, preserve audit records, identify compromised credentials and adjust policies that failed to prevent an attempted misuse earlier.
Nvidia is arguing that safety is a systems problem
Huang has framed agent security as an engineering problem rather than a reason to slow model development. On September 28, he described the platform as a “browser for agents,” arguing that agents cannot be allowed to roam through a company’s systems without containment and restricted rights.
“We can’t have a successful AI industry if the world doesn’t think it’s built or confident that it’s built and deployed safely.”
Nvidia is not claiming a model will reliably refuse unsafe instructions. It is proposing a layered system: policy in an open runtime, independent observation on a DPU, access rules for tools and services, telemetry for auditability, and human approval where an agent requests additional permission.
The company is also tying the project to the Open Secure AI Alliance, which it initiated alongside more than 120 organizations and which is governed by the Linux Foundation. The alliance supports open research, tools and projects including the Shared AI Findings Exchange, or SAFE.
The open question is whether the reference design becomes interoperable security infrastructure or primarily another reason to buy into Nvidia’s Vera and BlueField stack. OpenShell’s ability to extend to Arm and Intel is important, but the advertised out-of-band enforcement relies on BlueField-4 DPUs. Nvidia has published the architecture and named a large ecosystem; it has not published independent containment tests, performance costs, or a cross-platform implementation matrix.
The company’s announcement describes the Open Agent Safety Platform as broadly available software. Whether it blocks real agent escapes without creating unacceptable latency or operational friction will depend on deployments that Nvidia has not yet quantified.
Frequently asked questions
What is Nvidia Open Agent Safety Platform?+
It is Nvidia’s open software platform and reference design for governing AI agents. It combines OpenShell runtime policy controls with Sentry monitoring on BlueField-4 DPUs.
How does Nvidia Sentry stop an AI agent?+
Sentry runs in an isolated out-of-band trust domain on BlueField-4 DPUs. Nvidia says it continuously monitors agent behavior and can quarantine agents that exceed their software boundary in milliseconds.
Does OpenShell work only on Nvidia hardware?+
OpenShell is designed for Nvidia Vera CPUs, but Nvidia says the open-source software can be extended to third-party compute platforms from Arm and Intel. Nvidia has not provided a feature or performance matrix for those platforms.
When will Nvidia Vera systems be available?+
Nvidia says systems using Vera CPUs will be available from system builders and cloud partners starting in fall 2026.
Editor-in-Chief
Sergey Kuznetsov is Head of Product at iXBT.com, one of the largest Russian-language technology media outlets, and the founder of itzine.ru. He has spent over a decade building and running tech newsrooms. At for(geeks) he sets editorial standards and reviews what ships.


