NVIDIA Open Agent Safety Platform launches

NVIDIA logo with OpenShell and Sentry BlueField-4 labels beside NVIDIA's OpenShell AI stack graphic and Anthropic and Microsoft partner marks

/ NVIDIA ships OpenShell and BlueField-4 Sentry to sandbox AI agents outside the model, with 100-plus partners from Anthropic to SpaceXAI at launch.

by Hozefa Khety

· 8 min read

NVIDIA today launched the Open Agent Safety Platform: an open software stack and reference system design meant to put hard boundaries around autonomous AI agents, from testing through production. The pitch is blunt. Recent agent security incidents, NVIDIA says, share one pattern — the agent worked around application-layer controls to finish the job it was given. The company's answer is to move enforcement below the app, into a runtime the agent does not control, and optionally into silicon the agent cannot see.

NVIDIA logo and OpenShell and Sentry BlueField-4 labels beside NVIDIA's official OpenShell AI stack graphic with a hazard-striped safety barrier, plus Anthropic and Microsoft partner marks
NVIDIA's Open Agent Safety Platform pairs the open-source OpenShell runtime with Sentry on BlueField-4 DPUs. More than 100 organizations are listed as working with the platform at launch. (Graphic: The Threshold; OpenShell visual and logos: NVIDIA, Anthropic, Microsoft)

What launched: OpenShell plus Sentry

The platform has two named halves. NVIDIA OpenShell is an open-source secure runtime that sandboxes agents on CPUs, turns operator instructions into verifiable policies, and enforces which files, networks, tools, processes, and credentials an agent can touch. NVIDIA says the boundary sits outside the model and the agent harness, so the same rules apply to open and closed models. OpenShell 0.1.0 is broadly available on GitHub under Apache 2.0, with developer docs and a quickstart published alongside the announcement.

NVIDIA Sentry is the hardware watchdog in the reference design. It runs on NVIDIA BlueField-4 data processing units as an out-of-band monitor: if an agent tries to leave its software boundary, Sentry can quarantine it in milliseconds. Because Sentry lives on the DPU rather than in the host OS, NVIDIA argues it still works even if the agent runtime or host software is compromised. Sentry is built on NVIDIA DOCA for inspecting requests and responses, attested telemetry, agent identity, and zero-trust access to data, tools, APIs, and services.

NVIDIA OpenShell key visual: three AI agent bubbles above a layered translucent tech stack inside a yellow-and-black hazard safety barrier
NVIDIA's OpenShell Controls key visual from the developer launch post: agents above a layered stack, inside a hard safety perimeter. (Image: NVIDIA)

How OpenShell actually gates an agent

The developer blog walks through the runtime shape. An OpenShell Gateway manages many sandboxes and their policies. Each sandbox gets a Supervisor that sits outside the agent workload and checks outbound requests against policy. The Sandbox itself uses kernel-level controls on filesystem and processes, with no network path except through the supervisor. Policies can be specific enough to allow an HTTP read on one API while blocking a write on the same host — useful when an agent can invent its own tools, spawn shells, or hand work to sub-agents.

Credentials are deliberately kept outside the workload. The agent sees a placeholder; the supervisor substitutes the real key only for authorized endpoints. OpenShell also ships a policy prover that uses formal logic to check whether a policy still allows a forbidden action through another tool or generated code — a response to long-horizon cases where agents spent up to two hours trying to talk a reviewer into broader GitHub write access. Policy decisions are logged in an OCSF audit trail.

Diagram of OpenShell Gateway managing three sandboxed agents with policy-allowed connections down to application services for model APIs, data and memory, and remote MCP servers
Official OpenShell architecture: a gateway over sandboxed agents, with only policy-allowed connections to model APIs, data, and remote MCP servers. (Image: NVIDIA)

Vera CPUs, BlueField-4, and what is optional

OpenShell is optimized for NVIDIA Vera, which NVIDIA calls its first purpose-built CPU for agentic AI, and the company claims up to 80% faster sandbox performance versus traditional CPU infrastructure on that stack. OpenShell is also described as extendable to third-party platforms including Arm and Intel. Importantly for buyers who are not buying a full NVIDIA rack: OpenShell does not require BlueField-4. Without the DPU, you still get the software sandbox and policy layer. With BlueField-4, Sentry adds the independent in-silicon monitor.

Supported agent tooling called out on the product page and developer post includes Claude Code, Codex, Pi, Hermes, OpenCode, GitHub Copilot CLI, and OpenClaw, plus custom agents and sandbox images. That puts the launch squarely in the coding-agent and enterprise-automation wave, not only in chatbots.

Diagram showing an agent sending a request with a placeholder key to the OpenShell supervisor, which verifies policy and substitutes the real credential outside the agent workload
How OpenShell handles secrets: the real API key stays outside the agent and is bound only to authorized requests. (Image: NVIDIA)

Who is signing on

NVIDIA lists more than 100 organizations working with the platform at launch. Named partners in the press materials include Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI, among others.

A few integrations are concrete enough to quote. Anthropic's Claude Managed Agents already run the agent loop on a separate server from the sandboxes where work executes; OpenShell and BlueField are positioned as an extra control layer over what those sandboxes can reach. Paul Smith, Anthropic's chief commercial officer, said companies need to "direct and verify what those agents do, especially in sensitive environments." SpaceXAI says it is using the platform for Cursor coding agents and Grok models. Salesforce has integrated OpenShell with Slack so teams can view audit events and approve or reject permission requests from chat. SAP is embedding OpenShell with Joule Studio on its Business AI Platform and contributing engineering work back to the project.

Robotics names in the release include Figure, Gecko Robotics, and Skild AI. On the infrastructure side, Canonical, SUSE, and Red Hat are integrating the stack into OS and AI Factory offerings; cloud and systems partners listed include CoreWeave, Dell, HPE, Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure, Supermicro, and Together AI.

Why this lands now

Jensen Huang framed the launch as full-stack safety work, not a model-only problem: "AI's extraordinary potential for society will only be realized if we solve AI safety," he said in the NVIDIA release. The timing matches a week when agent failures are mainstream news — from storefront lockouts to agents that act in the physical world — and the day before OpenAI's DevDay keynote. NVIDIA is selling the idea that prompts and model safeguards shape what an agent tries to do, while runtime and silicon decide what it is allowed to do.

The software, including OpenShell and related skills, is available now through NVIDIA's developer resources and GitHub. The effort also feeds the Open Secure AI Alliance, which NVIDIA initiated with more than 120 organizations and which is governed by the Linux Foundation, including the Shared AI Findings Exchange (SAFE). Pricing for Sentry-class hardware deployments was not published in the launch materials; OpenShell itself is the open-source entry point.

For enterprises already shipping coding agents, Slack bots, or robotics controllers, the practical takeaway is narrower than the keynote language: you can put a policy boundary outside the model today, audit allow/deny decisions, and optionally add a DPU watchdog that the agent process cannot disable. Whether that becomes the default way agents ship — the way sandboxed browsers became the default for untrusted web code — is the next twelve months of adoption, not a slide.

AINVIDIAOpenShellAI agentsSecurityBlueField-4SentryAnthropicEnterprise AIAgent safety

Frequently asked questions

What is NVIDIA Open Agent Safety Platform?

It is NVIDIA's September 28, 2026 launch of an open software platform and reference system design for governing AI agents. It combines NVIDIA OpenShell, an open-source secure runtime, with NVIDIA Sentry, an out-of-band watchdog that runs on BlueField-4 DPUs.

What is NVIDIA OpenShell?

OpenShell 0.1.0 is an open-source runtime (Apache 2.0) that sandboxes AI agents, enforces file/network/tool/credential policies outside the agent process, and logs decisions. It works with open and closed models and does not require BlueField-4 hardware.

What is NVIDIA Sentry on BlueField-4?

Sentry is the hardware watchdog in the reference design. It runs on NVIDIA BlueField-4 DPUs, monitors agent behavior out of band, and can quarantine an agent in milliseconds if it tries to leave its software boundary — even if the host software is compromised.

Do I need BlueField-4 to use OpenShell?

No. NVIDIA says OpenShell can run on supported local, on-premises, cloud, and Kubernetes setups without BlueField-4. Sentry on BlueField-4 is an optional extra layer of in-silicon enforcement.

Which companies are using the platform?

NVIDIA lists more than 100 organizations at launch, including Anthropic, Microsoft, Salesforce, SAP, Scale AI, SpaceXAI, Red Hat, CrowdStrike, Dell, HPE, and many others across finance, energy, robotics, and cloud infrastructure.

Is OpenShell free and open source?

Yes. OpenShell is available on GitHub under an Apache 2.0 license, with documentation and a quickstart on NVIDIA's developer site. Enterprise hardware deployments that include Sentry and BlueField-4 are separate products; launch materials did not publish a Sentry price.

How is this different from model safety filters?

Model safeguards and prompts influence what an agent attempts. OpenShell and Sentry enforce what it is allowed to do at runtime and, with BlueField-4, in silicon outside the agent and host software.

Related