
Nvidia has introduced the Open Agent Safety Platform, an open software platform and reference architecture intended to control autonomous AI agents from evaluation through production deployment. The system combines an open-source secure runtime called OpenShell with Nvidia Sentry, an independent monitoring and enforcement design built around BlueField-4 data-processing units.
OpenShell establishes a runtime boundary outside the agent model and application harness. Agents operate inside isolated sandboxes without unrestricted network access, while policies govern the files, credentials, tools and external destinations they can reach. System calls and network requests can be monitored and filtered, with actions routed through a controlled gateway.
The platform follows a deny-by-default model under which permissions must be explicitly granted. Its policy-verification component checks whether proposed permissions remain within an authorised access boundary and whether network-policy changes would expose additional resources. Actions that are allowed or blocked are recorded for audit purposes.
OpenShell is optimised for Nvidia’s Vera CPUs but is being released as open-source software that can be extended to third-party computing platforms, including systems based on Arm and Intel technology. Nvidia said the runtime can work with different models, agent frameworks and deployment environments spanning public cloud, private cloud, on-premises infrastructure, edge systems and air-gapped installations.
Sentry provides a second enforcement layer outside the runtime. Designed to run on Nvidia BlueField-4 DPUs, it continuously monitors agent activity from an isolated hardware domain. If an agent attempts to move beyond its authorised software boundary, Sentry is designed to quarantine and stop it within milliseconds. The separation is intended to prevent the agent or an attacker operating through it from disabling the monitoring mechanism.
The architecture covers software agents as well as systems connected to computing infrastructure and robotics. It reflects a shift from relying exclusively on model-level alignment or application instructions to imposing access controls at the operating-environment and hardware layers.
Nvidia identified more than 100 participating organisations across the AI, cybersecurity, enterprise-software, financial-services and public-sector ecosystem. The announced group includes Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI and ServiceNow.
Anthropic is integrating additional controls around managed agents, while Scale AI is incorporating components into infrastructure used for enterprise and government deployments. Nvidia said OpenShell is broadly available; Sentry is presented as a reference system design tied to BlueField-4 hardware.
The platform does not by itself establish that every unsafe or unexpected agent action can be detected. Its effectiveness will depend on policy quality, deployment configuration, observability and the coverage of hardware and software controls. It nevertheless gives enterprises evaluating autonomous agents a defined architecture for limiting authority, recording behaviour and enforcing controls outside the agent process.




