Nvidia launches the Open Agent Safety Platform to contain rogue AI agents
Nvidia pairs open-source OpenShell sandboxes with a BlueField-4 hardware watchdog called Sentry that can quarantine misbehaving agents in milliseconds.

Nvidia announced the Open Agent Safety Platform on September 28, an open software platform plus a reference system design for controlling AI agents from testing to deployment. It has two main parts.
OpenShell and Sentry
- OpenShell is open-source runtime software that sets a secure boundary around an agent. It traces all actions and enforces policy while the agent runs, and Nvidia says it adds minimal overhead on its Vera CPUs. Because it is open source, it can be extended to third-party compute from Arm and Intel.
- Sentry is a reference design built around an out-of-band watchdog that runs on Nvidia BlueField-4 DPUs. It monitors agent behavior from a separate trust domain that the agent cannot see, and if an agent tries to leave its software boundary, Sentry quarantines it in milliseconds.
OpenShell is now broadly available through Nvidia's developer resources and GitHub.
Who is involved
Nvidia says more than 100 organizations are working with the technology. The launch partner list includes Anthropic, Cisco, CrowdStrike, Dell, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, ServiceNow and SpaceXAI. Salesforce has integrated OpenShell with Slack so teams can approve or reject permission requests from agents.
Nvidia's reasoning is that recent incidents followed the same pattern: the agent got around application-layer security controls to finish its task. Its answer is to enforce limits outside the model and outside the agent harness. The BBC reported that Nvidia says the tools could have prevented the Hugging Face breach, though that is Nvidia's claim, not an independent finding.
Why it matters
Until now, most agent safety lived inside the same software the agent could touch. Putting an enforcement layer in separate hardware is a different approach, and it comes from the company that sells the chips most agents run on. If the ecosystem adopts it, it could become a default for enterprises that need audit trails.
Dany's take
The idea of a watchdog the agent cannot see is smart, because a boundary the agent can edit is not a boundary. The catch is that it is Nvidia hardware first, so it also happens to sell Nvidia hardware. I like that OpenShell is open source. I would still want independent tests before treating "stops it in milliseconds" as proven.
Source: nvidianews.nvidia.com