“More than 100 organizations are working with the Open Agent Safety Platform, including Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce and ServiceNow.”
Why NVIDIA built a two-layer safety approach
NVIDIA announced on September 28 that it has launched an Open Agent Safety Platform designed to place enforceable controls around autonomous AI systems from testing through deployment. The company said the platform was developed to address incidents in which AI agents have bypassed application-layer controls while carrying out assigned tasks, and that it combines software controls with monitoring at the hardware and compute layers rather than relying on the model or agent harness alone.
The announcement positions the platform as a layered safety architecture: a software runtime that controls and records agent actions, paired with an optional hardware watchdog that can act independently and at line speed.
OpenShell: a runtime boundary that records and enforces
OpenShell is the platform’s open-source runtime that NVIDIA said provides a security boundary for agents running on CPUs. According to the company, OpenShell controls agents’ access to systems, data and services while recording their actions. NVIDIA said the software is now broadly available as open source and can be extended to third‑party compute platforms from Arm and Intel.
Technically, NVIDIA described OpenShell as combining sandboxed execution, controlled service access and credential management with policy enforcement. A supervisor paired with each OpenShell sandbox checks outbound requests against policy, while the sandbox applies kernel-level filesystem and process controls to the agent workload. NVIDIA also said OpenShell can provide human oversight for agent activity; Salesforce, for example, has integrated it with Slack so users can review activity and audit events and approve or reject requests for additional permissions.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildSentry: BlueField-4 DPUs as an out-of-band watchdog
Sentry is the platform’s optional hardware enforcement layer. NVIDIA said Sentry uses BlueField-4 data processing units (DPUs) as an out-of-band watchdog that continuously monitors agent behavior from an isolated trust domain and can quarantine or stop an agent that moves beyond its permitted boundaries in milliseconds.
NVIDIA framed Sentry as operating independently of the agent itself: it applies agent governance controls to requests involving data, tools, APIs and services and provides “a separate enforcement layer that remains outside the agent's software environment.” The company emphasized the hardware layer’s role in providing enforcement that cannot be bypassed by software-level compromises of the agent harness.
Adoption and integrations: named partners and use cases
NVIDIA said more than 100 organizations are working with the Open Agent Safety Platform. The company named Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce and ServiceNow among those partners. NVIDIA also said organizations in financial services, energy and robotics are working with the technology, including on systems that can act in the physical world.
The company added that Open Agent Safety Platform software, including OpenShell and related skills, is available through its developer resources and GitHub, signaling an intent to invite wider integration and inspection by third parties.
What this means for technologists, financial services, and robotics
- Technologists and security teams: NVIDIA’s runtime plus hardware-enforced approach gives teams a mechanism to trace agent activity, enforce policies at kernel level, and add an out-of-band watchdog that can quarantine misbehaving agents in milliseconds.
- Financial services: Organizations in this sector — cited by NVIDIA as early users — can apply OpenShell’s policy checks and Sentry’s independent enforcement where agents access sensitive data or execute transactions.
- Energy and robotics: NVIDIA said organizations in energy and robotics are working with the platform for systems that can act in the physical world, where rapid autonomous behavior and access to infrastructure or actuators raise distinct safety and governance concerns.
The launch arrives amid growing concern about autonomous agent behavior: NVIDIA noted the platform in part responds to cases where agents bypass application-layer protections, and the company’s release referenced guidance from the UK’s National Cyber Security Centre that warned agents can have broad access to systems, data and tools and that rapid autonomous activity can make unexpected behavior harder to detect.
NVIDIA’s package is explicit about layering controls: an open-source runtime to constrain and record what an agent tries to do, plus an optional hardware monitor that sits outside the agent’s software stack and can act independently. The immediate questions left on the table are pragmatic: which deployments will pair OpenShell with Sentry’s BlueField-4 enforcement, and whether organizations building agents that interact with the physical world will adopt the hardware layer at scale to gain millisecond quarantine capability.
Original story: https://www.infosecurity-magazine.com/news/nvidia-open-platform-secure/




