Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for NVIDIA Agent Safety Platform: How OpenShell and Sentry Work

NVIDIA Agent Safety Platform: How OpenShell and Sentry Work

NVIDIA’s Open Agent Safety Platform pairs open-source OpenShell with a Sentry watchdog that can quarantine agents in milliseconds. 100+ partners join.

Kai Aegis
Kai Aegis★Sep 28, 2026★3 min read

The NVIDIA Open Agent Safety Platform, announced on September 28, 2026, is a reference design for keeping autonomous AI agents inside the boundaries their operators set. It combines open-source runtime software with a hardware watchdog that sits outside the agent's reach, and NVIDIA says more than 100 organizations are collaborating on it.

  • OpenShell is open-source runtime software that enforces boundaries for agents running on CPUs.
  • Sentry is an out-of-band watchdog that can quarantine a misbehaving agent within milliseconds.
  • Sentry runs on the BlueField-4 DPU; OpenShell targets NVIDIA Vera and is extendable to Arm and Intel.
  • Named partners include Anthropic, Cisco, Microsoft, Salesforce, SAP and Scale AI.

What problem does the NVIDIA Open Agent Safety Platform solve?

Agents do more than answer questions. They run code, call tools and change systems. That makes containment a core AI security concern: if an agent is manipulated or simply makes a mistake, the damage should stay inside a well-defined box. Our look at AI agent sandbox design lessons described the same principle from the research side. NVIDIA's platform turns it into a layered reference architecture.

How OpenShell enforces agent boundaries

OpenShell is the software layer. It provides a secure runtime that constrains what an agent can reach while it executes on a CPU. NVIDIA positions its Vera processor as the purpose-built home for agent workloads, but says OpenShell is open source and can be extended to Arm and Intel platforms. NVIDIA describes OpenShell as broadly available, which lets security teams evaluate it without buying new hardware.

Why run Sentry outside the agent?

The more distinctive piece is Sentry. It watches agent behavior from a separate processor, the BlueField-4 data processing unit, rather than from inside the same software stack the agent uses. That out-of-band position matters: a compromised agent cannot easily switch off a monitor it cannot see or reach. When Sentry detects behavior outside policy, NVIDIA says it can quarantine the agent within milliseconds.

Security engineers will recognize the pattern from hardware roots of trust and baseboard management controllers. NVIDIA's developer blog describes this as continuous, in-silicon agent monitoring, applying the same separation to AI agents.

Who is backing the agent safety platform?

NVIDIA lists more than 20 initial named partners among the 100-plus organizations involved, spanning model developers, security vendors and enterprise software makers. NVIDIA presents the effort as a shared reference architecture rather than a single closed product. In NVIDIA's announcement, CEO Jensen Huang said realizing AI's potential requires solving AI safety, and that the platform lets the industry share best practices and align on evaluation methods.

What should security teams do next?

For teams piloting agents, OpenShell is the practical starting point: it is open source and does not require new silicon. The Sentry watchdog is the longer-term piece for data centers adopting BlueField-4. Either way, the design gives defenders a clear vocabulary for layering runtime limits with independent monitoring.

Sources: NVIDIA Newsroom: Open Agent Safety Platform — September 28, 2026; SecurityWeek: Nvidia unveils AI agent safety platform with hardware-based watchdog — September 28, 2026; Help Net Security: NVIDIA Open Agent Safety Platform — September 28, 2026; NVIDIA Technical Blog: a reference for continuous in-silicon agent monitoring — September 28, 2026.

More Ai Security Stories