NVIDIA’s new Open Agent Safety Platform has two different starting points. OpenShell is broadly available software for running AI agents inside policy-controlled sandboxes. Sentry is a reference design for an additional watchdog on BlueField-4 hardware. They should not be treated as equally deployable today.
In its September 28 announcement, NVIDIA says the platform can help organizations contain long-running agents and quarantine those that cross defined boundaries. A coding or enterprise agent may work for hours, use several tools and encounter instructions its operator never intended it to follow. The announcement does not establish that isolation and quarantine will prevent every harmful action, or independently validate the claimed speed of intervention in field use.
OpenShell Is the Part Developers Can Use Now
OpenShell is an open-source runtime, licensed under Apache 2.0, that runs agents in sandboxes with kernel-level isolation, according to NVIDIA’s technical description. Operators can define which files, networks, tools, processes and credentials an agent may access. NVIDIA says the runtime checks those limits before execution, enforces them while the agent works and records activity for review.
The boundary sits outside the model’s own instructions. Telling an agent not to read a private directory depends on its behavior; denying its sandbox access to that directory is an infrastructure control. That distinction becomes useful when an agent encounters a malicious instruction in a repository, web page or document, or simply tries an unintended way to finish an authorized task.
NVIDIA says OpenShell works with agents using open or closed models. It promotes low overhead on its Vera CPUs and says the open-source software can be extended to third-party compute platforms, including those from Arm and Intel. “Can be extended” is not the same as a verified promise of identical behavior on every machine. Teams considering another platform should check its supported configuration and test the boundaries they intend to rely on.
The immediate development task is less glamorous than installing a safety label: specify the permissions an agent actually needs. A coding agent might need to read one repository and run tests while having no reason to access production credentials. An enterprise agent might need a narrowly scoped application interface rather than unrestricted network access. OpenShell offers a place to enforce those distinctions, but the operator still has to draw them correctly.
Sentry Adds a Separate Control Point
Sentry is NVIDIA’s proposed hardware-backed layer. In the Open Agent Safety Platform reference design, it runs on a BlueField-4 data processing unit, or DPU, separate from the host running the agent. NVIDIA describes it as an out-of-band monitor that can apply policy even if the agent’s host environment cannot be trusted.
NVIDIA says its DOCA software connects that hardware layer to OpenShell policy. The proposed system can correlate agent interactions, policy decisions and access to tools or data; inspect requests and responses; and check agent identity and delegated authority. In NVIDIA’s Vera Rubin POD design, the company says BlueField-4 sits on a node’s only path to the model. That placement could make model traffic an effective point for observation and interruption in that architecture. It should not be assumed for every agent deployment.
The company claims Sentry can quarantine and stop an agent in milliseconds if it moves outside its software boundary. That is a vendor claim, not an independently established field result. The cited launch materials do not show how often the system correctly detects a violation, how it handles false alarms, or how quarantine performs across varied agent workloads.
Blocking a subsequent model request also cannot necessarily undo an action already completed. If an agent has sent data to an allowed destination or made an authorized but mistaken change, a fast kill switch cannot reverse that event. Sentry’s potential advantage is an enforcement point the agent cannot readily alter from its own sandbox. Its effectiveness still depends on which paths the hardware can observe, what the policy forbids and when the system recognizes a problem.
NVIDIA presents Sentry as part of a reference system design and OpenShell as broadly available software. Its technical blog says organizations already running a Vera system with BlueField-4 could enable the described protections through a software update. That specific scenario is not a general availability statement for Sentry across enterprise hardware.
Boundaries Cannot Define a Good Decision
Sandboxing and hardware monitoring address different failure modes from model training or task review. They can restrict reachable resources and provide evidence about attempted access. They cannot, by themselves, decide whether every action inside an agent’s permitted scope is wise.
Consider an agent allowed to edit and deploy a particular application. If it makes a damaging change using those authorized tools, an access policy may see no boundary violation. An agent permitted to send information to a business system could also send the wrong information without attempting to reach a prohibited service. Detecting those mistakes requires controls suited to the task, such as limited authority, approvals for consequential actions and review of what the agent produced.
An agent may also need additional access to finish legitimate work. NVIDIA says its OpenShell integration with Slack lets teams view activity and approve or reject requests for more permissions. That gives a human a decision point, but makes the quality and timing of approval part of the security system. An operator who routinely approves broad requests can weaken an otherwise sound boundary.

NVIDIA’s emphasis on agents that run for days or weeks is well placed. More time and more available tools create more opportunities for an agent to encounter an unexpected situation. A durable runtime policy could limit what happens next. It is not evidence that every unsafe deviation will look like a forbidden file read, network call or model request.
What Would Demonstrate the Protection
For teams assessing the platform, the useful question is which threats each layer catches that existing controls would miss.
A meaningful evaluation would try agent workloads with restricted files, credentials and network destinations, then check whether OpenShell blocks access and records the attempt. It would also test actions within the allowed scope, including mistaken tool use, to establish where policy enforcement stops helping. For Sentry, the tests would need to show what it can observe from its hardware position, how quickly it intervenes and whether an agent can act through an unmonitored path.
Frequently Asked Questions
4 questions
1Is NVIDIA OpenShell Available Now?
Yes. NVIDIA describes OpenShell as broadly available, open-source software for running AI agents in policy-controlled sandboxes. Operators can define access to files, networks, tools, processes and credentials. NVIDIA says OpenShell enforces those limits and records agent activity, but teams should test the configuration and hardware they plan to use.
2
Sources
- September 28 announcementnvidianews.nvidia.com
- OpenShelldeveloper.nvidia.com
- Hacker News discussionnews.ycombinator.com
- launch releaseglobenewswire.com





