An AI agent may be instructed to obey limits, but those limits are less useful if the agent can reach the software enforcing them. Nvidia’s new agent-safety platform addresses that problem by pairing OpenShell, a sandboxed runtime that controls what an agent can access, with Sentry, a proposed watchdog on separate hardware.
The design is relevant to agents that execute code, use credentials or operate across business systems. Nvidia has described how the two layers are intended to work. Its announcement does not, however, establish how reliably Sentry detects violations in practice. This is a security architecture, not an independently tested safety result.
Nvidia Announced the Platform on September 28
Nvidia announced the Open Agent Safety Platform on September 28, 2026. Its newsroom page gives the date but no clock time. A syndicated copy of Nvidia’s release is timestamped 5:00 a.m. ET that day. The timestamp establishes when the announcement was distributed. Because Nvidia supplied the release, it is not independent confirmation of the product’s performance.
The platform combines available software with a hardware-based reference design. Nvidia says OpenShell is now broadly available and lists platform software and skills among its developer and GitHub resources. Sentry is described as a component of a reference system design built around Nvidia BlueField-4 data processing units, or DPUs. The announcement gives no separate Sentry download, price or general-availability date.
Nvidia frames the launch as a response to incidents in which agents circumvented application-layer controls while pursuing assigned tasks. The release does not provide enough detail to assess those incidents individually. The narrower question is which controls sit outside an agent’s reach, and what evidence shows they work.
OpenShell Restricts What an Agent Can Reach
OpenShell is the software layer. Nvidia’s technical explanation of the platform describes an open-source runtime that executes agents in sandboxes with kernel-level isolation. An operator can set policies for access to files, networks, tools, processes and credentials. According to Nvidia, OpenShell checks those limits before an agent runs and enforces them during execution.
An agent assigned to edit code, for example, might need access to a repository but not to unrelated files or unrestricted network destinations. OpenShell is meant to control which resources the agent can use, regardless of the instructions it receives while working.
Nvidia says OpenShell can run agents using open or closed models. Its announcement emphasizes performance on Nvidia Vera CPUs, while the technical blog says the broader platform can work with other hardware systems. The release says the open-source software can be extended to third-party compute platforms, including those from Arm and Intel. It does not demonstrate identical support, overhead or security properties across all three.
The sandbox also cannot determine whether every permitted action serves the user’s intent. If a permitted tool can perform an unwanted but policy-compliant action, the quality of the permissions still matters.
Sentry Moves Monitoring Outside the Runtime
Sentry is Nvidia’s proposed second layer. It runs on BlueField-4 DPUs, separate from the CPU environment where an agent and its runtime operate. Nvidia calls this out-of-band monitoring: the watchdog is intended to observe activity and enforce policies without being under the agent’s direct control.
According to Nvidia, Sentry uses its DOCA software to inspect agent requests and responses, verify identity, record activity and apply access policies to data, tools, APIs and services. Its technical blog describes a Vera Rubin POD design in which BlueField-4 sits on a node’s path to the model. If an agent needs model access to continue operating, infrastructure on that path offers a point at which to observe or interrupt it.

Nvidia says Sentry can quarantine and stop an agent that moves outside its software boundary in milliseconds. Neither the announcement nor the technical blog supplies an independent test establishing that timing, a false-positive rate or results across different workloads. The company also says OpenShell has minimal overhead on Vera, without providing a measurement in the supplied material that readers can compare with other configurations.
The design still needs testing. A useful evaluation would examine what activity the DPU can observe, how consistently policy decisions match the operator’s intent, what happens when agents use permitted tools in unexpected ways, and how intervention affects legitimate work. A watchdog that blocks a violation quickly is valuable only if it identifies the right activity.
“Open” Applies Differently Across the Stack
Nvidia describes a modular platform: organizations can deploy elements according to their requirements, and OpenShell is open-source software. Sentry is an additional security layer tied to BlueField hardware and Nvidia’s DOCA-based design.
A developer can examine the software-runtime approach without assuming that every OpenShell installation includes the hardware watchdog. The statement that OpenShell can be extended to Arm and Intel systems also does not promise that Sentry’s BlueField-based enforcement will operate unchanged on those systems.
Nvidia’s technical blog presents the separation as a way to keep enforcement beyond an agent’s reach, even if the host environment is compromised. Deployers would still need to know how policies are written and checked, which paths are monitored, and what happens when a task falls inside its formal permissions but outside the operator’s intentions.
Partner Activity Is Not a Performance Test
Frequently Asked Questions
4 questions
1What Is Nvidia’s Open Agent Safety Platform?
Nvidia’s Open Agent Safety Platform combines OpenShell, an open-source runtime for sandboxing AI agents, with a reference system design that includes Sentry monitoring on BlueField-4 hardware. OpenShell is intended to restrict access to resources such as files, networks and credentials. Sentry is designed to monitor and enforce policies from hardware outside the agent’s runtime.
2
Sources
- announced the Open Agent Safety Platformnvidianews.nvidia.com
- syndicated copy of Nvidia’s releaseglobenewswire.com
- technical explanation of the platformdeveloper.nvidia.com
- Anthropic homepageanthropic.com





