NVIDIA has introduced Open Agent Safety Platform, an open architecture that pushes AI agent security beyond the model and the application running it. The approach combines OpenShell, an open-source runtime that enforces policies at execution time, with Sentry, a reference design that uses BlueField-4 DPUs to monitor agent activity from an independent layer.
Secure AI agents in 30 seconds
- NVIDIA combines OpenShell and Sentry to control agents from the software layer down to the infrastructure running their tasks.
- OpenShell creates isolated environments and enforces policies on what each agent can do, regardless of the model behind it.
- Sentry adds out-of-band monitoring via BlueField-4, capable of detecting and quarantining agents that step outside their limits.
- The platform already brings together more than 100 organizations, including Anthropic, Microsoft, Cisco, CrowdStrike, SAP, Salesforce, Red Hat, and Palo Alto Networks.
- OpenShell is open source and can be extended to third-party platforms, including Arm- and Intel-based solutions.
The move responds to a question that’s getting harder to ignore: an AI agent doesn’t just generate a response. It can access files, use tools, run code, query services, handle credentials, or interact with enterprise systems. Once it’s given autonomy over hours or days, security based solely on instructions baked into the model stops being enough.
NVIDIA proposes a different architecture. The agent may have the ability to decide what to do, but the infrastructure has to decide what it’s allowed to do. The company places that control outside the model and, with Sentry, outside the execution environment itself.
OpenShell: the Sandbox as the First Line of Defense
The software piece is NVIDIA OpenShell, an open-source runtime built to run autonomous agents inside isolated environments.
Its job is to set a boundary between the agent and the system’s resources. Policies can control things like file access, network connections, or which processes the agent is allowed to run. The intent is for these restrictions not to depend solely on the prompt or the instructions the model receives.
That’s an important distinction. An agent can be told not to access certain credentials, but that instruction lives in the same logical environment where the model makes decisions. OpenShell tries to move the restriction to an external layer that the agent can’t override just by changing its own behavior.
NVIDIA had already folded OpenShell into its software strategy for agents, and it’s now integrating it into a broader security platform. The project is distributed as open source and can be used with either open or proprietary models.
The company also highlights its integration with NVIDIA Vera, its CPU designed for agentic AI workloads. OpenShell isn’t limited to that hardware, though — NVIDIA says the software can be extended to run on third-party platforms, including those based on Arm and Intel.
That separates two concepts that tend to show up together but aren’t the same thing: using OpenShell and using NVIDIA hardware. The former is open software; the latter is part of the infrastructure architecture NVIDIA is proposing.
Sentry Pushes Control Down to the Infrastructure
The most distinctive part of the proposal is NVIDIA Sentry.
Sentry is a reference design for a monitoring system that runs out-of-band via NVIDIA BlueField-4 DPUs. A DPU, or Data Processing Unit, is a specialized processor that offloads and controls certain infrastructure functions, particularly around networking, storage, and security.
In this case, NVIDIA uses that position to create an independent monitoring layer.
Sentry can inspect agent requests and responses, verify their identity, generate telemetry, and enforce access policies for data, tools, application programming interfaces (APIs), and services. The technology relies on NVIDIA DOCA, the company’s software platform for its DPUs.
The company says Sentry can quarantine and stop an agent within milliseconds if it tries to step outside its set limits. That’s a capability NVIDIA describes within its reference architecture, not a guarantee that any malicious behavior will automatically be blocked in every deployment.
The difference from a conventional system lies in where the control runs. Sentry keeps monitoring in a domain separate from the agent, so the agent itself has no direct access to the mechanisms watching it.
The architecture is thus split into two layers:
| Layer | Technology | Function |
|---|---|---|
| Execution | OpenShell | Isolate the agent and enforce policies |
| Hardware | BlueField-4 + Sentry | Monitor and enforce controls out-of-band |
| Infrastructure | DOCA | Program the DPU’s security capabilities |
| Compute | NVIDIA Vera | Run agent workloads |
| Models | Open or proprietary | Provide the AI capabilities |
The idea is that security doesn’t disappear even if the model behind the agent changes.
NVIDIA Wants This to Become a Common Layer for Agents
The announcement comes with a long list of partners. NVIDIA says more than 100 organizations are working with Open Agent Safety Platform technologies, including Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, and ServiceNow.
The collaboration with Anthropic is especially notable because it ties this architecture to Claude Managed Agents. In that setup, the agent loop runs on a server separate from the sandboxes where it carries out its tasks. OpenShell and BlueField add extra controls over access to those environments.
Salesforce is bringing OpenShell to Slack. The integration lets users review activity and audit events, and manage agents’ requests for additional permissions directly from the platform.
SAP, for its part, is incorporating OpenShell into Joule Studio Runtime, within SAP Business AI Platform, while Red Hat is working with OpenShell and DOCA inside its enterprise AI infrastructure.
The project also extends to physical systems. NVIDIA names Figure, Gecko Robotics, and Skild AI among the robotics companies working with OpenShell to add security controls to systems capable of acting in the physical world. In finance, Citi and JPMorganChase appear on the list, while several U.S. energy companies are also collaborating on these technologies.
There’s another relevant piece: NVIDIA is trying to keep this proposal from standing apart from other AI security initiatives. The company places Open Agent Safety Platform within the work of the Open Secure AI Alliance, launched together with more than 120 organizations under the governance of the Linux Foundation. Its stated goal is to share research, tools, and practices related to agent security.
The Challenge: Controlling Agents With Ever-Growing Permissions
The problem NVIDIA is trying to solve isn’t specific to any one model. An enterprise agent can end up connected simultaneously to code repositories, internal systems, databases, productivity tools, external services, and APIs.
The more systems it can use, the larger the surface the infrastructure has to control.
OpenShell sets up a first barrier at the execution environment. Sentry adds another one at a lower level, independent of the agent. That separation means policies don’t depend solely on the model correctly interpreting a security instruction.
It also explains why NVIDIA is trying to bring the proposal to software companies, infrastructure providers, robot makers, and financial organizations. If agents end up as a standard layer for interacting with applications and machines, the controls will need to travel with them regardless of which model they use.
The platform is already available through NVIDIA’s developer resources, while OpenShell can be found on GitHub as an open-source project.
The move places NVIDIA in a position that goes beyond supplying GPUs. The company is also trying to define part of the infrastructure from which agents will carry out their actions and, above all, where the limits will be enforced once the model stops being a simple text generator and starts operating on real systems.
Frequently Asked Questions
What Is NVIDIA Open Agent Safety Platform?
It’s an open NVIDIA platform for controlling AI agent security from execution down to the infrastructure. Its two main components are OpenShell and Sentry.
What Is OpenShell For?
OpenShell creates an execution environment with boundaries and policies for agents. It controls how they interact with system resources and can be used with both open and proprietary models.
What Does Sentry Add?
Sentry adds an out-of-band monitoring layer using NVIDIA BlueField-4 DPUs. According to NVIDIA, it can detect when an agent tries to exceed its limits and quarantine it.
Does OpenShell Depend on an NVIDIA GPU?
Not necessarily. NVIDIA says OpenShell is open source and can be extended to third-party platforms, including Arm and Intel architectures.

