An AI agent can follow its assigned task and still reach a system it was never meant to access. Nvidia wants security controls that can stop the agent even when the agent’s own software does not.
On September 28, Nvidia announced the Open Agent Safety Platform, combining its OpenShell software with a reference design for monitoring agents on separate hardware. For IT teams, the practical question is whether those controls can restrict an agent’s access to files, services, and credentials while leaving it enough room to do its job.
OpenShell is broadly available, according to Nvidia. The hardware monitoring component, called Sentry, is part of a reference system design. Nvidia has not provided a separate price or general availability date for Sentry in its announcement.
OpenShell sets the agent’s boundaries
OpenShell runs agents in sandboxes and lets operators define which files, networks, tools, processes, and credentials each agent can use. A supervisor outside the agent’s workload checks outbound requests against those rules. Nvidia says teams can apply the controls to existing agents without rewriting them.
Those boundaries address an enterprise security blind spot: agents can act through accounts and connections that organizations may not govern as closely as employee access. OpenShell is open source and designed to run on Nvidia Vera CPUs, while Nvidia says the software can be extended to other compute platforms, including Arm and Intel.
Sentry watches from separate hardware
Sentry adds a second layer on Nvidia BlueField-4 data processing units. Nvidia says the separate watchdog monitors agent activity and is designed to quarantine an agent within milliseconds if it crosses its software boundary. The company’s technical description says the hardware can connect agent actions, policy decisions, and tool access into an activity record for investigation. These are Nvidia’s stated capabilities; the announcement does not establish how Sentry will perform across a customer’s own workloads.
The hardware design also has a deployment consideration. Sentry’s described monitoring layer uses BlueField-4, while OpenShell can be adopted separately. IT teams already weighing Vera Rubin infrastructure for agentic workloads may want to assess the security design alongside their compute plans.
Nvidia says more than 100 organizations are working with technologies in the platform. Its earlier Open Secure AI Alliance focused on shared approaches to AI security; this announcement gives teams specific software to examine and a hardware design to evaluate. Participation, however, does not mean every organization has deployed both layers.
For IT leaders, the immediate step is to map what each agent is allowed to reach, then test whether OpenShell’s policies enforce those limits in their environment. Sentry is the optional hardware monitoring layer in Nvidia’s reference design for BlueField-4 systems. Buyers still need to verify how the controls work with their own agents, access rules, and incident response needs.
Read more: OpenAI’s pause of a major AI training run after the Hugging Face security incident shows why containing agents during testing has become an urgent concern.