NVIDIA Launches Open Agent Safety Platform With Runtime and Hardware Controls
OpenShell is broadly available as a policy boundary for agents, while the Sentry design moves monitoring and intervention onto BlueField-4 DPUs.
Edited by Tyronne Panaino
NVIDIA announced the Open Agent Safety Platform on September 28, combining broadly available OpenShell runtime software with a Sentry reference system design for hardware-isolated monitoring. The launch matters to teams deploying long-running agents because it moves important controls outside the model and its application harness, where an agent should not be able to change or evade them.
The official launch announcement describes a layered system rather than a single safety filter. OpenShell traces agent actions and enforces runtime policy, while Sentry uses BlueField-4 data processing units and NVIDIA DOCA to monitor activity from an isolated trust domain. NVIDIA says organizations can adopt the platform components according to their own requirements.
Software boundary leaves the model
OpenShell is the part teams can use as the agent's secure runtime boundary. NVIDIA says the software controls how agents execute tasks across open and closed models, records their actions and applies policies while they run. That separates the permissions an agent receives from the reasoning process deciding what to do next.
The software is designed to run with NVIDIA Vera CPUs, but NVIDIA says its open-source design can extend to third-party compute platforms from Arm and Intel. The company has made OpenShell and related skills available through its developer resources and GitHub. Those points widen the potential deployment surface, although the announcement does not supply a compatibility matrix, migration evidence or independent testing across those systems.
For platform and security teams, the practical delta is an enforceable place to define which files, services, tools and network destinations an agent may reach. A model can still misunderstand a task or select an unsafe action, but the runtime policy can deny the operation and preserve a record for review. That is a stronger operating model than asking the same agent to police itself through instructions alone.
Hardware watchdog sits outside the host
Sentry is NVIDIA's reference design for a second control layer. It runs on BlueField-4 DPUs, monitors agent activity out of band and uses DOCA to inspect requests and responses, provide attested telemetry, verify agent identity and enforce granular access policies. Because the watchdog sits in a hardware-isolated domain, the design aims to keep enforcement beyond the reach of software running on the host.
NVIDIA claims Sentry can quarantine and stop an agent that crosses its software boundary within milliseconds. That timing is a first-party product claim, not an independently reproduced result in the evidence fetched for this article. The announcement also does not publish false-positive rates, coverage limits, comparative overhead or failure cases for the quarantine path.
What changes for deployment teams
The platform gives buyers two separate questions to test. First, does OpenShell express and enforce the permissions their workload actually needs? Second, does a BlueField-backed Sentry deployment observe and interrupt the same boundary violations when host software cannot be trusted? Passing one test would not establish the other.
This distinction also affects procurement. OpenShell's open-source and cross-platform direction could support a wider range of systems, while the hardware watchdog is specifically described around BlueField-4 and DOCA. Teams evaluating the complete design will need to separate what is available as software now from what depends on a particular server, DPU and integration path.
Evidence quality and next checks
The launch is confirmed by NVIDIA's own release, but its effectiveness evidence is still first-party. No independent audit, reproducible adversarial test suite or production incident reduction was included in the fetched source. NVIDIA also describes Sentry as a reference system design, so readers should not treat the platform announcement as proof that every listed ecosystem integration is deployed or generally available.
The next useful checkpoints are public implementation artifacts, documented policy examples, reproducible boundary-crossing tests and measured results for overhead, detection quality and quarantine time. Independent validation across non-NVIDIA compute would also test the breadth of the open-platform claim.
Status
Confirmed. Internal confidence is medium because NVIDIA is the primary authority for the launch and component descriptions, while the safety, timing and deployment claims were not independently reproduced in this run.
Sources
Update note: Last reviewed 2026-09-29. We will revise this post if NVIDIA publishes implementation evidence or independent testing evaluates the controls.
Sources
- NVIDIA — Open Agent Safety Platform launch — official
Drafted with AI assistance from source briefs; reviewed for citation completeness and label accuracy.