NVIDIA Open Agent Safety Platform

NVIDIA Open Agent Safety Platform: How It Secures AI Agents 

NVIDIA launched the NVIDIA Open Agent Safety Platform on September 28, 2026, to keep AI agents safe as they get better at working on their own. The platform uses both software and hardware controls to limit what agents can do and access. This is important because AI agents can do more than just give answers. 

For instance, a coding agent can handle source code, files, and tools without needing a person to approve each action. This creates new risks. If a chatbot makes a mistake, it usually just gives a wrong answer. 

But if an autonomous agent makes a mistake, it might change a file or take other actions. NVIDIA’s plan is to add security controls around the agent instead of just trusting the agent to follow its rules. Software limits can control access, and hardware monitoring provides extra safety outside the agent’s environment.

What Is the NVIDIA Open Agent Safety Platform?

The NVIDIA Open Agent Safety Platform is an open platform and reference architecture designed to help organizations deploy AI agents with stronger security controls.

Instead of giving an agent broad access and trusting it to follow instructions, organizations can define what resources it is allowed to use. These controls can cover files, networks, credentials, APIs, tools, and other system resources.

The platform brings together two key technologies:

  • NVIDIA OpenShell: An open-source runtime that creates a controlled environment for AI agents.
  • NVIDIA Sentry: A separate monitoring and enforcement layer that operates on NVIDIA BlueField-4 DPUs.

Together, these components create boundaries around an AI agent and the systems it can interact with.

Why Does AI Agent Safety Matter?

A typical chatbot mainly produces text or other content in response to a prompt. An AI agent can take actions based on its instructions.

For example, a software development agent may edit files, install dependencies, access a repository, or communicate with external services. An enterprise agent might interact with company data or business applications.

That extra capability makes permissions more important. The more systems an agent can reach, the greater the potential impact of an unwanted action.

NVIDIA has pointed to security research and incidents involving agents that can work around controls applied at the application level. Its platform attempts to address this by enforcing some restrictions outside the agent’s own software environment.

The idea is straightforward: an AI agent should not be responsible for deciding whether it is allowed to bypass its own security controls.

How Does NVIDIA OpenShell Work?

NVIDIA OpenShell provides a controlled runtime environment for AI agents. The agent operates inside this environment while policies determine which resources it can access.

Access can be restricted initially and then expanded only when a particular task requires it. This follows a more controlled permission model than giving an agent unrestricted access from the beginning.

OpenShell can manage access to areas such as:

  • Files and system resources
  • Network connections
  • Credentials
  • APIs and external services
  • AI inference requests
  • Agent tools and actions

The system can also keep records of permission decisions, including which requests were allowed or denied. This provides organizations with an audit trail for agent activity.

NVIDIA says OpenShell is designed for different deployment environments, including cloud, hybrid, on-premises, and air-gapped systems.

Another feature is its policy prover, which uses formal methods to check whether security policies stay within defined boundaries.

OpenShell is also designed to work with different AI models and agent frameworks. NVIDIA describes it as model-agnostic and harness-agnostic, meaning it is intended to provide the security layer rather than serve as an agent framework itself.

What Is NVIDIA Sentry?

NVIDIA Sentry provides an additional security layer outside the agent’s runtime.

It operates on NVIDIA BlueField-4 DPUs and is designed to monitor agent activity independently of the software environment in which the agent runs.

According to NVIDIA, Sentry can identify activity that crosses an approved security boundary and quarantine or stop the agent when necessary, with enforcement designed to happen within milliseconds.

This separation is important. If security controls exist only inside an agent’s environment, an agent that behaves unexpectedly could potentially interfere with those controls. An independent monitoring layer gives organizations another point from which to enforce restrictions.

Sentry can also monitor requests and responses, verify identities, collect telemetry, and apply policies involving data, tools, APIs, and services.

NVIDIA OpenShell vs. Sentry

The two technologies have different jobs, but they are designed to work together.

ComponentMain role
OpenShellProvides the controlled runtime and manages permissions
SentryIndependently monitors activity and enforces security policies
TogetherCombine software-based controls with hardware-level enforcement

In simple terms, OpenShell controls the environment where the agent operates, while Sentry provides an additional layer of independent oversight.

Who Is Working With the NVIDIA Agent Safety Platform?

NVIDIA says more than 100 organizations are working with technologies from its Open Agent Safety Platform.

The companies named by NVIDIA include Anthropic, Microsoft, Salesforce, SAP, ServiceNow, CrowdStrike, Palo Alto Networks, Hugging Face, Scale AI, Palantir, and Perplexity.

Several robotics companies, including Figure, Gecko Robotics, and Skild AI, are also using OpenShell for autonomous systems.

The interest makes sense as AI agents move beyond chat interfaces and into areas such as software development, enterprise applications, cybersecurity, infrastructure, financial services, and robotics.

Is NVIDIA Open Agent Safety Platform Open Source?

The entire platform should not be treated as one open-source product. NVIDIA OpenShell is open source, while the wider Open Agent Safety Platform is presented as an open software platform and reference system.

NVIDIA makes OpenShell available through its developer resources and GitHub.

The technology is also intended to support more than NVIDIA’s own computing hardware in some deployments. NVIDIA says OpenShell can be extended to third-party platforms, including Arm and Intel.

What Does NVIDIA’s Platform Mean for AI Agents?

The NVIDIA Open Agent Safety Platform reflects a shift in how companies are approaching AI agent security.

As agents gain more independence, controlling their output is only part of the problem. Organizations also need to consider what an agent can access, which tools it can use, what actions it can perform, and which systems it can reach.

NVIDIA’s approach combines runtime isolation, permission policies, activity monitoring, and hardware-based enforcement. These measures cannot remove every risk associated with autonomous AI, but they can create additional barriers between an agent and the systems it is allowed to use.

For businesses running agents for longer periods or giving them access to sensitive systems, this type of layered security may become increasingly important.

Conclusion

The NVIDIA Open Agent Safety Platform takes a layered approach to securing autonomous AI. OpenShell provides a controlled environment for agents, while Sentry adds independent monitoring and enforcement. As AI agents take on more complex tasks, these kinds of controls can help organizations place clearer limits on what agents are allowed to access and do.

Scroll to Top