Nvidia Launches Open Agent Safety Platform: OpenShell Sandbox Plus BlueField-4 Sentry Watchdog to Contain AI Agents
On September 28, 2026, Nvidia announced the Open Agent Safety Platform, pairing the Apache 2.0 OpenShell 0.1.0 agent sandbox with an optional Sentry watchdog on BlueField-4 DPUs that can quarantine out-of-bounds agents in milliseconds; more than 100…
On September 28, 2026, Nvidia CEO Jensen Huang introduced the Open Agent Safety Platform, a partly open-source reference design for governing and containing autonomous AI agents that write code, call APIs, and use credentials, spanning software, hardware, compute, and robotics. Huang described it as a containment system, or 'browser for agents,' framed sandbox escapes as a technically solvable engineering problem, and, per TechCrunch, opposed new regulation. The platform pairs OpenShell 0.1.0, an Apache 2.0 alpha runtime published on GitHub whose Gateway, Supervisor, and Sandbox components isolate each agent in a container or MicroVM with kernel-level filesystem and process controls, inspection of all outbound traffic (with the ability to block writes), verification of permission changes before access expands (optionally requiring human review), hot-reloadable YAML network policy enforced at HTTP method and path, and injection of real API keys outside the agent only for authorized endpoints. OpenShell is optimized for Vera CPUs (Nvidia claims sandboxes run up to 80% faster), extends to Arm and Intel, runs on ordinary Linux, macOS, and WSL, and works with Codex, Claude Code, Pi, and Hermes. Sentry, described variously as optional software and as an NVIDIA DOCA hardware reference design on BlueField-4 DPUs, monitors agents out of band, checks each request and verifies identity, and can quarantine an agent in milliseconds even if the host is compromised; MarkTechPost reports it can be enabled on existing Vera plus BlueField-4 systems via software update, while Hacker News reports no ship date yet and notes capability claims are not independently tested. Most reports say more than 100 organizations are committed (TechCrunch says dozens), including Anthropic, Microsoft, Salesforce, SAP, CrowdStrike, Palo Alto Networks, Cisco, Oracle, CoreWeave, Dell, HPE, Lenovo, Arm, Intel, Palantir, JPMorgan Chase, ServiceNow, and Red Hat, with MarkTechPost tying integrations to the Linux Foundation's Open Secure AI Alliance; sources disagree on SpaceX (TechCrunch) versus SpaceXAI (Hacker News), and OpenAI, Google, Meta, and Amazon were not named as partners. Adoption details include Scale AI using the reference design for mission-critical enterprise and government agents, Salesforce integrating OpenShell with Slack so users can review agent activity and approve or reject permission requests, and early use at Cadence, Slack, and Gecko Robotics. The launch follows…
- Announced September 28, 2026, by Nvidia CEO Jensen Huang, who called it a containment system or 'browser for agents' and framed agent safety as a solvable engineering problem.
- OpenShell 0.1.0 is an Apache 2.0 open-source alpha runtime published on GitHub, built from Gateway, Supervisor, and isolated Sandbox components that run each agent in a container or MicroVM.
- OpenShell applies kernel-level filesystem and process controls, routes outbound traffic through a policy supervisor that can block writes, and injects real API keys outside the agent only for authorized endpoints.
- Permission changes are verified against operator boundaries before access expands and can require human review; network policy is hot-reloadable YAML enforced at HTTP method and path.
- OpenShell is optimized for Vera CPUs (Nvidia claims up to 80% faster sandbox performance), extends to Arm and Intel, runs on ordinary Linux, macOS, and WSL, and works with Codex, Claude Code, Pi, and Hermes.
- Sentry is an optional out-of-band watchdog using NVIDIA DOCA on BlueField-4 DPUs that checks each request, verifies identity, and can quarantine an agent in milliseconds even if the host is compromised; reports describe it both as software…
- Existing Vera plus BlueField-4 systems can gain Sentry capabilities via a software update, per MarkTechPost.
- Most reports say more than 100 organizations are committed; TechCrunch reports 'dozens,' the only count discrepancy.
Coverage timelineoldest first · each row is one article
- · 1d agoNvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
SecurityWeek· 64
Nvidia launched an agent safety platform pairing OpenShell sandboxing with a BlueField-4 hardware watchdog.
- · 1d agoNVIDIA wants AI agent safety enforced in silicon, not left to the agent
Help Net Security· 63
NVIDIA released an open platform that confines AI agents with runtime policies and separate-hardware monitoring.
- · 1d ago