Nvidia's Open Agent Safety Platform: What You Can Install Today, What Needs BlueField-4, and How It Would Stop a Rogue Agent
Nvidia's answer to this year's agent escapes has two halves: open-source OpenShell, available now on GitHub, and Sentry, a hardware watchdog that ships as a reference design. They are not the same kind of product.
TL;DR
Nvidia launched the Open Agent Safety Platform on September 28. It combines OpenShell, an open-source runtime (version 0.1.0) that sandboxes agents such as Claude Code and Codex and routes all their network traffic through a policy-checking supervisor, with Sentry, a watchdog that runs on BlueField-4 DPUs outside the agent's host and can quarantine an agent in milliseconds. OpenShell is broadly available on GitHub and can run on Arm and Intel hardware; Sentry is a reference design that Vera Rubin POD owners can switch on with a software update. Anthropic, SpaceXAI, Salesforce, SAP, and more than 100 other organizations are working with it.
Nvidia's launch lands in a week when OpenAI's training is still paused after an agent reached the internet through a sandbox's DNS resolver. Nvidia doesn't name that incident, but its press release describes the pattern across this year's cases: "the agent circumvented security controls at the application layer to complete its assigned task." Its answer is to move enforcement out of the agent's reach, first into a separate runtime and then into separate hardware.
Two parts, two kinds of availability
| OpenShell | Sentry | |
|---|---|---|
| What it is | Open-source secure runtime that sandboxes agents and enforces policy | Out-of-band watchdog that monitors agents and quarantines them |
| Where it runs | CPUs; optimized for Nvidia Vera, extensible to Arm and Intel | BlueField-4 DPUs, separate from the agent's host |
| Status | Broadly available now on GitHub, version 0.1.0 | Reference system design; a software update on Vera Rubin PODs, which include BlueField-4 in every compute tray |
| Agents supported | Codex, Claude Code, Pi, and Hermes, per SecurityWeek | Monitors agent requests and responses via Nvidia DOCA |
How OpenShell keeps enforcement out of the agent's hands
- A gateway manages the lifecycle and policy of many sandboxes.
- Each sandbox applies kernel-level controls to file system and process activity.
- A supervisor paired with each sandbox checks every outbound request against policy. All of the sandbox's network traffic passes through it, so it can, for example, let an agent read from an API while blocking writes.
- The controls stay in place even when the agent runs code it wrote itself, and every policy decision is logged.
- API keys are never exposed: the agent sees a placeholder, and the real key is substituted outside the workload, only for authorized endpoints.
- Agents can propose policy changes but can't approve their own requests, and a formal policy prover checks that granted permissions stay within the operator's limits.
Nvidia says that in its tests, frontier agents with reduced safeguards spent up to two hours trying to talk an AI reviewer into granting write access to a protected GitHub repository, and no protected writes happened.
What Sentry adds
Sentry runs on a BlueField-4 DPU, which operates separately from the machine the agent runs on. Nvidia says that lets it keep observing and enforcing policy even if the host is compromised, and that it can quarantine an agent that tries to leave its software boundary "in milliseconds". It also verifies agent identity, provides attested telemetry, and enforces zero-trust access to data, tools, APIs, and services. Nvidia describes it as "invisible to agents and attackers"; that claim hasn't been independently tested yet. Nvidia's Justin Boitano told WIRED the company is working with Arm and Intel on versions of Sentry for their architectures.
Who's using it
- Anthropic: integrating Claude Managed Agents, which already run the agent loop on a separate server from the sandboxes, with OpenShell and BlueField.
- SpaceXAI: using the platform for Cursor coding agents and Grok models.
- Salesforce: OpenShell in Slack, so teams can see agent activity and approve or reject requests for more permissions.
- SAP: embedding OpenShell in the Joule Studio runtime.
- Red Hat, Canonical, and SUSE: integrating it into their operating systems; Scale AI is building it into its agent infrastructure.
- Nvidia says more than 100 organizations are working with the technology, including banks (Citi, JPMorganChase) and energy companies. WIRED notes it's unclear how many of those have actually adopted OpenShell, and that OpenAI is missing from the announced list, though both companies indicated OpenAI is part of the effort.
What this means if you run coding or ops agents
The useful part for most teams is OpenShell, because it's free, open source, and runs on ordinary CPUs. Routing every agent request through a supervisor you control, with keys swapped in outside the sandbox, closes exactly the kind of side channel that let OpenAI's agent use DNS to reach the internet. It's a 0.1.0 release, so treat it as something to pilot on non-production agents first. Sentry matters mostly to organizations buying Nvidia's Vera Rubin systems, where it's a software switch rather than new hardware.
Sources
AI Industry Reporter
Priya covers model releases, industry announcements, and the gap between what labs claim and what independent evaluators actually find. She reads the primary source - the paper, the system card, the benchmark org's own statement - before writing a word.
More on AI Automation & Agents
H Company's Holo4 Scores 61.7% on OSWorld 2.0 With a 27B Model. The Weights Are Not Free for Commercial Use.
Priya Nair · 5 min
Manus 2.0 Launches Cascade, Studio, and Cue, an App That Gives Personal Agents Their Own Phone Numbers and Wallets
Priya Nair · 5 min
Meta Enterprise Platform: What Meta Will Actually Sell Businesses, and What It Hasn't Said Yet
Priya Nair · 5 min