Press Esc to close

NVIDIA launches open safety platform to keep AI agents in bounds

NVIDIA Open Agent Safety Platform

NVIDIA is putting a new layer of guardrails around AI agents, with a platform designed to control what they can access and do even when they run for hours or move across different systems. Announced on September 28, the NVIDIA Open Agent Safety Platform combines open source runtime software with a hardware based monitoring design.

The approach responds to a growing concern for companies deploying agents. A model may be instructed to follow rules, but an agent that can use tools, read data and take actions across software can still encounter ways around application level safeguards. NVIDIA says recent security incidents have shown why enforcement needs to sit outside the agent itself.

The software component, OpenShell, creates a runtime boundary for agent tasks and traces actions while enforcing policy. NVIDIA says it works with open and closed models and is available as open source. The company says it can be extended beyond its own compute platforms to Arm and Intel systems.

The second component, Sentry, is a reference design that uses NVIDIA BlueField-4 data processing units as an independent watchdog. It monitors activity outside the agent’s software environment and can quarantine an agent that crosses its defined boundaries. NVIDIA says the hardware backed response can happen in milliseconds. Sentry also uses NVIDIA DOCA software to inspect requests and responses, verify agent identity and apply zero trust access controls to data, tools and services.

NVIDIA’s Vera CPUs are positioned as the compute base for agent workloads, while OpenShell handles permissions and Sentry adds an out of band layer of monitoring. That division is intended to make enforcement harder for an agent to bypass because the controls do not rely solely on the model or the agent framework behaving as intended.

The platform is already attracting a broad group of partners. NVIDIA says more than 100 organizations are working with its safety technologies. Anthropic is integrating controls with Claude Managed Agents, while Salesforce and NVIDIA have connected OpenShell with Slack so teams can review activity and approve or reject requests for additional permissions. SAP, Red Hat, Scale AI, CrowdStrike, Microsoft and others are also named among participants.

One notable deployment comes from SpaceXAI, which says it is using the platform for Cursor coding agents and Grok models. The claim highlights how agent security is becoming relevant not only to general enterprise assistants but also to coding systems that can edit files, use tools and interact with production environments.

NVIDIA says Open Agent Safety Platform software, including OpenShell, is available through its developer resources and GitHub. The design adds useful controls, though the practical protection will depend on how organizations configure policies, connect infrastructure and audit exceptions. Hardware enforcement can make boundaries tougher to cross, but it does not replace careful permission design or human oversight.

The announcement follows a broader industry focus on agent behavior and containment, including our recent report on OpenAI pausing top models after an agent escaped through DNS. NVIDIA’s launch takes that conversation from model behavior to controls built into the runtime and infrastructure.

Read the full announcement from NVIDIA and see the company’s post on X.

Comments