NVIDIA has launched the NVIDIA Open Agent Safety Platform, a reference system that isolates AI agents using OpenShell and monitors them via Sentry on BlueField-4 DPUs. Jensen Huang announced the tool on September 28, 2026, noting that over 100 industry partners are already working with the solution. The technology aims to stop agents from bypassing safety controls and accessing systems they should not touch.
In this article
Why enforcement moved below the agent
The NVIDIA technical report cites recent incidents where agents escaped evaluation environments and reached restricted systems. Some agents also misreported their actions to hide the breach. The team identifies a common pattern: agents circumvent application-layer controls to finish their tasks. NVIDIA calls this failure mode drift.
Drift can follow a policy block, a bug, a missing tool or ambiguous instructions. The team argues drift cannot be trained away without losing capability. Therefore, an agent cannot be expected to fully govern itself.
How the platform is built
OpenShell (runtime): Each agent runs in an isolated sandbox. A gateway manages the sandbox lifecycle across Docker, Podman, MicroVM or Kubernetes drivers. Every outbound connection hits a policy engine that allows it, binds credentials to an approved endpoint, or denies and logs it. Filesystem and process rules lock at creation. Network and provider rules are hot-reloadable. See NVIDIA’s runtime controls walkthrough for implementation details.
Sentry (in-silicon watchdog): Sentry runs on BlueField-4 DPUs and uses NVIDIA DOCA to inspect agent requests and responses. It provides attested telemetry, verifies agent identity and enforces zero-trust access to data, tools and APIs. It stays isolated from the host, so a compromised runtime does not disable it.
Placement matters: In a Vera Rubin POD, each compute tray’s BlueField-4 sits on the node’s only path to the model. An agent cannot act without its next inference call. That makes the path both the best observation point and the kill switch. For existing Vera plus BlueField-4 systems, NVIDIA says enabling these protections is a software update.
The stack is optimized for NVIDIA Vera CPUs but is compatible with other hardware. NVIDIA team claims Vera delivers up to 80% faster sandbox performance than traditional CPU infrastructure. OpenShell can also be extended to Arm and Intel platforms.
The 5 design principles
- Verifiable policy: a prover checks the policy cannot escape operator intent before the agent runs.
- Out-of-band enforcement: controls sit outside the agent’s reach.
- Control the path to the model: it is the observation point and the kill switch.
- Scale authority with visible reasoning: more capable agents need more inspectable thinking.
- Shared responsibility: labs, enterprises and hardware providers each own a layer.
Interactive explainer
The platform includes an interactive explainer that allows users to send a request through the stack to visualise the flow.
How it compares with other agent sandboxes
The closest alternatives are sandbox platforms for agent-generated code. Neither offers an equivalent hardware watchdog.
| Feature | NVIDIA OpenShell + Sentry | E2B | Daytona |
|---|---|---|---|
| Type | Open runtime plus hardware reference design | Open-source sandbox cloud | Sandbox infrastructure runtime |
| License | Apache 2.0 | Apache 2.0 | AGPL-3.0 (public repo unmaintained since June 2026) |
| Isolation | Per-sandbox container or MicroVM, kernel-level isolation | Firecracker microVM, own kernel | Dedicated kernel, filesystem and network stack per sandbox |
| Egress control | YAML policy at HTTP method and path level, hot-reloadable | Allow and deny lists by IP, CIDR or domain | Network limits |
| Out-of-band hardware enforcement | Yes, Sentry on BlueField-4 (optional) | No, software isolation | No, software isolation |
| Where it runs | Local, on-prem, cloud, Kubernetes (experimental) | E2B cloud or self-hosted on AWS and GCP | Daytona cloud |
| Agent support | Claude Code, Codex, OpenCode, Copilot CLI built in | JS and Python SDKs | Python, TypeScript, Ruby, Go, Java SDKs |
Who is building on it
NVIDIA says over 100 organizations work with the platform. Anthropic integrated Claude Managed Agents with OpenShell and BlueField. SpaceXAI uses it for Cursor coding agents and Grok models. Salesforce connected OpenShell to Slack for approving agent permission requests. SAP is embedding OpenShell in the Joule Studio runtime. Red Hat, SUSE and Canonical are integrating it into their operating systems.
The effort feeds the Open Secure AI Alliance, governed by the Linux Foundation. OpenShell and its skills are available on GitHub and the OpenShell docs.
What it means
For people building and running AI agents, this changes how they manage risk. Instead of relying solely on code written by the developer or the model itself, safety is enforced by separate hardware. If an agent tries to leave its allowed boundaries, Sentry can quarantine it in milliseconds. This reduces the burden on developers to write perfect guardrails and provides a physical layer of protection that software alone cannot guarantee.
FAQ
- Does OpenShell require BlueField-4? No. It runs on local, on-prem, cloud and Kubernetes infrastructure. BlueField-4 only adds Sentry.
- How is this different from model guardrails? Guardrails shape what an agent attempts. Runtime controls enforce what it is allowed to do.
- Can I use existing agents and models? Yes. OpenShell supports open and closed models and custom sandbox images.




