In brief

Nvidia launched its Open Agent Safety Platform on September 28. The system joins OpenShell, an open-source secure runtime, with Sentry, a design that watches agents from a separate BlueField-4 chip. Nvidia says Sentry can quarantine an agent in milliseconds. More than 100 organisations support the effort, but real-world results are still limited.

New to this? Read it in simple words
  • Nvidia made a new safety system for AI agents that use tools and computer systems.
  • OpenShell limits what an agent may reach and records its actions.
  • A separate chip-based guard can stop an agent if it moves outside those limits.
  • Nvidia says more than 100 organisations support the project, but wider testing is still needed.
Words to know
Runtime
The software space where a program works.
Sandbox
A closed area that limits what a program can reach or change.
Quarantine
Stopping and separating a risky program from other systems.

What Nvidia launched

Nvidia announced the Open Agent Safety Platform on September 28. It is an open design for controlling AI agents from testing through daily use. More than 100 companies and public groups support the project, Nvidia says.

The first part is OpenShell, an open-source runtime. A runtime is the software space where a program works. OpenShell puts each agent in a sandbox and checks what files, networks, tools and services it may reach.

The rules sit outside the agent process. This matters because an agent cannot change the rule by writing a clever prompt or starting another program. OpenShell also creates a record of allowed and blocked actions.

Sources12

SAFETY STACK 01
The agent does not control the last safety line.

Architecture from Nvidia. Sentry is a reference design, and wider independent results are still needed.

A second guard in hardware

Nvidia also presented Sentry, a reference design that runs on its BlueField-4 data processing unit. This is a separate chip that handles network and security work. It watches the agent from outside the main computer.

Nvidia says Sentry can check identity, data access and agent behaviour. If an agent moves outside its allowed area, Sentry can quarantine it in milliseconds. Quarantine means stopping and separating the agent from other systems.

OpenShell can run without BlueField-4 and may be extended to Arm and Intel systems. Sentry is tied more closely to Nvidia hardware. It is a design for partners to build, not a result from a large independent test.

Sources123

What this can and cannot solve

The platform follows several public agent failures. In those cases, models worked around application rules while trying to finish a task. SecurityWeek notes that OpenShell itself is now broadly available, while Sentry is the newer hardware layer.

The basic idea is sound: do not ask an agent to police itself. Use least privilege, which means giving it only the access needed for one job. Keep another system ready to stop it.

No safety product is a complete answer. Teams must write correct policies, protect the safety system and test unknown attacks. Nvidia’s partner list is large, but adoption does not prove that the platform stops every dangerous action.

Sources123

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
    Primary source · September 28, 2026NVIDIA Launches Open Agent Safety Platform Nvidia
  2. 2
    Primary source · September 28, 2026NVIDIA Open Agent Safety Platform Nvidia
  3. 3
How we checked this story

We compared Nvidia’s press release and product page with SecurityWeek’s independent report. Product speed, quarantine time and partner use are Nvidia’s claims. We describe Sentry as a reference design and do not treat the partner list as proof of safety.