News report
NVIDIA Launches Open Agent Safety Platform With OpenShell and Sentry
NVIDIA's Open Agent Safety Platform combines the OpenShell runtime with a BlueField-4 Sentry watchdog to enforce boundaries around autonomous AI agents.
On this page
NVIDIA is moving AI-agent controls outside the model
NVIDIA has launched its Open Agent Safety Platform, a software-and-hardware framework designed to enforce boundaries around autonomous AI agents from testing through deployment. The platform combines the broadly available OpenShell secure runtime with a Sentry reference design that monitors agent behavior from an isolated BlueField-4 DPU.
The architectural point is separation. OpenShell controls what an agent can access and do from outside the model and agent harness, while Sentry is designed to observe and enforce policy from an out-of-band hardware trust domain. NVIDIA says this allows the system to stop or quarantine an agent that attempts to move outside its permitted boundary.
OpenShell provides the software boundary
OpenShell is open-source runtime software that traces agent actions and applies policy while the agent works. NVIDIA positions Vera as its optimized CPU platform for OpenShell, but says the software can also be extended to third-party compute platforms including Arm and Intel.
That distinction matters for developers: the announcement is not a requirement that every OpenShell deployment use an NVIDIA CPU. The broader Open Agent Safety Platform does, however, include NVIDIA-specific hardware components when organizations want the Sentry out-of-band enforcement layer.
Sentry moves monitoring onto BlueField-4
NVIDIA Sentry is the hardware-oriented part of the reference design. It runs on BlueField-4 DPUs and uses NVIDIA DOCA software to inspect agent requests and responses, provide attested telemetry, verify agent identity and enforce access policies for data, tools, APIs and services.
Because that monitoring executes outside the host environment used by the agent, NVIDIA describes it as an independent trust domain that the agent cannot directly control. The company says Sentry can quarantine an agent that crosses its software boundary in milliseconds. That timing is a vendor claim for the reference design, not an independent Core Tech Tips measurement.
The platform already has a broad integration ecosystem
NVIDIA names more than 100 organizations working with technologies around the platform. Its announcement highlights Anthropic integrations around managed-agent sandboxes, Salesforce integration that exposes OpenShell activity and permission approvals through Slack, and SAP work connecting OpenShell with Joule Studio runtime.
IBM separately confirmed support for the platform on September 28. IBM says Agent Identity and HashiCorp Vault integrate with OpenShell for identity and least-privilege access, while its infrastructure work extends into BlueField-backed data protection. These integrations show ecosystem participation; they should not be read as independent security certification of the complete NVIDIA design.
What is confirmed and what still needs validation
Confirmed by NVIDIA: OpenShell is broadly available and open source; it can extend beyond Vera to Arm and Intel platforms; the Sentry reference design uses BlueField-4 DPUs and DOCA; and the platform is intended to enforce agent permissions and provide an out-of-band monitoring layer.
Not established by today's launch are universal performance overhead, effectiveness against every agent-security failure, or a guarantee that third-party integrations provide identical enforcement. NVIDIA describes minimal OpenShell overhead on Vera and millisecond-scale Sentry quarantine, but independent testing will be needed to quantify those claims across real deployments.
Sources
Primary and technical sources
These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.
Related
Continue from here
Useful next steps selected from the same technical reference and publication system.
Compatibility & upgrades
ATX vs Micro-ATX vs Mini-ITX Motherboard Sizes
Compare ATX, Micro-ATX, and Mini-ITX motherboard dimensions, mounting and case-fit implications without confusing board size with chipset features or performance.
Compatibility & upgrades
Gaming Monitor Upgrade Compatibility: GPU Outputs, Refresh Rate, DSC, VRR, HDR, and Cables
Check whether your GPU, cable or adapter path, monitor input, Windows setup, VRR, HDR, and display mode can work together before upgrading a gaming monitor.
Compatibility & upgrades
Monitor Arm Compatibility Explained: VESA Mounts, Load Ratings, Ultrawides, Desk Clamps, and Recessed Mounts
Check monitor-arm compatibility by VESA pattern, monitor mass, arm load range, curved-screen geometry, recessed mounts, desk clamps, grommets, clearance, and cabling.
Technical guide
Monitor Flickering on Windows 11: Cable, Refresh Rate, VRR, Driver, and Hardware Troubleshooting
Diagnose monitor flickering in Windows 11 by isolating the app, driver, refresh-rate and VRR mode, cable path, GPU output, monitor input, and display hardware.