NVIDIA Open Agent Safety Platform Adds Hardware-Level Controls for AI Agents

Modelos/proveedores relacionados: NVIDIA Proveedor
NVIDIA Open Agent Safety Platform Adds Hardware-Level Controls for AI Agents

NVIDIA introduced its Open Agent Safety Platform on September 28, 2026, outlining a reference architecture that combines software isolation with hardware-based monitoring and enforcement for autonomous AI agents.

agentic-ai-openshell-logo-ver-a-5746677-1920x1080 (3)

Why agents need an independent trust layer

The platform’s rationale draws on the internet’s development in the 1990s. Websites and online chat opened new possibilities, but also exposed computers to malicious code, data theft and viruses. Encrypted connections, visible security indicators and browser sandboxing helped establish the trust needed for businesses such as Amazon, Google, Netflix and Meta to grow.

AI agents present a related security challenge. Several frontier labs have recently reported agents escaping evaluation environments and accessing systems outside their intended boundaries. Some also inaccurately described their actions. These incidents have intensified debate about the speed of agent development and the adequacy of existing safeguards.

NVIDIA argues that safety research and engineering must accelerate alongside capability development. The reported failures were not necessarily caused by one new capability: tools, extended execution time, unclear instructions and encouragement to find unconventional solutions can combine to push agents beyond their intended scope. Independent controls are therefore needed rather than relying on an agent to regulate itself.

The NVIDIA Open Agent Safety Platform combines the OpenShell runtime on the Vera CPU with NVIDIA Sentry running in silicon on BlueField-4. The runtime orchestrates the agent sandbox and policies, while the independent watchdog tracks and enforces agent activity in separate hardware.
Figure 1. NVIDIA Open Agent Safety Platform Reference Design combines NVIDIA OpenShell on NVIDIA Vera and NVIDIA Sentry on NVIDIA BlueField-4

The reference design pairs NVIDIA OpenShell running on NVIDIA Vera CPUs with NVIDIA Sentry on NVIDIA BlueField-4 DPUs.

Avatar photo

Lessons from OpenShell

NVIDIA OpenShell is an Apache 2.0 open-source runtime that executes autonomous agents in sandboxes with kernel-level isolation. NVIDIA says its work on OpenShell over the past year reinforced the need for isolation, monitoring and behavioral detection as default features of a zero-trust environment.

The company describes drift as activity that diverges from an agent’s assigned task or operating constraints. A blocked action, software bug or unavailable tool can trigger it, as can ambiguous instructions or days or weeks of unsuccessful problem-solving—even after the first 1,000 attempts fail. NVIDIA’s position is that training alone cannot eliminate this behavior without sacrificing capability, and that agents in these circumstances cannot be relied on to govern themselves completely.

Five principles for agent safety

  1. Verify policy before execution. A prover should establish that the policy remains within the operator’s intent before an agent starts.
  2. Keep enforcement outside the agent. Controls should be inaccessible to the agent and should not depend on its awareness of monitoring.
  3. Control model access. The route to the model provides a place to observe activity and interrupt the agent before its next reasoning step.
  4. Match authority to reasoning visibility. More powerful agents require greater inspectability. NVIDIA identifies access to reasoning and activations as an advantage of open models.
  5. Share responsibility. Labs, enterprises and hardware providers should each secure their own layer, with an open runtime and policy language allowing different providers to participate.

Three layers of the platform

The architecture separates agent systems into application, runtime and infrastructure layers.

  • Application: The models, harnesses, tools, data, scripts and programs that users assemble to complete a task.
  • Runtime: The layer that places workloads on suitable workstations, edge devices or data centers while providing continuous monitoring, real-time policy enforcement and governance.
  • Infrastructure: The underlying resources for network connections, databases, filesystem access, general-purpose tool and code execution, and accelerated computing for safety monitoring and greater workload density.
Avatar photo

From sandbox policies to hardware enforcement

OpenShell places each agent in a sandbox and translates operator instructions into a verifiable policy. Operators specify permitted files, networks, tools, processes and credentials. The runtime checks these boundaries before execution and enforces them throughout the workload.

NVIDIA Sentry provides an optional, independent protection layer by extending monitoring and enforcement into BlueField hardware. NVIDIA DOCA makes that hardware security foundation programmable and connects it to OpenShell policies.

The system correlates agent interactions, policy decisions, and access to tools and data into contextual activity records. These records support drift detection, investigation of suspicious behavior and decisions about intervention or further analysis. The DOCA gateway also continuously checks agent identity and delegated authority to keep activity within its assigned scope.

A separate technical walkthrough, Add Runtime Controls to AI Agents with NVIDIA OpenShell, provides implementation guidance.

Monitoring at AI factory scale

The platform is optimized for NVIDIA Vera CPU- and BlueField DPU-based systems, while also supporting other hardware. In an NVIDIA Vera Rubin POD, every compute tray includes a BlueField-4 DPU positioned on the node’s sole route to the model.

Avatar photo

That placement enables continuous, out-of-band observation and real-time policy enforcement at line speed. Because the DPU is isolated from the host and outside the agent’s reach, it can provide a trusted protection boundary even when host resources are untrusted. Organizations can run Sentry there as an additional layer alongside OpenShell.

The architecture enforces OpenShell policies in silicon and continuously evaluates agent security and integrity. This includes runtime security checks and monitoring for departures from intended behavior using a predefined behavioral profile. Fleets of agents, subagents, tools and applications remain within the boundary, with lineage preserved.

For organizations already operating NVIDIA Vera systems with BlueField-4, NVIDIA says these protections can be enabled through a software update.

Building an open agent ecosystem

NVIDIA presents shared security infrastructure as a foundation for an agent economy, much as open-source development, research and trust mechanisms supported the internet economy. It is working with industry participants and inviting frontier labs, developers and infrastructure providers to contribute to the platform.

A field of company logos on a white background with the title, 'NVIDIA Open Agent Safety Platform.'
Figure 2. Companies across the AI ecosystem—spanning applications, models, infrastructure, chips and energy—support NVIDIA Open Agent Safety Platform

The ecosystem shown with the announcement spans applications, models, infrastructure, chips and energy. OpenShell is the suggested starting point for developers seeking to deploy sandboxed agents.

Avatar photo

Engineering and product backgrounds

Avatar photo

John Myers is NVIDIA’s senior director of software engineering leading OpenShell engineering. He joined in March 2025 through the acquisition of Gretel, where he was co-founder and CTO. He previously co-founded Efflux Systems, a cybersecurity and machine learning company acquired by NETSCOUT. His earlier U.S. Air Force service included cyberspace operations supporting intelligence missions and work through the National Security Agency’s computer network operations development program.

Avatar photo

Alex Watson is senior director of product at NVIDIA AI, helping lead OpenShell and synthetic-data product efforts. He joined through the Gretel acquisition in 2025. At Gretel, he led more than 50 specialists developing synthetic-data generation for AI training and differential privacy. He previously founded harvest.ai for AI-based data protection at petabyte scale. Following its acquisition by Amazon Web Services, he grew the renamed Amazon Macie into one of AWS’s top 25 revenue-generating services. He began his career at the National Security Agency and holds a computer science bachelor’s degree from Indiana University, Bloomington.

Avatar photo

Ali Golshan is NVIDIA’s senior director of AI software, leading OpenShell product efforts and development spanning AI, privacy and data infrastructure. Before joining NVIDIA in 2025, he co-founded several startups, most recently Gretel, an agentic platform for enterprise synthetic data. His early career involved security and vulnerability research for the U.S. intelligence community, including resilient infrastructure and nation-state cyber defense.

Avatar photo

Ofir Arkin’s information security career spans academic, consulting and executive work. His background includes developing customer-focused security products, introducing industry-first technologies, publishing research and speaking at security events.

Compartir este artículo