The short version
- NVIDIA has launched the Open Agent Safety Platform around OpenShell and the Sentry reference design
- OpenShell places policy enforcement outside the agent process while Sentry adds an independent monitoring layer on BlueField-4 DPUs
- The design is aimed at long-running agents that can use tools access data write files and interact with external systems
NVIDIA is putting a new security boundary around autonomous AI agents with a platform that treats agent control as an infrastructure problem rather than a prompt-writing problem. The company has combined its OpenShell runtime with a hardware-backed reference design called Sentry to govern what an agent can access and what it can do while it is running.
The control layer sits outside the model
OpenShell is the software side of the design. It runs an agent inside a sandbox and converts operator instructions into policies covering files networks tools processes and credentials. NVIDIA says those controls are enforced outside the agent process so a model cannot simply decide to ignore them. The runtime is open source and can be extended to third-party compute platforms including Arm and Intel systems.
The distinction matters because an agent can generate code call an API launch another process or continue working after its original prompt has been interpreted. A prompt can tell an agent not to touch a resource but a runtime boundary can actually block the request. NVIDIA describes this as a zero-trust approach to agent execution.
The important change is moving enforcement from a promise made by the model to a boundary enforced by the system around it
NVIDIA
The company says OpenShell can trace agent actions and enforce policy as work proceeds. It is designed for both open and closed models and can sit beneath existing agent harnesses rather than requiring a new model.
Sentry adds an independent watchdog
The second layer is Sentry which runs on NVIDIA BlueField-4 DPUs. The NVIDIA platform documentation describes the two layers as a software runtime boundary and an independent hardware enforcement layer. It is designed to observe agent activity outside the host software running the workload. NVIDIA says the watchdog can inspect requests and responses verify agent identity enforce access policies and quarantine an agent that moves outside its permitted boundary.
That separation is the deeper engineering point. If the agent runtime or host workload is compromised the security layer is not supposed to disappear with it. Sentry uses NVIDIA DOCA to connect telemetry policy decisions and access requests and NVIDIA positions the DPU as an independent trust domain.
The platform is arriving as reports from several AI labs have highlighted agents reaching systems they were not expected to access during security testing. NVIDIA has positioned the release as an open reference architecture rather than a single closed product and lists support from companies across AI infrastructure software and enterprise technology.
For developers the practical implication is a shift in where agent safety is implemented. The model remains responsible for reasoning and task execution but the runtime becomes responsible for enforcing the limits. That division becomes increasingly important as agents move from short prompts to long-running workflows that can change files call services and delegate work to other processes.
One reason the architecture is notable is that NVIDIA is treating agent authority as a resource that can be measured and constrained. An agent that can read a project directory but cannot write outside it has a narrower operational boundary than an agent with unrestricted filesystem access. The same model can therefore be deployed with different permissions without retraining the model itself.
That separation also gives enterprise operators a clearer audit trail. OpenShell records allow and deny decisions while the hardware layer can observe activity independently. For teams deploying coding agents or automation agents this creates a path toward reviewing what an agent attempted to do rather than only reviewing the final result.