The short version
- NVIDIA introduced OpenShell 0.1.0 as an open-source runtime for controlling what autonomous AI agents can access.
- The runtime combines sandboxed execution, controlled service access, credential management and policy analysis.
- OpenShell is organized around a gateway, supervisor and sandbox model.
NVIDIA introduced OpenShell 0.1.0 as an open-source runtime for controlling what autonomous AI agents can access. NVIDIA’s OpenShell addresses a problem that becomes more important as AI agents gain access to tools and external systems. A model can be instructed to behave safely, but instructions alone do not create a hard technical boundary around what an agent can access.
Runtime controls for agentic software
NVIDIA said the system uses formal verification to examine policy changes before they are applied.
NVIDIA’s OpenShell documentation lays out the gateway supervisor and sandbox design along with the controls intended to constrain agent access.
OpenShell 0.1.0 approaches the problem at runtime. NVIDIA describes a system built around a gateway, supervisor and sandbox, with controls for service access, credentials and policy analysis. The open-source runtime is intended to make those controls enforceable around the agent rather than leaving every application to implement them separately.
- NVIDIA describes a system built around a gateway, supervisor and sandbox, with controls for service access, credentials and policy analysis.
- The runtime uses a gateway, supervisor and sandbox architecture.
- The runtime combines sandboxed execution, controlled service access, credential management and policy analysis.
Organizations including Cadence, Slack and Gecko Robotics are adopting OpenShell for different agent workloads.
OpenShell addresses a specific problem created by agentic software: the model can decide which tools to call, but the operating environment still needs to enforce what those tools can access.
The runtime uses a gateway, supervisor and sandbox architecture. The supervisor can enforce restrictions around process identity, filesystem access, network egress and credentials, placing security controls around the workload rather than relying only on model behavior.
That distinction matters in production. An agent can encounter an unexpected document, a malicious instruction or an application state that was not anticipated by its developer. Sandboxing and controlled access can limit the consequences even when the model itself produces an unsafe decision.
Formal policy analysis is another part of the design. For infrastructure teams, the ability to inspect and enforce policy changes is useful because security rules need to be predictable even when the software inside the sandbox is autonomous.
OpenShell does not eliminate the need for application security. Organizations still need identity management, logging, network controls and human approval for sensitive actions. Its significance is that those requirements can be expressed as part of the runtime environment in which an agent operates.