NVIDIA has introduced the Open Agent Safety Platform to regulate how autonomous AI agents interact with systems, data, tools and physical machines. This new framework pairs open source runtime software with hardware-based monitoring to ensure agent operations remain contained.

Central to this architecture is the combination of NVIDIA OpenShell, which defines and enforces operating boundaries for agents, and the NVIDIA Sentry reference system design running on BlueField-4 data processing units. By shifting security controls entirely outside the underlying AI model and agent software stack, the platform reduces the ability of an agent to interfere with the mechanisms governing its actions.

OpenShell sets boundaries around agent activity

OpenShell provides a secure runtime environment capable of hosting autonomous AI agents across both open and closed models. Within this space, organisations can clearly establish which files, networks, tools, processes and credentials an agent is permitted to access. As tasks proceed, the software simultaneously logs all ongoing actions and actively enforces these operational restrictions to maintain administrative oversight.

While the software is optimised specifically for NVIDIA Vera CPUs, its open source architecture ensures broader flexibility across the wider industry. Developers can readily extend the software to third-party computing platforms, including architectures built on Arm and Intel technologies.

To address pressing operational risks, NVIDIA pointed to recent security incidents where agents bypassed application-level controls in their drive to complete assigned tasks. OpenShell resolves this vulnerability by constructing an independent security perimeter around the runtime environment itself, moving away from an exclusive reliance on internal model constraints or supervising software. This architectural separation ensures organisations can predetermine permissions before an agent starts working and continue applying them as it accesses other systems and tools.

Sentry adds independent hardware enforcement

Building on the software foundation, NVIDIA Sentry carries these protective measures directly into BlueField-4 hardware. According to NVIDIA, the system continuously monitors agent activity from an isolated environment and possesses the capability to quarantine an agent within milliseconds should it attempt to operate outside its permitted boundaries.

The hardware monitoring framework is built on NVIDIA DOCA software, which provides the programmable capabilities needed to inspect agent requests and responses, verify identities and apply access policies across data, tools, application programming interfaces and services. NVIDIA describes this mechanism as in-silicon enforcement because the monitoring routines and policy controls execute independently on the BlueField-4 processor. That physical separation is designed to preserve the enforcement layer even if the host system running the agent cannot be trusted.

“AI’s extraordinary potential for society will only be realised if we solve AI safety,” said Jensen Huang, founder and CEO of NVIDIA. “As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering. NVIDIA Open Agent Safety Platform brings together industry, researchers and public-sector organisations to share best practices, align on evaluation methods and foster international cooperation. Together, we can raise the bar for global AI safety.”

More than 100 organisations are working with the technology

Adoption is already expanding across multiple sectors, with NVIDIA reporting that more than 100 organisations are working with technologies from the Open Agent Safety Platform. These deployments cover AI development, enterprise software, infrastructure, financial services, energy and robotics.

Among these partners, Anthropic has worked with NVIDIA to add OpenShell and BlueField controls to Claude Managed Agents. Claude Managed Agents already separate the agent loop from the isolated environments where its work is carried out, with the NVIDIA technologies adding controls over what agents can access through those environments.

“Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments,” said Paul Smith, chief commercial officer of Anthropic. “Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software.”

Enterprise software providers are also embedding the software into core workplace tools. Salesforce has integrated OpenShell with Slack, allowing teams to view agent activity and audit events while approving or rejecting requests for additional permissions. Meanwhile, SAP is embedding OpenShell into the Joule Studio runtime and contributing engineering work to the project.

In specialised AI infrastructure, Scale AI is incorporating technologies from the platform into the agent architecture used for its enterprise and government customers, while SpaceXAI is using the platform with Cursor coding agents and Grok models. Furthermore, the framework extends beyond pure code into autonomous machinery, where robotics firms such as Figure, Gecko Robotics and Skild AI are building with OpenShell to apply agent controls to systems that can take actions in the physical world.

The Open Agent Safety Platform software, including OpenShell and associated skills, is available to the broader industry. Developers can access these components directly through NVIDIA developer resources and GitHub.

Share