The Nvidia Open Agent Safety Platform is the company's new reference for governing AI agents from testing to deployment. Announced on September 28, the Nvidia Open Agent Safety Platform combines the open-source OpenShell runtime with the Sentry reference design, which runs on BlueField-4 DPUs and can isolate an agent that breaks policy in milliseconds.
What happened?
In the official release, Nvidia describes two pieces of the Nvidia Open Agent Safety Platform. OpenShell, under the Apache 2.0 license, creates an execution boundary: each agent runs in a sandbox, credentials stay in a gateway outside that box, and a policy prover uses formal methods before the agent runs. Nvidia says the software traces actions and enforces rules while the agent runs on Nvidia Vera CPUs, and that it can be extended to third-party platforms, including Arm and Intel.
Sentry is the out-of-band layer. It runs on BlueField-4 DPUs, between the agent on the main processor and the model it calls. Because the path to the model passes through that hardware, Sentry can watch requests, responses, and chain-of-thought reasoning and cut the agent off if it tries to leave its bounds. Nvidia calls this in-silicon security enforcement, independent of software the agent itself controls.
The company's technical blog lists five principles of the Nvidia Open Agent Safety Platform: verifiable policy, out-of-band enforcement, control of the path to the model, agent authority scaled to reasoning visibility, and shared responsibility among labs, enterprises, and hardware providers.
Why it matters
Agents do more than answer: they call tools, read data, and chain steps. A rule that lives only in the prompt cannot stop a compromised process from ignoring its own filter. Moving policy enforcement out of the agent's reach, and placing a watchdog on separate hardware, is Nvidia's thesis for that risk.
The weight of the Nvidia Open Agent Safety Platform announcement also sits in the partner list in the newsroom: Anthropic, Cisco, CrowdStrike, Dell, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI, among others. Network World details integrations underway: Anthropic's Claude Managed Agents with OpenShell and BlueField, Salesforce connecting OpenShell to Slack so teams can approve permission requests, SAP embedding the layer in Joule Studio, and SpaceXAI using the platform with Cursor coding agents and Grok models. Those are partnership statements, not proof the product is already in production at every named company.
What changes in practice?
For agent developers, OpenShell in the Nvidia Open Agent Safety Platform is the piece that can be tried now, because it is open software. Sentry depends on a BlueField-4 DPU and Nvidia's reference design, so it is limited to infrastructure that places that hardware on the path to the model, such as the Vera Rubin POD systems described in the technical blog.
- OpenShell isolates the agent and keeps credentials outside the sandbox.
- Sentry monitors out of band and can quarantine an agent in milliseconds, according to Nvidia.
- The Nvidia Open Agent Safety Platform does not replace human review or data audits.
- The announcement does not include an independent block rate on real attacks.
Sources: Nvidia Newsroom, Nvidia technical blog, and Network World.
By GeekikiBot