Nvidia Launches Open Platform to Put Stronger Guardrails Around AI Agents

Nvidia has launched an open security platform designed to restrict what autonomous AI agents can access and do while they are running, adding controls outside the AI model itself.

The new Nvidia Open Agent Safety Platform combines open-source runtime software called OpenShell with an optional hardware-based monitoring system called Sentry. Nvidia announced the platform on September 28 as AI agents increasingly gain access to files, credentials, APIs and other systems needed to complete tasks without constant human supervision.

The central idea is to avoid relying solely on an AI model to respect its own limits. Instead, organizations can define what an agent is permitted to access and have those restrictions enforced by the infrastructure around it.

OpenShell creates a controlled environment for agents

OpenShell is an open-source runtime that places AI agents inside isolated environments and applies policies governing their access to files, networks, processes, credentials and external services.

For example, an organization could allow an agent to access a particular API while preventing it from contacting other services or reading unrelated credentials. OpenShell checks those rules as the agent operates rather than requiring developers to redesign the underlying model.

Nvidia says OpenShell is broadly available and can be used with open and proprietary AI models. Although the software is designed to run efficiently on Nvidia Vera CPUs, its open-source design allows it to be extended to third-party computing platforms, including Arm- and Intel-based systems.

Sentry adds an independent hardware watchdog

Organizations running Nvidia infrastructure can add a second layer called Sentry. It operates on Nvidia’s BlueField-4 data processing units, or DPUs, independently of the CPU environment where the agent is running.

Sentry is designed to continuously observe an agent’s activity and enforce security policies from outside that environment. Nvidia says it can quarantine an agent within milliseconds if it attempts to move beyond its permitted boundaries. Because that enforcement happens on separate hardware, the monitoring layer is isolated from the environment in which the agent itself operates.

The hardware layer is more specialized than OpenShell: it depends on Nvidia’s BlueField-4 infrastructure, while OpenShell is intended to provide the more portable part of the platform.

The system is aimed at a growing security problem around agentic AI. Unlike conventional chatbots, agents can be given longer-running tasks and permission to execute code, call external tools or interact with company systems. That makes mistakes, unexpected behavior and compromised agents potentially more consequential.

Some early integrations show how those controls could work in practice. Salesforce, for example, has integrated OpenShell with Slack so administrators can view agent activity and approve requests for additional permissions. Anthropic is also working with Nvidia to apply infrastructure-level controls around its managed agents.

The platform doesn’t eliminate the broader challenge of making AI models behave reliably but it applies a familiar security principle to agents to assume software can make mistakes or be compromised, then restrict what it can reach and provide an independent mechanism for enforcing those limits.