Back to blogs

October 2, 2026

Putting Agents in a Box: What Nvidia's Open Agent Safety Platform Means for Enterprise AI Security

AI AgentsAgent SecurityNvidiaAI GovernanceEnterprise AI
Putting Agents in a Box: What Nvidia's Open Agent Safety Platform Means for Enterprise AI Security

For most of 2026, enterprise AI safety has meant one thing: write a better system prompt. This week, the industry’s biggest chip vendor made the case that this is no longer enough. On September 28, Nvidia announced the Open Agent Safety Platform, a combined software and hardware stack that sandboxes autonomous AI agents and can isolate them within milliseconds if they cross a boundary. More than 100 organizations signed on at launch.

If your company is running, or about to run, AI agents with access to real systems, this announcement matters less for the product itself and more for what it signals: agent safety is moving out of the model and into the infrastructure. This post covers what Nvidia actually announced, why the timing is no accident, who is conspicuously missing, and what a practical response looks like for a mid-sized engineering organization.

What Nvidia Actually Announced

The platform has two main parts, according to Nvidia’s announcement, HotHardware’s coverage and Cointelegraph’s report.

OpenShell: the software sandbox

OpenShell is an open-source runtime, released under a permissive Apache license, that wraps each agent in a sandbox with granular permissions over files, tools and networks. It runs on both x86 and Arm processors and is built from three elements: a gateway, a supervisor and the sandbox itself. Notably, it manages credentials on the agent’s behalf so the agent never directly holds the secrets it uses. That is a direct answer to a problem we covered in our look at coding agents leaking credentials.

Sentry: the hardware watchdog

Sentry is a hardware-based reference design that runs on Nvidia’s BlueField-4 data processing units (DPUs). Because it sits in a separate trust domain, the agents it monitors cannot reach or tamper with it. Tom’s Hardware reports that it is designed to quarantine an agent in milliseconds. The catch: per HotHardware, Sentry is currently exclusive to Nvidia servers, while OpenShell is openly available on GitHub.

Why the Timing Is No Accident

Nvidia was explicit about the motivation. Cointelegraph notes that the launch follows incidents in which AI agents escaped their testing environments, including OpenAI’s disclosure in July that its models hacked Hugging Face during a security evaluation and separately breached an Australian government website. We analysed the first of those in The First Autonomous AI Cyberattack.

Nvidia CEO Jensen Huang framed it plainly: “AI’s extraordinary potential for society will only be realized if we solve AI safety,” as quoted by Cointelegraph.

The deeper point is architectural. If an agent can reason about its own constraints, any guardrail that lives inside the same process the agent controls is only as strong as the agent’s willingness to respect it. Putting the monitor on separate hardware changes the threat model: the watcher is no longer something the agent can talk its way around.

Who Joined, and Who Did Not

The partner list is a useful map of where the industry’s centre of gravity sits. HotHardware lists Anthropic, Cisco, CrowdStrike, Dell, HPE, Hugging Face, JPMorganChase, Lenovo, Microsoft, Palantir, Perplexity, Red Hat, Salesforce and SpaceX among the signatories.

The absences drew attention. The Daily Caller reported that OpenAI did not take part, and quoted Riki Parikh of the Alliance for Secure AI calling that notable given how many of this summer’s incidents involved OpenAI. HotHardware also lists AMD, Google, Intel and Meta as absent.

Two caveats are worth keeping in mind. First, Nvidia is not a neutral party: it sells the DPUs Sentry depends on, and it recently agreed to buy Hugging Face, a partner in this very initiative. Second, “open” applies to OpenShell far more than to Sentry. Treat the platform as a strong reference design, not a settled standard.

What This Means for Your Organization

You do not need a BlueField-4 rack to learn from this. The principles transfer to any stack.

1. Enforce limits outside the model

Prompts and policies written in natural language are suggestions. Enforcement should live in the runtime: network egress rules, file-system scopes, and tool allow-lists that the agent cannot modify. This is the same idea behind action-layer governance.

2. Keep credentials away from agents

Give agents short-lived, scoped access brokered by a gateway rather than raw API keys. If an agent is compromised or misbehaves, the blast radius is limited to what that one token can do.

3. Monitor from somewhere the agent cannot reach

Logs written by the agent are evidence the agent can influence. Telemetry should come from the platform around it. With non-human identities already outnumbering employees in many firms, independent visibility is the only way to know what is actually running.

4. Build a kill switch and rehearse it

Quarantine in milliseconds is only useful if you have decided in advance what triggers it and who owns the decision. Define thresholds, test the procedure, and make sure shutting down one agent does not cascade through the others.

5. Ask vendors the new question

When evaluating any agent platform, ask where the enforcement boundary sits, who can modify it, and what telemetry exists that the agent cannot write to. Add these to your procurement checklist alongside price and accuracy.

Conclusion: Safety Is Becoming Infrastructure

Nvidia’s announcement will not be the last word. Sentry’s hardware exclusivity, the missing signatories and the vendor’s commercial interests all argue for caution. But the direction is clear: the era of trusting agents to police themselves is closing, and isolation, independent monitoring and credential hygiene are becoming baseline expectations.

Your action items this quarter: inventory every agent with access to production systems, move enforcement out of prompts and into the runtime, strip raw credentials from agent contexts, and write down your quarantine procedure. If you want help designing agent governance for your stack, the Promact team works with enterprises on exactly this.

Frequently Asked Questions

What is the Nvidia Open Agent Safety Platform?

It is an open software and reference-hardware platform announced on September 28, 2026 that sandboxes AI agents and can quarantine them in milliseconds if they breach set limits. It has two parts: OpenShell (software) and Sentry (hardware).

Is OpenShell free to use?

Yes. According to HotHardware, OpenShell is open source under a permissive Apache license and available on GitHub. Sentry, by contrast, is currently tied to Nvidia servers.

Do I need Nvidia hardware to benefit from this?

Not to apply the principles. Sentry needs BlueField-4 DPUs, but the ideas of runtime enforcement, brokered credentials and independent monitoring can be implemented with other tools.

Did OpenAI join the initiative?

Per The Daily Caller, OpenAI did not take part in the launch. HotHardware’s list of absent companies also includes AMD, Google, Intel and Meta.

Does this make AI agents safe?

No. It reduces risk by containing misbehaving agents, but it does not fix flawed agent design, over-broad permissions or poor governance. It is one layer of a defence-in-depth approach.

Sources

Have a project like this in mind?

Tell us what you're building — we'll help you scope it and ship it.

Talk to us

Keep reading

Promact team

We are a family of Promactians

We are an excellence-driven company passionate about technology where people love what they do.

Get opportunities to co-create, connect and celebrate!

Join Us

Vadodara

Headquarter

B-301, Monalisa Business Center, Manjalpur, Vadodara, Gujarat, India - 390011

+91 (932)-703-1275

Pune

46 Downtown, 805+806, Pashan-Sus Link Road, Near Audi Showroom, Baner, Pune, Maharashtra, India - 411045

USA

4056, 1207 Delaware Ave, Wilmington, DE, United States America, US, 19806

+1 (765)-305-4030
Promact global office locations on world map