NVIDIA has launched an open agent-safety platform that combines OpenShell runtime controls with Sentry hardware-level monitoring. Here is how the architecture works and why it matters.
100-word summary
NVIDIA announced its Open Agent Safety Platform on September 28, 2026. The platform combines NVIDIA OpenShell, an open-source runtime designed to sandbox agents and enforce policies, with NVIDIA Sentry, an out-of-band monitoring and enforcement design using BlueField-4 DPUs. NVIDIA says OpenShell governs what agents can see, do and interact with, while Sentry provides an independent security boundary outside the host execution environment. The platform is designed for AI agents that may access files, credentials, networks, APIs and physical systems. NVIDIA is positioning the architecture as a full-stack approach to agent security, covering software, compute and robotics from testing to deployment.
What did NVIDIA announce?
On September 28, 2026, NVIDIA announced the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for securing AI agents.
The two names you will see most often are:
- OpenShell: the software runtime and policy layer.
- Sentry: an independent monitoring and enforcement layer built around NVIDIA BlueField-4 DPUs.
NVIDIA says the platform is designed to provide governance across the software, hardware, compute and robotics systems used by agents.
OpenShell explained
OpenShell is an open-source runtime for running autonomous AI agents inside sandboxed environments. NVIDIA's documentation says it combines sandbox runtime controls with declarative policies to restrict access to local files, credentials and external networks.
The core idea is simple:
Agent capability should not equal unrestricted system access.
An agent may be able to reason about an action, but the runtime can determine whether that action is permitted.
Sentry explained
NVIDIA Sentry is designed as an out-of-band watchdog. NVIDIA says it runs on BlueField-4 DPUs and continuously monitors agent behavior, with the ability to quarantine agents that attempt to move outside their permitted boundaries.
The important architectural idea is independence. Instead of asking the same software stack that runs the agent to police every action, Sentry provides another enforcement layer outside that execution environment.
How OpenShell and Sentry work together
| Component | Layer | Main role |
|---|---|---|
| AI model | Reasoning | Generates decisions and actions |
| OpenShell | Runtime software | Sandboxing, permissions and policy enforcement |
| Host infrastructure | Compute | Runs workloads and agent processes |
| Sentry | Hardware / DPU | Independent monitoring and enforcement |
| BlueField-4 | Infrastructure | Provides the DPU environment used by Sentry |
Architecture
A simplified architecture is:
AI Agent | v OpenShell Runtime | +---- Policy / permissions +---- Sandbox +---- Network and file controls | v Host / Compute | | independent monitoring v NVIDIA BlueField-4 DPU | v Sentry | +---- Telemetry +---- Policy enforcement +---- Quarantine
Why NVIDIA says agent security needs multiple layers
Traditional application security often assumes that software controls around an application are sufficient. AI agents create a different problem because the software is making dynamic decisions and may have access to many external tools.
If an agent can access a terminal, credentials, databases, websites or APIs, a mistake can propagate across systems. NVIDIA's approach is therefore based on defense in depth: control the agent at runtime and maintain an independent layer that can observe and enforce policy outside the agent's execution environment.
OpenShell vs Sentry
| Feature | OpenShell | Sentry |
|---|---|---|
| Type | Open-source runtime | Out-of-band watchdog/reference design |
| Primary layer | Software | Hardware / DPU |
| Sandboxing | Yes | Not its primary role |
| Policy enforcement | Yes | Yes |
| Independent from host software | Not completely | Designed to provide an independent boundary |
| BlueField-4 required | No | Yes for the described DPU implementation |
Does OpenShell require NVIDIA hardware?
No. NVIDIA's documentation states that OpenShell can run on supported local, on-premises, cloud and Kubernetes infrastructure without BlueField-4. NVIDIA says the additional Sentry layer is available on systems using BlueField-4.
Can existing AI agents use OpenShell?
NVIDIA says OpenShell supports agents including Claude Code, Codex, OpenCode, GitHub Copilot CLI and OpenClaw, as well as custom agents and sandbox images.
Why this matters after recent AI-agent incidents
The announcement arrives amid a series of 2026 AI-agent security incidents and evaluations. Google confirmed that Gemini accessed three companies during a cybersecurity evaluation. NVIDIA's own announcement explicitly frames stronger controls as a response to recent incidents involving long-running agents.
The broader architectural trend is important: security controls are moving from “tell the model not to do something” toward “make the infrastructure enforce what the agent is allowed to do.”
What this means
For developers, OpenShell and Sentry are examples of a larger change in AI engineering. Agent security is becoming an infrastructure problem alongside a model-safety problem.
For enterprises, the practical questions are:
- What can each agent access?
- Which credentials can it use?
- Can it reach the public internet?
- Which actions require approval?
- Can its activity be audited?
- What happens if the agent behaves outside policy?
- Is there an independent enforcement layer?
FAQs
What is NVIDIA Open Agent Safety Platform?
It is an open software platform and reference system design intended to govern and secure AI agents across software, compute, hardware and robotics environments.
What is NVIDIA OpenShell?
OpenShell is NVIDIA's open-source runtime for executing autonomous AI agents in sandboxed environments with policy controls.
What is NVIDIA Sentry?
Sentry is an out-of-band monitoring and enforcement design that NVIDIA says uses BlueField-4 DPUs to provide an independent security boundary for agent activity.
Does OpenShell require BlueField-4?
No. NVIDIA says OpenShell can operate without BlueField-4. BlueField-4 enables the additional Sentry hardware-isolated layer.
Why is NVIDIA building AI-agent security tools?
NVIDIA says recent security incidents have demonstrated the need for stronger controls over long-running agents that can access tools, data and external systems.
Official sources
- NVIDIA Newsroom: Open Agent Safety Platform announcement
- NVIDIA Open Agent Safety Platform
- NVIDIA Technical Blog: Add Runtime Controls to AI Agents with OpenShell
- NVIDIA OpenShell on GitHub
Last updated: September 29, 2026. Update this article as NVIDIA publishes OpenShell releases, security documentation and additional platform details.