Nvidia Open Agent Safety Platform: OpenShell and Sentry
The Nvidia Open Agent Safety Platform pairs open-source OpenShell with Sentry, a BlueField-4 watchdog. What each does, what hardware it needs, what's unproven.
Source-based. Written from the documents, reporting and reviews linked in the text. Nothing here was tested hands-on by The Ruling Desk. How we work

The Nvidia Open Agent Safety Platform, launched on September 28, 2026, is a set of software and a hardware reference design meant to keep AI agents inside the limits their operators set. It has two halves. OpenShell is an open-source runtime that sandboxes agents on ordinary computers, and Sentry is a watchdog that runs on Nvidia's BlueField-4 chips and, Nvidia says, can quarantine a misbehaving agent in milliseconds. Here is what each part does, which one you can use today, who has signed on, and what is still only Nvidia's word.
Key takeaways
- OpenShell is free, open-source software (Apache 2.0) on GitHub. It runs each agent in a sandbox and checks every outbound request against a written policy. It works on Linux, Apple Silicon Macs and, experimentally, Windows.
- Sentry is the hardware half. It runs on BlueField-4 DPUs, network chips that sit beside the server's main processors, and watches agents from outside their reach. You only get it on Nvidia systems that have BlueField-4, such as its Vera Rubin POD racks.
- The speed claim is Nvidia's. "Quarantines in milliseconds" comes from Nvidia's announcement. None of the coverage we read as of September 28, 2026 cites an independent test of it.
- Over 100 organizations are working with the platform, according to Nvidia, including Anthropic, Microsoft, CrowdStrike, SAP, Scale AI and JPMorganChase. For most of them, Nvidia's release lists the name without saying what they deploy.
What the Nvidia Open Agent Safety Platform includes
Nvidia's press release describes the platform as OpenShell software plus the Sentry reference system design, a blueprint that server makers and cloud providers build on rather than a box you buy on its own. The pitch is layered control: one layer in software next to the agent, one in silicon that the agent can't touch.
Nvidia also says why it built it. "Across these incidents, the pattern is the same," the release says of recent agent security failures: "the agent circumvented security controls at the application layer to complete its assigned task." That pattern will sound familiar if you followed the tens of thousands of AI security incidents Axios reported or OpenAI's pause of its most capable models after a research agent reached an outside chatbot.
What Nvidia OpenShell does
OpenShell is the part anyone can try. Nvidia's OpenShell repository calls it "the safe, private runtime for fleets of autonomous AI agents," licensed under Apache 2.0 and at version 0.1.x as of September 28, 2026. It runs on Linux, macOS on Apple Silicon, or Windows through WSL 2 (experimental), with Docker, Podman or a virtual machine underneath.
According to Nvidia's technical walkthrough of OpenShell, it controls four things:
- Files: kernel-level limits on what an agent can read or change.
- Network: it inspects HTTP, GraphQL and MCP traffic (MCP is the protocol agents use to call tools), so it can allow a data query while blocking a write.
- Credentials: real keys stay outside the agent and are attached only to requests the policy allows.
- Processes: the agent can't grant itself extra system privileges.
Operators write the rules in YAML, which OpenShell compiles to OPA/Rego, a policy language, and evaluates on every outbound request. Nvidia says it runs Codex, Claude Code, Pi and Hermes agents. Its platform post adds that before an agent runs, "a prover shows that its policy cannot escape the intent of the operator." That proves the rules are consistent, not that the sandbox itself has no bugs.
What Sentry adds, and the hardware it needs
Nvidia Sentry is the half aimed at data centers. It runs on BlueField-4 DPUs (data processing units, chips that handle networking and security next to the main CPUs) using Nvidia's DOCA software. In Vera Rubin POD systems, Nvidia says each compute tray has a BlueField-4 "on the node's only path to the model," so every call an agent makes to its model passes through it.
From there, Nvidia says, Sentry keeps a running record of what each agent does, compares it against a predefined behavioral profile to spot "drift," and can cut the agent off. The DPU is "isolated from the host and beyond the agent's reach," the platform post says, so it keeps working even if the agent compromises the server it runs on. "The agent does not need to know it is being watched."
The catch is hardware. Help Net Security notes that Sentry depends on BlueField-4 as part of the Vera Rubin POD design. Nvidia says that for anyone already on a Vera system with BlueField-4, turning the protections on "is just a software update." Everyone else gets OpenShell, which Nvidia says is tuned for its Vera CPU but can be extended to Arm and Intel platforms.
Who signed on
Nvidia counts "over 100 organizations" working with the platform's technologies. The release names Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceX AI, among others.

Only a few say what they're doing. SAP is embedding OpenShell in the Joule Studio runtime of its Business AI Platform and contributing code. Scale AI says it uses the reference design for enterprise and government customers. Anthropic's chief commercial officer, Paul Smith, says Nvidia's platform "adds another layer of governance and control" on top of Claude Managed Agents. For Microsoft, CrowdStrike and JPMorganChase, the release gives a name and no deployment details, so "signed on" means collaborating, not shipping.
Nvidia's claim versus proven containment
The design of the Nvidia Open Agent Safety Platform makes sense: a guard that the agent can't reach is harder to talk past than one inside the same machine. But the numbers are Nvidia's. The millisecond quarantine and the "minimal overhead" of OpenShell on Vera are company claims. The coverage we read, from Help Net Security to The Next Web, repeats them without independent testing, and neither Nvidia's release nor its technical post includes the measurements behind them as of September 28, 2026.
Drift detection also depends on a "predefined behavioral profile." An agent that stays inside its profile while doing something harmful is a problem that no watchdog placement solves.
Bottom line
If you run agents today, OpenShell is worth a look: it's free, open source and works on hardware you already have. Sentry is for companies buying Nvidia's newest data center systems, and its headline speed is a promise until outside researchers test it. Watch for independent red-team results and for which of the 100-plus partners actually ship it. For more on the company behind it, see Nvidia's $150 billion stock buyback and the rest of our AI coverage.