What Was Announced
On 28 September 2026 Nvidia launched the Open Agent Safety Platform, backed by more than 100 partner organisations including Anthropic, SpaceXAI, Salesforce, SAP, CrowdStrike, Palo Alto Networks and Cisco.
The interesting part is not that Nvidia shipped agent security software. It is where the enforcement lives.
OpenShell: The Software Half
OpenShell is an open-source secure runtime published under the Apache 2.0 licence at version 0.1.0. It is already available through Nvidia developer resources and on GitHub.
It provides kernel-level isolation, and it works by converting administrative parameters into verifiable policies before a workload runs. If formal proof verification finds an escape path out of the sandbox, execution is denied. That is a meaningfully different model from the usual approach of running the agent and watching what it does.
Apache 2.0 at 0.1.0 means you can read it, fork it and ship it commercially - and also that it is a first public release, so treat the version number as the warning it is.
Sentry: The Hardware Half
Sentry is an optional out-of-band monitor that runs on Nvidia BlueField-4 data processing units, built on Nvidia DOCA software.
The design point is isolation from the thing it is watching. Sentry sits on the host node's route to the model, inspects network packets and tool queries at line speed, and can act as an external kill switch when it sees divergent execution patterns. Because it runs on the DPU rather than the host, it keeps working when the host operating system has been compromised.
BlueField-4 units are integrated into every compute tray in Nvidia Vera Rubin POD systems. Enterprises already running Vera and BlueField-4 can turn the protections on with a software update.
Why an Agent Kill Switch Belongs on a Different Chip
Every software-only agent sandbox shares one weakness: the thing enforcing the policy runs on the same machine as the thing being restrained. If an agent escapes into the host, it is now inside the same trust boundary as its own supervisor.
Putting the monitor on a separate processor with its own network path removes that shared fate. It is the same reasoning behind a hardware security module or a baseboard management controller, applied to autonomous software instead of secrets.
Whether it works as advertised is an open question - this launched a day ago and OpenShell is at 0.1.0. But the architecture is addressing a real gap rather than repackaging an existing one.
The Catch
The software half is genuinely open. The hardware half requires Nvidia BlueField-4 DPUs.
So a platform announced as open in fact splits along a familiar line: you can adopt OpenShell anywhere, and you get the part that survives a compromised host only if you buy Nvidia infrastructure. That is a reasonable commercial position and it is worth naming plainly rather than reading past.
Who Should Care
- Running agents in production with real credentials: OpenShell is worth evaluating now. Pre-execution policy verification is a stronger guarantee than runtime observation.
- Already on Nvidia infrastructure: if you have Vera systems with BlueField-4, Sentry is a software update away.
- Building agent tooling: Apache 2.0 at 0.1.0 is an invitation. The integration surface is being defined right now.
- Experimenting with agents on a laptop: this is not for you yet.
FAQ
Is OpenShell free?
Yes. It is published under the Apache 2.0 licence, version 0.1.0, available via Nvidia developer resources and GitHub.
Do I need Nvidia hardware?
For OpenShell, no. For Sentry, yes - it runs on BlueField-4 DPUs.
How is this different from running an agent in a container?
A container isolates at the operating system level and is enforced by the host. OpenShell verifies policies before execution and denies the workload if an escape path can be proven; Sentry monitors from separate hardware that a compromised host cannot reach.
Who are the partners?
More than 100 organisations. Named ones include Anthropic, SpaceXAI, Salesforce, SAP, CrowdStrike, Palo Alto Networks and Cisco.