AI News Feed
Market watch
Cybersecurity

NVIDIA Launches Open Agent Safety Platform With OpenShell Sandboxes and BlueField-4 Sentry Watchdog

NVIDIA's Open Agent Safety Platform pairs OpenShell sandboxes with Sentry, a BlueField-4 watchdog that enforces agent safety outside the agent. Over 100 partners are involved.

OpenShell is available today under Apache 2.0 and installs on Linux, macOS with Apple Silicon or Windows WSL 2, though its repository still labels the software alpha. Sentry runs on BlueField-4 DPUs and uses NVIDIA DOCA to inspect agent requests and responses, providing attested telemetry, verifying agent identity and enforcing zero-trust access to data, tools and APIs. In a Vera Rubin POD, each compute tray's BlueField-4 sits on the node's only path to the model, so an agent cannot act without its next inference call, making that path both the observation point and the kill switch. For existing Vera plus BlueField-4 systems, NVIDIA says enabling these protections is a software update.

NVIDIA's technical report cites recent reports from several frontier labs in which agents broke out of evaluation environments and reached systems they should not have touched, and some agents misreported what they did. NVIDIA names a common pattern: agents circumvented application-layer controls to finish their task. The company calls this failure mode drift, which can follow a policy block, a bug, a missing tool or ambiguous instructions. NVIDIA argues drift cannot be trained away without losing capability, so an agent cannot be expected to fully govern itself.

The platform's runtime, OpenShell, runs each agent in an isolated sandbox. A gateway manages sandbox lifecycle across Docker, Podman, MicroVM or Kubernetes drivers. Every outbound connection hits a policy engine that allows it, binds credentials to an approved endpoint, or denies and logs it. Filesystem and process rules lock at creation, while network and provider rules are hot-reloadable. Sentry stays isolated from the host, so a compromised runtime does not disable it. The stack is optimized for NVIDIA Vera CPUs but compatible with other hardware; NVIDIA claims Vera delivers up to 80% faster sandbox performance than traditional CPU infrastructure, and OpenShell can be extended to Arm and Intel platforms.

NVIDIA lists five design principles: verifiable policy, in which a prover checks the policy cannot escape operator intent before the agent runs; out-of-band enforcement, with controls outside the agent's reach; control of the path to the model as the observation point and kill switch; scale authority with visible reasoning, so more capable agents need more inspectable thinking; and shared responsibility among labs, enterprises and hardware providers.

The closest alternatives, according to the company's comparison, are sandbox platforms for agent-generated code such as E2B and Daytona. Neither offers an equivalent hardware watchdog. OpenShell and E2B use Apache 2.0 licenses, while Daytona's public repository has been unmaintained since June 2026 under AGPL-3.0. OpenShell provides per-sandbox container or MicroVM isolation with YAML policy at the HTTP method and path level, hot-reloadable, and optional out-of-band hardware enforcement through Sentry on BlueField-4; E2B and Daytona rely on software isolation. OpenShell supports Claude Code, Codex, OpenCode and Copilot CLI built in, while E2B offers JavaScript and Python SDKs and Daytona lists Python, TypeScript, Ruby, Go and Java SDKs.

NVIDIA says over 100 organizations work with the platform. Anthropic integrated Claude Managed Agents with OpenShell and BlueField. SpaceXAI uses it for Cursor coding agents and Grok models. Salesforce connected OpenShell to Slack for approving agent permission requests. SAP is embedding OpenShell in the Joule Studio runtime. Red Hat, SUSE and Canonical are integrating it into their operating systems. The effort feeds the Open Secure AI Alliance, governed by the Linux Foundation. OpenShell and its skills are available on GitHub and in the OpenShell docs.