Nvidia has launched Open Agent Safety Platform, combining open-source software and a hardware reference design intended to give organizations more control over what AI agents can access and do.
The platform combines Nvidia OpenShell, a runtime for sandboxing and governing AI agents, with Nvidia Sentry, a hardware-based watchdog designed to monitor agents independently of their software environment.
OpenShell is available now. Sentry is part of a reference system design using Nvidia BlueField-4 data processing units (DPUs), so the two components have different deployment requirements.
What OpenShell can restrict
AI agents can read and write files, call APIs, access networks, use credentials and run commands, depending on how they are configured.
OpenShell is designed to place controls around those actions rather than relying on the agent to follow instructions. Nvidia says its policies can control files, processes, network requests, credentials and inference routing, while logging allow and deny decisions for auditing.
The basic approach is default-deny: an agent does not automatically receive access to everything available on the host machine. A policy can then grant specific access when required.
Nvidia’s supported-agent documentation lists configurations including Claude Code, OpenCode, Codex and GitHub Copilot CLI, although policy coverage varies between them.
A practical example: blocking GitHub access
Nvidia’s OpenShell documentation provides a concrete example in its GitHub sandbox tutorial. Claude Code is placed inside an OpenShell sandbox with a default network policy. When the agent attempts to push code to GitHub, the request is denied.
The user can then update the policy outside the sandbox to grant access to a specific GitHub repository and verify that the change works.
The example demonstrates the intended workflow: an agent can have the capability to use a service without automatically receiving unrestricted access to it. Because it comes from Nvidia, however, it demonstrates the documented workflow rather than independently establishing how OpenShell performs across different workloads.
OpenShell does not require BlueField-4
An important distinction for businesses is that OpenShell and Sentry are separate layers. Nvidia says OpenShell is open-source software that can work with third-party compute platforms, including Arm and Intel. Its documentation supports Docker, Podman, Kubernetes and MicroVM runtimes.
Sentry is the hardware-backed layer in Nvidia’s reference design. It runs on BlueField-4 DPUs and is designed to monitor agent behavior independently of the software environment.
Nvidia says Sentry can quarantine or stop an agent that moves outside its permitted boundary. It also uses Nvidia DOCA software to inspect requests and responses, verify identity and enforce access policies for data, tools, APIs and services.
Businesses can therefore deploy OpenShell’s software controls without adopting the BlueField-4 hardware used in the reference design.
What is available now?
Nvidia says OpenShell and associated software are available through its developer resources and GitHub. The documentation provides installation options for local workstations and Kubernetes.
Nvidia also lists companies including Anthropic, Microsoft, Salesforce, ServiceNow, Red Hat and Scale AI as working with the platform or its technologies. These are Nvidia’s adoption claims and do not independently establish deployment scale or effectiveness.
What this means for businesses
The practical change is that agent permissions can be enforced outside the AI model itself. That matters when an agent needs access to files, credentials, APIs or external services to complete a task. OpenShell provides a way to define and enforce those permissions while the agent runs, rather than relying solely on the model to obey a safety instruction.
Nvidia’s own AI Red Team has identified agent-security risks involving access control, arbitrary code execution, network access and exposed secrets, and has recommended controls including sandboxing and network restrictions.
OpenShell packages several of those controls into an agent runtime. Sentry adds a separate hardware enforcement layer for organizations using Nvidia’s reference design.
The useful distinction for businesses is therefore not that OpenShell makes agents safe. The announcement does not establish that. It provides a software layer for controlling and auditing agent permissions now, while the BlueField-4-based Sentry design offers an additional hardware enforcement option.
Start the conversation by posting the first comment