Nvidia Open Agent Safety Platform Secures AI Agents Operating Via ARM, Intel And Nvidia Vera CPUs.
Nvidia Open Agent Safety Platform Secures AI Agents – NVIDIA has launched Open Agent Safety Platform, a software and hardware security architecture designed to contain autonomous AI agents and enforce limits on the systems, data and tools they are permitted to access.
The platform combines OpenShell, an open-source secure runtime, with Nvidia Sentry, an independent hardware-based monitoring and enforcement layer running on BlueField-4 DPUs. The architecture is designed to place security controls outside the AI agent itself, allowing policies to remain enforceable even when an agent behaves unexpectedly.
It’s a solution that might find its way into electronic security solutions given the pace of change and the potential new threat vectors the market is witnessing – it supports ARM and Intel, as well as Nvidia Vera CPUs.
In this application, OpenShell runs agents in isolated sandboxes and allows operators to define access to files, networks, tools, processes and credentials. These permissions are converted into verifiable policies that are checked before an agent runs and continuously enforced during operation. OpenShell also maintains audit records of allow and deny decisions and sandbox activity.
According to Nvidia vice president of enterprise AI Justin Boitano, model-level safeguards are insufficient once autonomous agents are given access to enterprise infrastructure.
“Recent incidents have highlighted a fundamental hurdle for AI agents, and that is that model-level safeguards alone can’t govern what agents can access or do,” Boitano said.
The second layer, Sentry, operates independently on Nvidia BlueField-4 DPUs and continuously monitors agent behaviour from an isolated, out-of-band trust domain. Sentry uses Nvidia DOCA software to inspect agent requests and responses, verify agent identity, generate attested telemetry and apply zero-trust policies governing access to data, tools, APIs and services.
If an agent attempts to operate outside its authorised software boundary, Sentry can quarantine and stop it in milliseconds. Because enforcement takes place outside the host environment, the security layer remains separated from the agent and the software it is monitoring.
“OpenShell governs the agent’s actions, and then Sentry independently monitors and contains suspicious behaviour,” Boitano said.
OpenShell is optimised for Nvidia Vera CPUs but, as open-source software, can be extended to third-party computing platforms including Arm and Intel. Sentry is an optional additional layer for systems equipped with BlueField-4 hardware.
The architecture reflects a significant change in AI security thinking. Instead of relying entirely on the model to obey instructions, Open Agent Safety Platform treats autonomous agents more like potentially untrusted workloads, applying sandboxing, least-privilege access, continuous monitoring and independent policy enforcement.
According to Nvidia, more than 100 organisations are participating in the platform ecosystem, with partners including Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, JPMorganChase, Microsoft, Palo Alto Networks, Palantir, Perplexity, Red Hat, Salesforce, SAP and ServiceNow.
You can learn more about Nvidia Open Agent Safety Platform here or read more SEN news here.
Nvidia Open Agent Safety Platform Features
Open Agent Safety Platform At A Glance
OpenShell – open-source runtime, available now
- Open-source secure runtime for autonomous AI agents (Apache 2.0)
- Sandboxed agent execution with kernel-level isolation
- Defined access to files, networks, tools, processes and credentials
- Permissions converted to verifiable policies, checked before an agent runs and enforced while it runs
- Audit records of allow and deny decisions and sandbox activity
- Optimised for Nvidia Vera CPUs, extensible to Arm and Intel
Sentry – optional hardware layer, requires BlueField-4
- Out-of-band monitoring and enforcement on Nvidia BlueField-4 DPUs
- DOCA-based inspection of agent requests and responses
- Agent identity verification and attested telemetry
- Zero-trust control of access to data, tools, APIs and services
- Quarantines agents operating outside their boundaries in milliseconds
“Nvidia Open Agent Safety Platform Secures AI Agents Operating Via ARM, Intel And Nvidia Vera CPUs.”










