
NVIDIA and more than 100 partners launched the Open Agent Safety Platform to secure autonomous AI agents through runtime access controls, independent monitoring, and rapid containment. Its OpenShell and Sentry components are designed to restrict tools and resources, detect abnormal behavior, and isolate agents without relying on the agents to police themselves.
Key takeaways
- NVIDIA’s platform uses infrastructure-level controls instead of relying only on prompts, model alignment, or agent reasoning.
- OpenShell provides runtime sandboxing and policy enforcement for data, tools, networks, and system resources.
- Sentry independently monitors agent activity and can serve as an external enforcement and kill-switch layer.
- NVIDIA says the platform can inspect network packets and tool queries at line speed and quarantine abnormal agents within milliseconds.
- Enterprises still need to assess availability, supported environments, pricing, production readiness, and integration commitments before deployment.
NVIDIA and more than 100 partners launched the Open Agent Safety Platform on September 28, 2026, introducing an infrastructure-first approach to AI agent security. The platform is designed to restrict what autonomous agents can access, monitor their activity independently, and contain them when their behavior moves beyond approved boundaries.
The launch comes as enterprises give AI agents broader access to tools, data, applications, and business workflows. Instead of relying only on prompts, model alignment, or an agent’s own reasoning to prevent misuse, NVIDIA’s approach places safety controls in the runtime environment around the agent.
What the NVIDIA Open Agent Safety Platform Does
The platform combines two primary components: OpenShell, an open-source runtime boundary, and Sentry, an independent monitoring and enforcement layer.
OpenShell is intended to let organizations define the information, systems, and tools an agent may access. It checks those restrictions during execution, helping enforce policies such as:
- Allowing an agent to read approved files but not modify them
- Limiting tool calls to specific applications or APIs
- Preventing access to sensitive databases or credentials
- Restricting network connections and other resources
Sentry operates separately from the agent’s CPU or GPU environment. This separation gives it an independent view of the agent’s activity and reduces reliance on the agent or its host environment to report policy violations accurately.
NVIDIA says the system can inspect network packets and tool queries at line speed, generate telemetry, and act as an external kill switch when execution diverges from a verified profile. The company also says agents that attempt to move outside approved boundaries can be quarantined within milliseconds.
How OpenShell and Sentry Contain Rogue AI Agents
OpenShell provides the runtime sandboxing layer. It is designed to run on NVIDIA’s Vera AI CPU and enforce access policies while an agent is operating, rather than checking behavior only before or after a task.
Sentry adds monitoring outside the agent’s execution environment. It can observe requests, interactions, and other runtime signals, then compare behavior with established policies or verified activity profiles. If an agent begins making unusual tool calls, accessing unauthorized resources, or attempting to expand its privileges, the platform can block or isolate it.
This creates a layered model for AI agent guardrails:
- Define boundaries for data, tools, networks, and systems.
- Enforce restrictions during runtime through OpenShell.
- Monitor independently through Sentry and its telemetry.
- Contain abnormal behavior without waiting for the agent to cooperate.
NVIDIA is positioning OpenShell as the broadly available software layer and Sentry as a hardware-backed reference design. Reported plans include support for Arm and Intel x86 architectures, although the full availability and deployment scope remain to be established.
Why Infrastructure-Level AI Agent Safety Matters for Enterprises
AI agents are increasingly expected to complete multi-step tasks with limited supervision. That autonomy can improve productivity, but it also creates a larger security boundary. An agent with access to email, code repositories, financial systems, or internal documents may cause damage through a faulty instruction, a compromised tool, or an unexpected chain of actions.
NVIDIA’s central argument is that agents should not be expected to police themselves. Infrastructure must enforce organizational boundaries even when the model behaves unpredictably.
Key enterprise use cases for tool access control and monitoring
Organizations could use the platform to:
- Restrict agents to approved tools and data sources
- Isolate autonomous workflows from sensitive systems
- Detect policy violations and unusual execution patterns
- Record telemetry for audits and incident response
- Stop or quarantine agents before abnormal activity spreads
Reported participants and collaborators include Anthropic, Cisco, CoreWeave, CrowdStrike, Dell Technologies, Hugging Face, JPMorganChase, Mistral, Microsoft, Palantir, Salesforce, Scale AI, and SAP. However, participation does not necessarily mean that every organization has adopted OpenShell or committed to a specific integration.
Important questions also remain around platform availability, supported environments, pricing, production readiness, and the scope of future integrations. The launch establishes NVIDIA’s direction, but enterprises will need implementation details before assessing the platform against their existing AI governance and security architecture.
For security teams, the immediate takeaway is clear: safer autonomous workflows will require more than model-level controls. Runtime sandboxing, independent AI agent observability, strict tool access control, and rapid containment are becoming core elements of enterprise AI safety.
By the numbers
More than 100 partners participated in the Open Agent Safety Platform launch.
NVIDIA’s September 28, 2026 announcement, as described in the article, identifies the launch as a collaboration involving over 100 partners.
The platform is built around two primary components: OpenShell and Sentry.
The article describes OpenShell as the runtime boundary and Sentry as the independent monitoring and enforcement layer.
NVIDIA says abnormal agents can be quarantined within milliseconds.
This is a capability claim attributed to NVIDIA; real-world response times will depend on deployment architecture, workload, and policy configuration.
NVIDIA says Sentry can inspect network packets and tool queries at line speed.
The article reports this as a stated platform capability from NVIDIA, subject to validation across supported production environments.
Step by step
- 01
Define approved agent boundaries
Specify which files, databases, applications, APIs, network destinations, credentials, and other resources each agent may access.
- 02
Enforce runtime policies with OpenShell
Deploy the runtime boundary to restrict tool calls and resource access while the agent is executing, including read-only or deny rules for sensitive systems.
- 03
Monitor activity independently with Sentry
Configure external telemetry and monitoring to observe network packets, tool queries, requests, and execution signals outside the agent’s own environment.
- 04
Quarantine abnormal agent behavior
Create enforcement rules that block, isolate, or terminate agents when they make unauthorized requests, attempt privilege expansion, or diverge from verified activity profiles.
Frequently asked questions
What is NVIDIA’s Open Agent Safety Platform?
NVIDIA’s Open Agent Safety Platform is an infrastructure-focused system for controlling, monitoring, and containing autonomous AI agents. It combines OpenShell, an open-source runtime boundary, with Sentry, an independent monitoring and enforcement layer. The platform is intended to protect enterprise data, tools, applications, and workflows when agents operate with limited supervision.
How do OpenShell and Sentry secure AI agents?
OpenShell enforces access policies during agent execution, while Sentry monitors activity independently and can trigger containment. OpenShell can restrict files, tools, APIs, networks, and credentials. Sentry is designed to identify unusual behavior and provide an external block, quarantine, or kill-switch capability.
Why do enterprises need infrastructure-level AI agent safety?
Infrastructure-level controls prevent an agent from exceeding approved boundaries even when its instructions, reasoning, tools, or behavior are compromised. Agents connected to email, code repositories, financial systems, and internal documents can create wider risks than conventional software. Runtime sandboxing and independent monitoring add enforcement that does not depend on the agent cooperating.
How quickly can NVIDIA’s platform contain a rogue AI agent?
NVIDIA says agents can be quarantined within milliseconds when they move beyond approved boundaries. The company also says Sentry can inspect network packets and tool queries at line speed. These are NVIDIA’s reported capabilities, and enterprises will need production testing to validate performance in their own environments.
Which companies are involved in the Open Agent Safety Platform?
NVIDIA says more than 100 partners are involved, including Anthropic, Cisco, CrowdStrike, Microsoft, Salesforce, SAP, and others. Participation indicates collaboration or involvement in the launch, not necessarily adoption of OpenShell or commitment to a particular integration. Deployment scope, availability, pricing, and supported environments remain important evaluation questions.
