Nvidia Releases Software to Stop AI Agents Misbehaving
Nvidia has launched the Open Agent Safety Platform, combining its broadly available OpenShell software with a Sentry reference design that monitors AI agents from a separate processor. OpenShell sets policy boundaries around an agent's access to data and tools. Sentry, running on BlueField-4 data processing units, can detect attempts to cross those boundaries and, Nvidia says, quarantine the agent within milliseconds. “Safety and security require full-stack engineering,” Huang said. The announcement gives that claim a software runtime and a hardware enforcement design. The product reaches beyond content filtering: it governs what a software agent may do inside business systems after a model has produced an instruction. For customers adopting agents that can execute code, access data and trigger transactions, that is an operational problem with implications for the choice of processors and networking equipment.
OpenShell traces agent actions and applies rules while agents run on CPUs. Nvidia says it runs with minimal overhead on Vera, the CPU it has designed for agent workloads. The runtime is open source and can be extended to Arm and Intel platforms, so organizations can start with existing compute and common policy controls. Sentry adds an isolated trust domain on BlueField-4. Nvidia's DOCA software supplies identity checks, telemetry and access policies for application programming interfaces, services and data. The division gives developers a portable entry point while defining a particular role for Nvidia silicon in more demanding installations. That architecture lets a company test the policy layer without replacing its entire computing estate. It also offers Nvidia a way to make enforcement independent of the machine running the agent, a difference that becomes more valuable when the agent can alter its own environment or has access to high-impact workflows.
The integration list is more informative than the headline partner count. Anthropic says Claude Managed Agents can add OpenShell and BlueField controls around its agent sandboxes. Salesforce has tied OpenShell to Slack, where teams can inspect agent activity and approve requests for greater access. SAP is embedding the runtime in Joule Studio, and SpaceXAI says it is using the platform with Cursor coding agents and Grok models. These are different routes to enterprise use: model infrastructure, workplace approvals, business applications and coding workflows. A control embedded in a developer sandbox reaches the place where agent actions begin, while a Slack approval loop reaches the people authorizing sensitive actions. Those placements can turn a platform announcement into a repeatable operating practice across departments rather than a separate security dashboard.
Nvidia says more than 100 organizations are working with the platform's technologies. Red Hat is running OpenShell and DOCA on its AI Factory with Nvidia; Figure, Gecko Robotics and Skild AI are building with OpenShell for machines that act in the physical world. Citi and JPMorganChase are among financial groups collaborating on shared open source agent safety technologies. That span gives the runtime multiple distribution channels, though the named relationships range from integrations to collaborative work. It also puts policy and audit requirements into computing choices made well before a customer selects a particular GPU cluster. The variety of partners also reveals where Nvidia wants the same rules to travel: from model hosting to enterprise applications and physical systems. If customers standardize those rules, they may look for processors, network interfaces and management software that implement the policy consistently across installations.
The commercial path differs by layer. OpenShell can spread across mixed CPU estates and establish a familiar policy model. Sentry could make BlueField-4 relevant wherever independent enforcement is required, while Vera's reported efficiency gives Nvidia another way to compete for agent hosts. In each case the platform inserts Nvidia into an architectural decision about how agents are governed, a decision that could shape hardware and software procurement across enterprise fleets. The platform could change competitive positions even when the first installation uses non-Nvidia CPUs. A widely adopted open runtime would give Nvidia a seat in enterprise agent architecture; BlueField-4 attachment would determine whether that software influence becomes a distinctive hardware revenue stream.
Analysis
OpenShell’s portability can seed a common policy layer across existing CPU fleets, while Sentry gives Nvidia a route to sell BlueField-4 as an independent enforcement point. That is a familiar platform trade: a broadly accessible software layer expands adoption, but the differentiated hardware earns a return only when buyers value isolation enough to deploy it. Integrations with Anthropic, Salesforce and SAP put the controls where agents are created and approved, making distribution more meaningful than a partner count. If host-based controls suffice for most workloads, OpenShell may spread widely without a comparable BlueField attachment rate.