StorageReview.com

NVIDIA Open Agent Safety Platform: OpenShell on the CPU, Sentry on BlueField-4, and 100-Plus Partners From Anthropic to SpaceXAI

AI  ◇  Enterprise

NVIDIA has launched the NVIDIA Open Agent Safety Platform, an open software platform and reference system design that puts guardrails around autonomous AI agents at two layers: a secure runtime on the host CPU and an out-of-band watchdog on the DPU that the agent can’t see. NVIDIA says the pattern in recent agent security incidents has been the same each time, with the agent circumventing application-layer controls to finish its assigned task, and its answer is to move enforcement below the application. More than 100 organizations are working with the platform at launch, including Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Microsoft, Palantir, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI.

NVIDIA Open Agent Safety Platform context: Jensen Huang on stage at GTC 2026 in front of the NemoClaw reference agent diagram, with the OpenShell sandbox runtime highlighted among the tools, memory, and model components

“AI’s extraordinary potential for society will only be realized if we solve AI safety,” said Jensen Huang, founder and CEO of NVIDIA. “As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering. NVIDIA Open Agent Safety Platform brings together industry, researchers, and public-sector organizations to share best practices, align on evaluation methods, and foster international cooperation. Together, we can raise the bar for global AI safety.”

OpenShell: A Runtime Boundary on the CPU

The software half is NVIDIA OpenShell, the secure runtime that first appeared in the NemoClaw reference stack at GTC 2026 and has since shown up in the Dell, HPE, and SUSE AI Factory stacks. NVIDIA now calls it broadly available. OpenShell runs agents in sandboxed environments with kernel-level isolation, converts an operator’s instructions into verifiable policies before the agent starts, and enforces those policies during execution: which files, networks, tools, processes, and credentials the agent can touch. The boundary sits outside the model and the agent harness, so it applies the same way to open and closed models. The code is on GitHub under an Apache 2.0 license.

NVIDIA says OpenShell runs with minimal overhead on NVIDIA Vera, which the company calls the first purpose-built CPU for agentic AI, and because it’s open source, it can be extended to third-party platforms, including Arm and Intel processors.

Sentry: In-Silicon Enforcement on BlueField-4

The hardware half is NVIDIA Sentry, the reference system design’s out-of-band watchdog, which runs on NVIDIA BlueField-4 DPUs and monitors agent behavior from a trust domain the agent and any attacker can’t reach. NVIDIA describes it as in-silicon enforcement: if an agent tries to move outside its software boundary, Sentry quarantines and stops it in milliseconds. It combines threat detection, hardware-based agent governance, and data access protection, and it operates independently of the host, so a compromised agent runtime doesn’t take the watchdog with it.

Sentry is built on NVIDIA DOCA, which supplies the programmability to inspect agent requests and responses, provide attested telemetry, verify agent identity, and enforce granular zero-trust access policies for data, tools, APIs, and services. NVIDIA’s technical blog notes that in Vera Rubin POD systems, the BlueField-4 sits on the node’s only path to the model, which is what lets Sentry observe and enforce at line speed without the host’s cooperation.

Who’s Building With It

Anthropic and NVIDIA have paired the platform with Claude Managed Agents, which already separates the agent loop from the sandboxes where its work executes by running the two on different servers; OpenShell and BlueField integrations let enterprises enforce strict control over what agents can reach through those sandboxes. “Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments,” said Paul Smith, chief commercial officer of Anthropic. “Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software.”

SpaceXAI is using the platform for Cursor coding agents and Grok models. “As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, president at SpaceXAI. “Customers should be able to set those limits for Cursor and Grok and trust they will hold.” Scale AI is incorporating the technologies into the agentic infrastructure layer of its Scale GenAI Portfolio for enterprise and government customers, citing isolation, policy enforcement, and auditability.

On the application side, Salesforce and NVIDIA have integrated OpenShell with Slack so teams can view agent activity and audit events and approve or reject an agent’s requests for additional permissions from inside Slack. SAP is embedding OpenShell with the Joule Studio runtime on the SAP Business AI Platform, contributing engineering work to OpenShell, and working on interoperability standards through the Open Secure AI Alliance. Figure, Gecko Robotics, and Skild AI are building with OpenShell to put agent safety controls into robots that act in the physical world, and Citi and JPMorganChase are collaborating on shared open-source agent safety technologies for financial services, alongside a group of energy and grid operators that includes Hitachi Energy, EPRI, NextEra Energy, Schneider Electric, and Siemens Energy.

Canonical, SUSE, and Red Hat are integrating the platform into their operating systems, and Red Hat runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA across hybrid cloud environments. Infrastructure partners offering systems and services that support the platform include Baseten, Cisco, CoreWeave, Dell Technologies, GMI Cloud, HPE, HP Inc., Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure, Supermicro, and Together AI.

Availability

NVIDIA Open Agent Safety Platform software, including OpenShell and its skills, is available now through NVIDIA’s developer resources and GitHub. The platform feeds into the Open Secure AI Alliance, which NVIDIA initiated with more than 120 organizations and which is governed by the Linux Foundation; the alliance runs open research, skills, and tools for agent security, along with projects such as the Shared AI Findings Exchange, or SAFE.

NVIDIA Open Agent Safety Platform

Engage with StorageReview

Newsletter | YouTube | Podcast iTunes/Spotify | Instagram | Twitter | TikTok | RSS Feed

Harold Fritts

I have been in the tech industry since IBM created Selectric. My background, though, is writing. So I decided to get out of the pre-sales biz and return to my roots, doing a bit of writing but still being involved in technology.