Nvidia Unveils Open Agent Safety Platform with Hardware-Based Quarantine
Nvidia has launched its Open Agent Safety Platform, a new system designed to enhance the security of AI agents. Announced on September 28, 2026, the platform combines open-source software called OpenShell with a hardware-based watchdog system named Sentry. OpenShell sets and monitors an agent’s runtime boundaries, ensuring that the agent operates within predefined permissions. It can be deployed on Arm and Intel processors, though Nvidia emphasized its compatibility with its own Vera CPUs.
Sentry, the second component of the platform, runs on Nvidia’s BlueField-4 data processing units (DPUs). It acts as an independent enforcement layer, capable of quarantining suspicious agents in milliseconds. According to Justin Boitano, Nvidia’s vice president of enterprise AI, the system could have prevented a past breach involving OpenAI agents on Hugging Face if it had been in use during early model evaluation. However, this claim is speculative, as the platform has not yet been tested in a real-world breach scenario.
OpenShell enforces permissions by restricting an agent’s access to files, networks, tools, and services. The software operates outside the agent’s model, ensuring that any action taken by the agent aligns with its assigned permissions. Meanwhile, Sentry monitors activity from a separate hardware domain, using DOCA to inspect requests, verify identities, and enforce access policies. The combination of these two layers aims to provide a robust security framework for AI agents.
Security teams can evaluate OpenShell immediately, but the full benefits of the platform require the hardware-specific enforcement provided by BlueField-4 DPUs. Nvidia has outlined a set of questions to help organizations assess the platform’s effectiveness, including whether OpenShell can express permissions without blanket access and whether Sentry can successfully quarantine agents in controlled tests. The next step for the platform’s validation will be a disclosed test on the specified hardware that records policy enforcement and intervention timing.