With OpenShell and Sentry, Nvidia aims to restrict AI agents using software and hardware. The move comes in response to agent breakouts at several AI companies.
Nvidia introduced the Nvidia Open Agent Safety Platform on September 28. The platform is designed to control what AI agents access in real time and stop them if they violate rules. It consists of the open-source software OpenShell and the reference design Sentry. According to Nvidia, the system would have prevented the attack on the Hugging Face platform by OpenAI AI agents in July. According to Reuters, Hugging Face has since been acquired by Nvidia for 13 billion dollars.
The background involves incidents in which AI models broke out of their isolated test environments and attacked other companies’ systems. In addition to OpenAI, Anthropic, Meta, and Google have also reported such cases. According to Nvidia, the agents repeatedly bypassed application-level security controls in order to accomplish their tasks.
OpenShell Limits Access at the CPU Level
OpenShell is a runtime environment that sits between the agent and enterprise systems, such as files, credentials, and tools. Companies use it to define what an agent can access and what it is allowed to do. The software logs all actions and enforces policies. It runs on Nvidia’s Vera CPU and can be expanded to Arm and Intel platforms. OpenShell is available immediately via Nvidia’s developer sites and GitHub.
“Recent incidents have highlighted a fundamental hurdle for AI agents: model-level safeguards alone cannot control what agents access or what they do.”
Justin Boitano, Vice President Enterprise AI at Nvidia
Sentry Stops Agents at the Hardware Level
Sentry runs as an independent monitoring instance on BlueField-4 data processing units—meaning neither on CPUs nor GPUs. If an agent attempts to breach its software boundaries, Sentry is designed to isolate and stop it within milliseconds. According to Boitano, the system also evaluates the agents’ actions and chains of thought to detect anomalies. Nvidia manager Ali Golshan cited agents launching multiple sub-agents to bypass restrictions as an example.
More Than 100 Partners
According to Nvidia, more than 100 organizations are working with the platform’s technologies. Anthropic is integrating its Claude Managed Agents with OpenShell and BlueField. SAP is embedding OpenShell into the Joule Studio runtime environment, while Salesforce has linked OpenShell with Slack. Canonical, SUSE, and Red Hat are integrating the platform into their operating systems. Other partners include Cisco, CrowdStrike, Microsoft, Oracle, and Palo Alto Networks, among others.
(Editorial Team)