
NVIDIA has introduced Open Agent Safety Platform, combining OpenShell runtime controls with Sentry hardware monitoring for AI agents. The open software and reference system design covers testing and deployment across computing and robotics systems.
Organizations can deploy individual components according to their requirements. The controls operate outside the model and agent software to address attempts to bypass application-level restrictions.
“AI’s extraordinary potential for society will only be realized if we solve AI safety,” said Jensen Huang, founder and CEO of NVIDIA. “As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering. NVIDIA Open Agent Safety Platform brings together industry, researchers and public-sector organizations to share best practices, align on evaluation methods and foster international cooperation. Together, we can raise the bar for global AI safety.”
Runtime Boundaries and Hardware Enforcement
OpenShell, now broadly available, sets runtime boundaries for agents running on CPUs. It controls task execution across open and closed models, independently of the model and the software managing the agent.
NVIDIA says OpenShell runs with minimal overhead on its Vera CPU. Developers can extend the open-source software to third-party computing platforms, including Arm and Intel.
The reference design includes NVIDIA Sentry, an out-of-band watchdog running on BlueField-4 data processing units. Sentry continuously monitors agent activity and enforces security policies independently of the software running the agent. NVIDIA says Sentry can quarantine and stop an agent within milliseconds if it attempts to leave its software boundary.
Sentry combines threat detection, hardware-based controls and data access protection within an isolated trust domain. NVIDIA describes this domain as invisible to agents and attackers and responsive in real time.
Built on NVIDIA DOCA software, Sentry inspects agent requests and responses, provides attested telemetry and verifies agent identity. It also enforces granular, zero-trust access policies for data, tools, application programming interfaces and services.
Agent and Enterprise Software Integrations
Anthropic and NVIDIA have integrated OpenShell and BlueField with Claude Managed Agents. Claude Managed Agents runs the agent loop on a separate server from the sandboxes where tasks execute. The integrations give enterprises controls over agent access through those sandboxes.
“Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments,” said Paul Smith, chief commercial officer of Anthropic. “Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software.”
SpaceXAI is using NVIDIA Open Agent Safety Platform for Cursor coding agents and Grok models.
“As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, president at SpaceXAI. “Customers should be able to set those limits for Cursor and Grok and trust they will hold.”
Scale AI is working with NVIDIA to incorporate the technologies into the agent infrastructure layer of Scale GenAI Portfolio.
“Scale AI is using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for our enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start,” said Francis deSouza, CEO of Scale AI. “We support agentic security with clear boundaries that define what agents can do, and controls that keep them operating within those permissions.”
Salesforce and NVIDIA have integrated OpenShell with Slack. Teams can view agent activity and audit events, then approve or reject requests for additional permissions directly in Slack.
SAP is embedding OpenShell into the Joule Studio runtime, part of SAP Business AI Platform. SAP is also contributing engineering work to OpenShell and working with NVIDIA on interoperability standards through the Open Secure AI Alliance.
Robotics, Infrastructure and Industry Participation
More than 100 organizations are working with NVIDIA Open Agent Safety Platform technologies. Alongside SAP and Scale AI, participants include Accenture, Armadin, Cadence, Cognition, CrowdStrike, Cisco, Dassault Systèmes, Deloitte, EY, Hugging Face, IBM, Irregular, Perplexity, Microsoft, ServiceNow, Siemens, Synopsys, OpenClaw, Palantir and Palo Alto Networks.
Figure, Gecko Robotics and Skild AI are building with OpenShell to incorporate agent safety controls into autonomous systems. Citi and JPMorgan Chase are collaborating with NVIDIA on shared open-source agent safety technologies.
Energy and infrastructure participants include Hitachi Energy, EPRI, NextEra Energy, Quanta Services, SPP, Schneider Electric, Siemens Energy and Worley.
Canonical, SUSE and Red Hat are integrating the technologies into operating systems. Red Hat runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA, which supports building, deploying and managing AI across hybrid cloud environments.
Infrastructure providers offering systems that use or support the technologies include Baseten, Cisco, CoreWeave, Dell Technologies, GMI Cloud, HPE, HP Inc., Irregular, Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure, Supermicro and Together AI.
Availability and Open-Source Work
NVIDIA Open Agent Safety Platform software, including OpenShell and skills, is available through NVIDIA’s developer resources and GitHub.
The initiative supports the Open Secure AI Alliance, which NVIDIA initiated alongside more than 120 organizations. Governed by the Linux Foundation, the alliance supports open research, skills, tools and projects, including the Shared AI Findings Exchange (SAFE).
Source: NVIDIA
About NVIDIA
![]()
NVIDIA, founded in 1993 and headquartered in Santa Clara, CA, designs and manufactures graphics processing units, systems on chips, networking hardware, and AI intelligence software such as CUDA. Its products serve industries including gaming, data centers, autonomous vehicles, professional visualization, robotics, health care, and energy. The company introduced the GPU in 1999 and later expanded into accelerated computing and AI infrastructure. In gaming, its GPUs support high-performance rendering, while in AI and high-performance computing, its systems provide the infrastructure for training and deploying large-scale models. NVIDIA also develops tools for robotics and autonomous driving.
