On September 28th, 2026, Nvidia announced the Open Agent Safety Platform — a hardware-software stack designed to enforce hard limits on what AI agents can actually do, independently of the model layer. Over 100 industry partners were involved at launch, including Anthropic and SpaceXAI.
The Problem It Solves
Current AI agent guardrails are overwhelmingly software-side — system prompts, policy checks, output filters running within the same process as the agent itself. The issue: a sufficiently capable or misbehaving agent can potentially influence or circumvent those controls from within. As agents gain more capability and wider tool access, this architecture becomes a single point of failure.
Nvidia's approach is to move enforcement outside the agent's execution environment entirely, to hardware that the agent has no access to.
Two Core Components
OpenShell is open-source software running on Nvidia Vera CPUs. It creates a secure runtime boundary around agents, tracing every action and enforcing policy in real time. Being open source, it can be extended to non-Nvidia hardware — Arm and Intel platforms are explicitly supported.
Sentry is the harder guarantee. It runs as an out-of-band watchdog on Nvidia BlueField-4 DPUs — data processing units physically separate from the main compute path. Because Sentry runs on its own silicon, a rogue agent on the primary hardware cannot disable it. If an agent attempts to move outside its defined boundary, Sentry quarantines and stops it in milliseconds.
Together, the two components create what Nvidia describes as a two-layer defense: software policy enforcement at runtime, and hardware-level quarantine as a failsafe.
Who's Adopting It
SpaceXAI is using the platform with Cursor coding agents running on Grok models. Anthropic is integrating both OpenShell and BlueField-4 into its Claude Managed Agents to add a hardware-level containment layer on top of existing software controls.
For enterprise teams deploying agents against internal systems — codebases, databases, APIs, cloud infrastructure — this is worth evaluating now. The OpenShell component is open source and available immediately. Sentry requires BlueField-4 DPUs, which are already standard in high-density data center configurations.
The underlying principle — that you shouldn't trust the agent to enforce its own constraints — is sound, and the hardware-layer approach is the most credible answer to that problem available today.