NVIDIA has introduced an Open Agent Safety Platform that pairs two pieces of technology: OpenShell, an open source runtime boundary for agents, and Sentry, a reference system design that watches agent behavior from outside the machine running it. The company says the platform covers governance across software, hardware, compute and robotics, and it is aimed at securing agents from the testing stage through to deployment.
OpenShell is the part organizations can use right away, since NVIDIA says it is now broadly available. It runs on NVIDIA Vera CPUs and traces everything an agent does while enforcing policy at the same time. NVIDIA also says the runtime can be extended to third-party compute platforms, naming Arm and Intel among them. No price for the platform was disclosed.
Sentry takes a different approach. It is an out-of-band watchdog that runs on BlueField-4 DPUs, monitors agent behavior continuously, and enforces security policies independently in silicon. When an agent steps outside its boundaries, Sentry can quarantine it in milliseconds, according to NVIDIA. The watchdog is built on NVIDIA DOCA software, which inspects agent requests and responses, provides attested telemetry, verifies agent identity, and enforces zero-trust access policies for data, tools, APIs and services. Organizations can deploy whichever elements of the platform fit their requirements.
NVIDIA points to recent security incidents as motivation, describing a pattern in which an agent circumvented application-layer controls. Anthropic worked with NVIDIA on securing the agent stack, and Claude Managed Agents run the agent loop separately from sandboxes, with OpenShell and BlueField integrations enforcing sandbox access control. Paul Smith, chief commercial officer of Anthropic, said, "Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments."
The platform already has users and integration work underway. SpaceXAI is using it for Cursor coding agents and Grok models, while Scale AI is incorporating it into the infrastructure behind its Scale GenAI Portfolio. Salesforce integrated OpenShell with Slack so activity and audit events can be viewed and permissions approved, and SAP is embedding OpenShell in the Joule Studio runtime, part of its Business AI Platform, while contributing engineering to the project and working on interoperability standards through the Open Secure AI Alliance.
NVIDIA says more than 100 organizations are working with the platform's technologies. Robotics builders involved include Figure, Gecko Robotics and Skild AI, and financial services collaborators include Citi and JPMorganChase. Energy and infrastructure names span Hitachi Energy, EPRI, NextEra Energy, Quanta Services, SPP, Schneider Electric, Siemens Energy and Worley. Canonical, SUSE and Red Hat are integrating the platform into operating systems, with Red Hat running OpenShell and DOCA on Red Hat AI Factory with NVIDIA, and infrastructure partners include Baseten, CoreWeave, GMI Cloud, Nebius, Oracle Cloud Infrastructure and Together AI.
The announcement lands days after NVIDIA's Isaac ROS 5.0 release for agentic, open source robotics development at ROSCon Toronto, and follows its own arguments that physical AI deployment needs safety at every layer. It also comes more than two weeks after the company pitched an open robotaxi stack, a market projected at $400 billion by 2035.













