Layered Architecture: OpenShell Software and Sentry Hardware
The NVIDIA Open Agent Safety Platform is built upon a layered safety architecture that integrates both software and hardware components to provide robust security and continuous monitoring. At its core are NVIDIA OpenShell, an open-source software, and NVIDIA Sentry, a reference system design. OpenShell functions as an open-source secure runtime environment, executing autonomous AI agents within sandboxed environments that feature kernel-level isolation. This software component is designed to run on NVIDIA Vera CPUs, providing governance tools that dictate what an agent can perceive, perform, and interact with. OpenShell traces all agent actions and enforces defined policies, ensuring that controls remain active even if an agent behaves unexpectedly, thereby limiting the potential spread of errors. As open-source software, OpenShell can also be extended to other compute platforms. Complementing OpenShell, NVIDIA Sentry operates as an independent, out-of-band watchdog. Sentry is a hardware-based component that runs on NVIDIA BlueField-4 Data Processing Units (DPUs), offering continuous in-silicon telemetry of agent activity and enforcing security policies. This hardware layer enables Sentry to quarantine agents in milliseconds if policy violations are detected, providing an additional, independent layer of security enforcement. The combined architecture of OpenShell on Vera CPUs and Sentry on BlueField DPUs delivers full-stack governance and continuous monitoring, though NVIDIA notes the platform is also compatible with other hardware systems.Full-Stack Governance and Control Features
The platform's design emphasizes comprehensive governance and control mechanisms to mitigate risks associated with autonomous AI agents. OpenShell provides a secure runtime that combines sandboxed execution, controlled resource access, credential protection, and formal policy verification. These features are enforced outside the agent's workload, allowing operators to manage agent behavior independently of its immediate environment and govern how agents interact with enterprise systems, data, and external services. This includes the ability to govern individual workloads and groups, with separate workspaces, permissions, and service access for teams sharing infrastructure. For an additional layer of security, Sentry provides in-silicon security enforcement through continuous monitoring and policy enforcement. This out-of-band capability ensures that agent behavior is constantly scrutinized against predefined rules. The platform also includes a Policy Prover, a tool that uses formal logic to verify the permissions granted by a policy. This prover can establish that modeled permissions remain within operator-defined boundaries or identify a concrete action that exceeds them, providing crucial evidence for human and AI reviewers to assess proposed policy changes. This integrated approach aims to ensure that AI agents adhere to established rules and prevent unintended consequences, even when agents behave unexpectedly.Practical Benefits for AI Agent Deployment
For organizations deploying AI agents, the NVIDIA Open Agent Safety Platform offers significant practical benefits by enhancing security across the entire agent lifecycle. The platform delivers full-stack governance, runtime control, and continuous monitoring, which are critical for securing enterprise AI agents from their initial testing phases through to live deployment. This comprehensive approach allows developers to establish safer boundaries for AI agents, thereby preventing unintended actions that could arise from agents pursuing objectives without adequate constraints. By providing tools to keep AI agents isolated, observable, and governed, the platform supports teams as agents take on increasingly complex tasks. This continuous oversight and control are designed to strengthen AI agent security across various industries, addressing the challenges posed by agents that might otherwise operate beyond their intended scope. Industry leaders from across the AI ecosystem, including Anthropic, Cisco, CrowdStrike, Dell Technologies, Microsoft, and Salesforce, are joining NVIDIA in this initiative to strengthen AI safety across the full stack of infrastructure, software, models, and robotics.Next Steps and Future Considerations for Adoption
NVIDIA encourages developers and product managers to engage with the Open Agent Safety Platform to enhance the security of their AI agents. Recommended next steps include getting started with NVIDIA OpenShell to run agents in sandboxed environments with kernel-level isolation and exploring the platform's layered safety architecture. Developers can also consult technical walkthroughs for detailed implementation of runtime controls with OpenShell. The long-term practical security value of the platform will depend on several factors, including independent evaluation of its effectiveness, its portability across various processor architectures at scale, and the broader open-source community's engagement. Community adoption will hinge on whether the platform's policies are found to be auditable and its architecture deemed sound. This launch signifies a notable shift in the industry's approach to agent security, moving beyond sole reliance on an agent's internal instructions to enforcing restrictions at both the runtime and hardware layers.| Component | Function | Layer of Enforcement | Benefit |
|---|---|---|---|
| OpenShell | Provides a secure runtime boundary for AI agents, tracing all actions and enforcing policies. | Software layer, sandboxed execution with kernel-level isolation on NVIDIA Vera CPUs. | Enables developers to set safer boundaries for AI agents and prevent unintended consequences from agent actions. |
| Sentry | Acts as an out-of-band watchdog, continuously monitoring agent behavior and enforcing policies. | Hardware-based component on NVIDIA BlueField-4 DPUs, providing in-silicon telemetry and policy enforcement. | Provides an additional, independent layer of security, enabling rapid quarantine of agents in milliseconds. |
| Platform Integration (OpenShell + Sentry) | Combines software and hardware for comprehensive agent security, including formal policy verification. | Full-stack governance across software and hardware, with continuous monitoring. | Delivers full-stack governance and continuous monitoring, mitigating risks from testing to deployment and ensuring agents adhere to rules. |
Sources
- NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment — NVIDIA Newsroom
- NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring | NVIDIA Technical Blog — NVIDIA Technical Blog
- OpenShell — BUILD
- NVIDIA Open Agent Safety Platform — NVIDIA











