An AI assistant that answers questions is one thing. An agent that can edit files, call services and keep working for hours needs a different kind of supervision: a boundary it cannot simply talk its way around.
On 28 September 2026, Nvidia announced its Open Agent Safety Platform. It combines OpenShell software with a hardware-based monitoring design called Sentry. The announcement marks a commercial infrastructure launch, with different components at different stages of availability. Nvidia’s announcement
Permissions that sit outside the agent
An AI agent is software that uses a model to choose and carry out actions towards a goal. Access to useful tools also gives it opportunities to make consequential mistakes.
OpenShell creates a controlled environment for that work. Nvidia’s technical documentation describes isolated workspaces, restrictions on service access and a way to keep real credentials outside the agent’s own environment. Permission changes can be reviewed separately from the software requesting them. OpenShell technical explanation
Think of the difference between asking a visitor to stay in one room and giving that visitor a key that opens only that room. The second approach places the restriction in the surrounding system.
OpenShell 0.1.0 is open source and supports existing agent frameworks. Nvidia says it can run CPU and GPU workloads across containers, virtual machines and Kubernetes environments. These are different ways of packaging and managing computing jobs. Supported capabilities

A separate watchdog in the hardware
Sentry adds another layer. In Nvidia’s reference design, it runs on a BlueField-4 data processing unit—a specialised processor that can handle infrastructure and security work separately from the main application.
The design places monitoring outside the agent’s normal computing environment. Nvidia says Sentry can detect attempts to cross security boundaries and quarantine agents within milliseconds. That is a company performance claim, rather than an independently verified guarantee covering every deployment. Sentry design and claims
The technical description also treats safety as a shared responsibility across model developers, organisations running agents and infrastructure providers. It does not reduce the problem to buying one chip. Nvidia’s reference architecture
The boundary still needs the right rules
Our assessment is that this approach addresses an increasingly important part of AI deployment: controlling what software can do after it receives a task. But strong enforcement cannot rescue a badly chosen permission policy. An agent authorised to perform a harmful action can remain inside its boundaries while causing damage.
The practical test will be how well these controls work under independent testing and everyday workloads, including their effect on performance and legitimate tasks. Nvidia has supplied a framework for that work. It has not demonstrated that AI agents are now universally safe.
Featured image: representative photograph by Umberto / Unsplash. Images illustrate the subject and do not show the specific project or experimental equipment described.


Leave a Reply