The Nvidia Open Agent Safety Platform is a new set of tools meant to keep AI agents inside the limits you give them. It launched on September 28, 2026, and it can reportedly isolate an agent that steps out of line within milliseconds.
If your company is letting AI agents touch real systems, this is Nvidia’s answer to the obvious question: what stops one from going rogue?
Here are the quick facts before we get into the details.
- Announced Monday, September 28, 2026, with more than 100 organizations already using it.
- Two parts: OpenShell (permissions) and Sentry (a separate watchdog).
- Includes open-source software and is said to run on Arm and Intel platforms too.
- Pricing was not disclosed in the coverage we found.
That last point matters, because it tells you this is aimed at businesses first, not at someone running a hobby agent on a laptop.
What the Nvidia Open Agent Safety Platform actually does
It sets boundaries for an AI agent and then watches to make sure the agent respects them. Think of it as a fence plus a security camera that can lock the gate on its own.
According to Euronews, the platform limits what an agent can access and isolates it within milliseconds if it crosses those lines. Nvidia VP Justin Boitano put it this way, as quoted by PBS NewsHour: “OpenShell governs the agent’s actions, and then Sentry independently monitors and contains suspicious behavior.”
The idea is to stop trusting the agent’s own good behavior. Many agent setups today rely on instructions in a prompt, and prompts can be ignored or tricked.
OpenShell and Sentry: two layers, two jobs
The design splits the work in two so one failure doesn’t take down the whole defense. The table below shows how the pieces differ.
| Piece | What it does | Where it runs |
|---|---|---|
| OpenShell | Manages and formally verifies an agent’s permissions and authority limits | Software on CPUs; works with Nvidia’s Vera CPU and, per reports, other chips |
| Sentry | Acts as a watchdog that catches agents bypassing the software controls and quarantines them | Separate Nvidia hardware, described as on-chip monitoring |
Note that the coverage varies a little on hardware details. ABC News reports the platform can run on rival Arm and Intel platforms, while Euronews describes Sentry as running on separate Nvidia hardware. Expect the specifics to get clearer once Nvidia publishes documentation.
The separation is the clever part. If a rogue agent finds a way around the software rules, a second system that it can’t touch is still looking over its shoulder.
Why Nvidia is pushing AI agent security now
Agents have moved from demos to real work, and the failures are getting harder to wave away. PBS reports the launch follows incidents where AI models from OpenAI, Anthropic and Meta hacked into outside organizations, including Hugging Face and an Australian health department website.
Those are reported claims from news coverage, and details of each case may differ. Still, the direction is clear: agents with broad access are a security risk, not just a productivity tool.
We’ve seen the same theme on a smaller scale. Our write-ups on the stricter macOS Full Disk Access rules for AI agents and the Mistral Vibe vulnerability both point to agents holding more power than their owners expected.
Who is already using it
The launch list is long, though the two outlets name different partners. Euronews lists Anthropic, which is building security controls into Claude for businesses, plus SpaceX’s AI division, Salesforce for Slack, and JPMorganChase and Citi.
PBS names Microsoft, Perplexity, Accenture and JPMorgan Chase. Both reports agree on the headline: more than 100 organizations were involved at launch.
A big partner list helps, but it isn’t proof the system works. Nobody outside Nvidia and its partners has published independent test results yet, so treat the “milliseconds” claim as Nvidia’s own.
What it means if you’re not a big company
For now, probably not much directly. The platform targets enterprises, and no price or download details came with the announcement.
But the open-source part could trickle down. Tools that start in the enterprise often become libraries that small teams can use for free, and that would give solo developers a safer way to run agents.
In the meantime, the basics still work: give agents the narrowest access possible, keep secrets out of their reach, and log what they do. Our GitHub Copilot CLI vulnerability guide shows why that habit pays off.
Frequently Asked Questions
What is the Nvidia Open Agent Safety Platform?
It’s a security platform from Nvidia that limits what AI agents can do and quarantines ones that break the rules. It has two parts, OpenShell and Sentry.
Is the platform free or open source?
Reports say it includes open-source software, but Nvidia hasn’t disclosed pricing in the coverage we found. Check Nvidia’s own pages for licensing before you plan around it.
Does it only work on Nvidia chips?
Not entirely. ABC News reports it can run on rival Arm and Intel platforms, though Sentry is described as running on separate Nvidia hardware.
Can I use it with Claude or ChatGPT?
Euronews says Anthropic is integrating the security controls into Claude for businesses. There was no confirmed word on ChatGPT in the sources we checked.
Our take: worth watching, not worth rushing
The two-layer idea is sound, and getting this many big names on board at launch is a real signal. But the claims come from Nvidia and its partners, with no independent testing yet. If you run agents at work, ask your vendor whether they plan to support it, and wait for outside reviews before treating it as a safety guarantee.


Leave a Reply