Photo: Coolcaesar, CC BY-SA 4.0, via Wikimedia Commons — Nvidia's headquarters in Santa Clara, California, photographed in August 2018.

NVIDIA Bundles Its AI Agent Security Tools Into One Platform; No Price or Date for Its Hardware Watchdog

NVIDIA on Monday put a new name over a set of tools meant to keep AI agents from doing something they weren’t supposed to do, folding an already-public open-source runtime and a hardware-based reference design into what it calls the “NVIDIA Open Agent Safety Platform.” The company says the goal is “to strengthen AI security from agent testing to deployment.” Most of what changed Monday is packaging and a partner list — the core open-source piece was announced in March; the code has been public on GitHub since February.

What the platform does

The platform has two parts. The first, called OpenShell, is software that sits underneath an AI “agent” — a program that can take actions on its own, such as writing code or sending messages, rather than answering a question. NVIDIA describes OpenShell as a “secure runtime boundary” that “traces all actions and enforces policy” while an agent runs, and says it operates with “minimal overhead” on NVIDIA’s Vera CPUs. It is open source and, per NVIDIA, can be extended to run on Arm and Intel chips as well.

The second part, called Sentry, is part of what NVIDIA calls a “reference system design,” meaning a blueprint NVIDIA’s partners can use to build their own systems; the release does not say whether Sentry itself can be downloaded or bought separately. Sentry runs as an “out-of-band watchdog” on BlueField-4 DPUs — specialized processing chips, separate from a computer’s main processor, that handle networking and security tasks. NVIDIA says Sentry can quarantine and stop an agent that tries to move outside its assigned boundary “in milliseconds,” calling this “in-silicon security enforcement” — meaning it’s enforced in the chip itself, NVIDIA says — built on DOCA, NVIDIA’s software for its DPUs.

What’s new since March

OpenShell itself is not new. NVIDIA first announced it at GTC in March, describing it then as “the newly announced NVIDIA OpenShell runtime,” installed by a tool called NemoClaw, which NVIDIA said installs OpenShell “in a single command” for OpenClaw, an open-source platform for running autonomous AI agents. Its GitHub repository, licensed under Apache 2.0, was created Feb. 24, 2026, and had drawn nearly 9,000 stars by Monday. It has had numbered releases since March 16; the 0.1 series began Sept. 25, with version 0.1.2 out Monday.

What Monday actually added: the umbrella “platform” name, NVIDIA’s description of OpenShell as “now broadly available,” the Sentry reference design, and a list of over 100 partner organizations.

Who says they’re using it

NVIDIA named partners including Anthropic, SpaceXAI, Scale AI, Salesforce, SAP, Microsoft, CrowdStrike, Palo Alto Networks, Cisco, Citi, JPMorganChase and NextEra Energy. Three gave attributed quotes in the release. Paul Smith, Anthropic’s chief commercial officer, said: “Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments.” Mike Nicolls, president at SpaceXAI, said: “As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past.” Francis deSouza, CEO of Scale AI, said: “Scale AI is using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for our enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start.” NVIDIA also said it initiated an “Open Secure AI Alliance” with more than 120 organizations, governed by the Linux Foundation.

What NVIDIA didn’t say

The release gives no date or price for Sentry-based systems. The release covers availability only for the software: “NVIDIA Open Agent Safety Platform software, including OpenShell and skills, are available through the NVIDIA developer resources page and GitHub.” It describes Sentry as part of a reference design.

The company also did not name any specific security incident behind the announcement, saying only that “recent security incidents have underscored the need” for tools like this and that in each case “the agent circumvented security controls at the application layer to complete its assigned task.” No incident is identified. And the claim that Sentry stops an agent “in milliseconds” is NVIDIA’s own; no independent test has surfaced.

What is available now

The OpenShell software is available now as open source, through NVIDIA’s developer page and GitHub, NVIDIA says. The hardware-backed part — Sentry on BlueField-4 DPUs — is a reference design, and NVIDIA gave no date or price for it.

Sources and further reading

Share this article