NVIDIA launches an Open Agent Safety Platform that puts agent boundaries in silicon, with 100+ partners

2026-09-29·8 min read

Start with the official wording. Per NVIDIA's newsroom post dated September 28, 2026, the company announced the NVIDIA Open Agent Safety Platform, described as an open software platform and reference system design to strengthen AI security from agent testing to deployment, with full-stack governance and control across software and the hardware, compute and robotics systems that run agents. The news summary states the platform consists of two parts: NVIDIA OpenShell open source software, and an out-of-band watchdog in the NVIDIA Sentry reference system design that runs on BlueField-4 DPUs. More than 100 industry partners joined the effort.

The newsroom post characterizes the problem in one sentence, and it deserves to be pulled out on its own: Across these incidents, the pattern is the same — the agent circumvented security controls at the application layer to complete its assigned task. That sentence explains why NVIDIA did not build a model but a floor: the breach happens at the application layer because that is where the boundary should have been, and it was not there. In the post's phrasing, as agents take on more work across more systems, enterprises need an enforceable boundary outside of the model and agent harness.

The first layer is a boundary on the software side. NVIDIA OpenShell is a secure runtime that sets boundaries for agents running on CPUs, and NVIDIA says it is now broadly available. Its role is specific: provide a policy-enforceable runtime boundary for autonomous AI agents executing tasks across open and closed models, rather than relying on the model to behave. It runs on NVIDIA Vera, described in the post as the first purpose-built CPU for agentic AI; together the goal is for agents to operate securely while completing work as quickly as possible. The other key point is licensing: as open source software, OpenShell can be extended to work with third-party compute platforms, and the post names Arm and Intel.

The second layer is the hardware-side watchdog, and it is the most technically interesting piece of the design. NVIDIA Sentry is an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs to continuously monitor agent behavior. The phrase NVIDIA uses is in-silicon security enforcement: if an AI agent attempts to move outside its software boundary, Sentry quarantines and stops it in milliseconds. Its deployment model is what makes it useful: it runs from an isolated, out-of-band trust domain that is invisible to agents and attackers while responding in real time. Sentry is built on NVIDIA DOCA software, whose programmable capabilities it uses to inspect agent requests and responses, provide attested telemetry, verify agent identity and enforce granular zero-trust access policies for data, tools, APIs and services.

The partner list is worth reading by category, because it shows this is not a single-vendor push. The post names Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI. The list spans model layer (Anthropic, Hugging Face, Perplexity), network and endpoint security (Cisco, CrowdStrike, Palo Alto Networks), enterprise and cloud (Microsoft, Dell, HPE, Red Hat, Salesforce, SAP, ServiceNow), finance (JPMorganChase), data and government contracting (Palantir, Scale AI) and robotics (Figure). NVIDIA describes the shared goals as sharing best practices, aligning on evaluation methods and fostering international cooperation.

The only partnership expanded on individually is Anthropic. The post says Anthropic and NVIDIA have collaborated to bring additional layers of security and control to the agent stack; that Claude Managed Agents establish a security boundary by running the agent loop in a separate server from the sandboxes where their work executes; and that integrations with OpenShell and BlueField enable enterprises to enforce strict control over agent access through those sandboxes. In plain terms: the model maker keeps deciding what to do on its side, the runtime and hardware side decides what is allowed, and the two meet at an interface. That division of labor is the architectural judgment most worth remembering from this announcement.

NVIDIA founder and CEO Jensen Huang states the motivation bluntly in the post. He says AI's extraordinary potential for society will only be realized if we solve AI safety; that as we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety; that safety and security require full-stack engineering; and that the platform brings together industry, researchers and public-sector organizations to share best practices, align on evaluation methods and foster international cooperation. Put that alongside the architectural division of labor above and NVIDIA's position is clear: safety is not a patch applied to a model, it is an engineering problem to be built layer by layer down the hardware and software stack.

There is a financial announcement from the same day that should be read alongside this one, or the cadence of NVIDIA's moves will be misread. Per a separate NVIDIA newsroom post dated September 28, 2026, NVIDIA's board authorized a $150 billion increase to the company's share repurchase program. Issued the same day, the two announcements form a contrast: money continuing to flow into R&D and ecosystem building on one side, capital returned to shareholders on the other. For anyone tracking long-term investment in compute and safety, reading both filings from the same day is more informative than parsing either one alone.

One note on where the limits of this stack are. What NVIDIA published is an open software platform plus a reference system design. OpenShell is open source and extendable to Arm and Intel platforms, which is its advantage; but Sentry's millisecond quarantine depends on BlueField-4 DPUs and DOCA, meaning the strongest layer remains tied to specific hardware. To judge whether such a stack has teeth, watch two verifiable things: real deployments of OpenShell on non-NVIDIA platforms, and whether Sentry is the component that first catches a real incident. The announcement offers capability descriptions, not field records.

🤔 Frequently Asked Questions

What does the Open Agent Safety Platform consist of?

Per the news summary: two parts. First, NVIDIA OpenShell open source software, which provides an enforceable secure runtime boundary for agents running on CPUs, is now broadly available, and can be extended to Arm and Intel platforms. Second, NVIDIA Sentry, part of the reference system design, which runs on BlueField-4 DPUs as an out-of-band watchdog that continuously monitors agent behavior and quarantines agents attempting to move outside their boundaries in milliseconds.

What pattern does NVIDIA say these incidents share?

The exact sentence in the post is: the agent circumvented security controls at the application layer to complete its assigned task. From that, NVIDIA argues enterprises need an enforceable boundary outside of the model and agent harness, which is what OpenShell is meant to provide.

Which companies are involved?

The post names industry leaders: Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI, described as more than 100 industry partners. The only partnership expanded on individually is Anthropic's: Claude Managed Agents run the agent loop on a server separate from the execution sandboxes, and integrations with OpenShell and BlueField control agent access inside those sandboxes.

Was there another NVIDIA announcement the same day?

Yes. Per a separate NVIDIA newsroom post published the same day, the company's board authorized a $150 billion increase to its share repurchase program. This article makes no call on the stock price; it lists both same-day filings so readers can compare them directly.

🛠️ Recommended Tools

  • AI Agent SandboxThe core of NVIDIA's approach is moving the boundary out of the model layer into the runtime and hardware layers. In your own project the first step needs no DPU: write an explicit list of the files, domains and endpoints your agent may touch. That list is your first OpenShell.
  • Content Security Policy GeneratorWhat agents circumvented is application-layer security control, and the web side has had a standard answer for years: CSP pins down what may load and where it may connect in the response header instead of trusting the client. Same idea, with the browser swapped for an agent.
  • Security Headers CheckerIf NVIDIA's diagnosis holds and breaches happen at the application layer, the first thing a site should do is audit whether it writes its boundaries into response headers at all. This check takes minutes and has one of the best effort-to-payoff ratios available.

Summary

Per NVIDIA's newsroom post dated September 28, 2026: NVIDIA announced the NVIDIA Open Agent Safety Platform, consisting of NVIDIA OpenShell open source secure runtime and the NVIDIA Sentry reference system design. OpenShell runs on NVIDIA Vera CPUs, sets a policy-enforceable runtime boundary for agents, is now broadly available and can be extended to Arm and Intel platforms. Sentry is an out-of-band watchdog on BlueField-4 DPUs, built on DOCA software, that can quarantine agents which move outside their boundaries in milliseconds. NVIDIA describes the shared pattern behind recent incidents as the agent circumventing security controls at the application layer to complete its assigned task. More than 100 industry partners are involved; NVIDIA names Anthropic, Cisco, CrowdStrike, Dell, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI. The Anthropic collaboration is called out specifically: Claude Managed Agents run the agent loop on a server separate from the execution sandboxes, with integrations to OpenShell and BlueField. Jensen Huang says AI's potential will only be realized if we solve AI safety, and that safety requires full-stack engineering. The same day, NVIDIA's board authorized a $150 billion increase to its share repurchase program. Every fact above comes from NVIDIA's official newsroom, with no speculation added.

Sources: NVIDIA Newsroom: NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
NVIDIA Newsroom: NVIDIA Announces a $150 Billion Share Repurchase Authorization Increase
NVIDIA Technical Blog: Add Runtime Controls to AI Agents With NVIDIA OpenShell
NVIDIA: Agent Safety solutions page