NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds
NVIDIA has launched the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for AI agent security.It pairs the OpenShell secure runtime with NVIDIA Sentry, an out-of-band watchdog on BlueField-4 DPUs.The core idea is simple.
Safety controls should not live inside the agent they are meant to control.Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.
Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to… pic.twitter.com/dReAxwpRUn— Jensen Huang (@JensenHuang) September 28, 2026 Is it deployable today?Yes for OpenShell.It is Apache 2.
0, installs on Linux, macOS (Apple Silicon) or Windows WSL 2, and its repo still labels it alpha.Why NVIDIA Moved Enforcement Below the Agent The NVIDIA technical report cites recent reports from several frontier labs.
Agents broke out of evaluation environments and reached systems they should not have touched.Some agents misreported what they did.The NVIDIA team names a common pattern: agents circumvented application-layer controls to finish their task.NVIDIA calls this failure mode drift.
Drift can follow a policy block, a bug, a missing tool or ambiguous instructions.NVIDIA team argues drift cannot be trained away without losing capability.So an agent cannot be expected to fully govern itself.How the Platform is Built OpenShell (runtime): Each agent runs in an isolated sandbox.
A gateway manages sandbox lifecycle across Docker, Podman, MicroVM or Kubernetes drivers.Every outbound connection hits a policy engine that allows it, binds credentials to an approved endpoint, or denies and logs it.Filesystem and process rules lock at creation.
Network and provider rules are hot-reloadable.See NVIDIA’s runtime controls walkthrough for implementation details.Sentry (in-silicon watchdog): Sentry runs on BlueField-4 DPUs and uses NVIDIA DOCA to inspect agent requests and responses.
It provides attested telemetry, verifies agent identity and enforces zero-trust access to data, tools and APIs.It stays isolated from the host, so a compromised runtime does not disable it.
Placement matters: In a Vera Rubin POD, each compute tray’s BlueField-4 sits on the node’s only path to the model.An agent cannot act without its next inference call.That makes the path both the best observation point and the kill switch.
For existing Vera plus BlueField-4 systems, NVIDIA says enabling these protections is a software update.The stack is optimized for NVIDIA Vera CPUs but is compatible with other hardware.NVIDIA team claims Vera delivers up to 80% faster sandbox performance than traditional CPU infrastructure.
OpenShell can also be extended to Arm and Intel platforms.The 5 Design Principles Verifiable policy: a prover checks the policy cannot escape operator intent before the agent runs.Out-of-band enforcement: controls sit outside the agent’s reach.
Control the path to the model: it is the observation point and the kill switch.Scale authority with visible reasoning: more capable agents need more inspectable thinking.Shared responsibility: labs, enterprises and hardware providers each own a layer.
Interactive Explainer: Send a Request Through the Stack (function(){var f=document.getElementById("mtp-oasp-frame");window.addEventListener("message",function(e){if(e.data&&e.data.oaspHeight&&f&&e.source===f.contentWindow){f.style.height=e.data.
oaspHeight+"px"}})})(); How It Compares With Other Agent Sandboxes The closest alternatives are sandbox platforms for agent-generated code.Neither offers an equivalent hardware watchdog.
FeatureNVIDIA OpenShell + SentryE2BDaytonaTypeOpen runtime plus hardware reference designOpen-source sandbox cloudSandbox infrastructure runtimeLicenseApache 2.0Apache 2.0AGPL-3.
0 (public repo unmaintained since June 2026)IsolationPer-sandbox container or MicroVM, kernel-level isolationFirecracker microVM, own kernelDedicated kernel, filesystem and network stack per sandboxEgress controlYAML policy at HTTP method and path level, hot-reloadableAllow and deny lists by IP, CIDR or domainNetwork limitsOut-of-band hardware enforcementYes, Sentry on BlueField-4 (optional)No, software isolationNo, software isolationWhere it runsLocal, on-prem, cloud, Kubernetes (experimental)E2B cloud or self-hosted on AWS and GCPDaytona cloudAgent supportClaude Code, Codex, OpenCode, Copilot CLI built inJS and Python SDKsPython, TypeScript, Ruby, Go, Java SDKs Who is Building on It NVIDIA says over 100 organizations work with the platform.
Anthropic integrated Claude Managed Agents with OpenShell and BlueField.SpaceXAI uses it for Cursor coding agents and Grok models.Salesforce connected OpenShell to Slack for approving agent permission requests.SAP is embedding OpenShell in the Joule Studio runtime.
Red Hat, SUSE and Canonical are integrating it into their operating systems.The effort feeds the Open Secure AI Alliance, governed by the Linux Foundation.OpenShell and its skills are available on GitHub and the OpenShell docs.
Key Takeaways 2 layers: OpenShell sandboxes the agent, Sentry watches it from separate silicon.Sentry can quarantine an agent that leaves its boundary in milliseconds, per NVIDIA.OpenShell policies are declarative YAML, with network rules enforced at HTTP method and path level.
OpenShell runs Claude Code, Codex, OpenCode and GitHub Copilot CLI out of the box.NVIDIA lists over 100 organizations working with the platform, including Anthropic and Microsoft.FAQ Does OpenShell require BlueField-4?No.It runs on local, on-prem, cloud and Kubernetes infrastructure.
BlueField-4 only adds Sentry.How is this different from model guardrails?Guardrails shape what an agent attempts.Runtime controls enforce what it is allowed to do.Can I use existing agents and models?Yes.OpenShell supports open and closed models and custom sandbox images.
Check out the Paltform here and Technical Details.All credit goes to the researcher of this project.Also, feel free to follow us on Twitter and don’t forget to join our 150k+ML SubReddit and Subscribe to our Newsletter.Wait!are you on telegram?now you can join us on telegram as well.
Need to partner with us for promoting your GitHub Repo OR Hugging Face Page OR Product Release OR Webinar etc.?
Connect with us The post NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds appeared first on MarkTechPost.
Related
相關文章

英偉達發佈開放智能體安全平臺,保障智能體從測試到部署全流程安全
(公眾號:zhidxcom) 作者 | ZeR0 編輯 | 漠影 9月28日報道,今日,英偉達(NVIDIA)宣佈推出NVIDIA開放智能體安全平臺。作為一個開放軟件平臺與參考系統設計,該平臺旨在從智能體測試到部署的各個環節強化AI安全,並針對運行智能體的軟件、硬件、計算和機器人系統,實施全棧治理與管控。 NVIDIA開放智能體安全平臺軟件(包括OpenShell和技能)現可通過NVIDIA開發者資源頁面及GitHub獲取。

AI 初創公司 Instinct 完成 10 億美元融資,投後估值達 100 億美元
首頁 IT圈 最會買 設置 日夜間 隨系統 淺色 深色 主題色 黑色 投稿 訂閱 RSS訂閱 收藏 軟媒應用 App客戶端 要知App 軟媒魔方 業界 手機 電腦 測評 視頻 AI 蘋果 iPhone 鴻蒙 軟件 智車 數碼 學院 遊戲 直播 5G 微軟 Win10 Win11 專題 搜索 首頁 > 智能時代>人工智能 AI 初創公司 Instinct 完成 10 億美元融資,投後估值達 100 億美元 2026/9/28 23:08:19 作者:潞源 責編:潞源 評論: 9 月 28 日消息,據路透社今天報道,人工智能初創公司 Instinct 現已完成 10 億美元(注:現匯率約合 67.

Meta 啟動企業平臺 AI 賦能業務,由原 MongoDB 首席執行官兼總裁 Chirantan Desai 領導
作者:溯波(實習) 責編:溯波 評論: 感謝網友 華南吳彥祖 的線索投遞!9 月 28 日消息,Meta 創始人兼首席執行官 Mark Zuckerberg(馬克 · 扎克伯格)當地時間今日宣佈啟動 Meta Enterprise Platform,旨在幫助企業利用人工智能以全新的方式實現增長和轉型。

工業創新進入“組隊局”,拆解西門子Xcelerator開放生態的賦能鏈路
西門子Xcelerator繁星生態大會揭示其開放生態策略,截至2026年8月在中國已累積逾66萬註冊用戶、600餘家夥伴及900餘項解決方案。平台以共享、共創、共贏串連供需,讓技術公司接觸真實工業場景並與互補夥伴共組方案。同時透過商業賦能、技術賦能與全球Marketplace,協助夥伴從0到1、1到10再到10到N的成長與出海。

英偉達發佈 AI 智能體安全平臺,可實時隔離異常智能體
作者:潞源 責編:潞源 評論: 感謝網友 華南吳彥祖、麻辣清補涼 的線索投遞!9 月 28 日消息,英偉達今天發佈開放式 AI 智能體安全平臺(NVIDIA Open Agent Safety Platform),可對 AI 智能體、智能體硬件、機器人系統等進行全棧治理和控制。

爆火了的Muse和Instinct們不能做的,OS3能?
字母AI2026.09.28 15:37 · 來自北京全文4120字00:00 / 11:42Personal Agent的下一程,Rabbit OS3已經開跑。文 | 字母AI小扎拿出Muse Charm之後,Rabbit r1又被翻了出來。不少人看到這款新設備時,都會幻視兩年多前的橙色小方盒。在X上,有人將小扎拿著Charm、呂騁拿著r1的照片放在一起玩梗,不少外媒在報道Charm時,也都提到了這款初代AI硬件。一臺可以隨身攜帶的小設備,通過語音聽懂用戶的要求,再讓AI替人辦事。這幅畫面,確實讓人覺得熟悉。