What changed
On September 28, NVIDIA launched Open Agent Safety Platform, combining the broadly available OpenShell secure runtime with a Sentry reference design for BlueField-4 DPUs. OpenShell runs agents inside isolated sandboxes, applies filesystem, process, network and provider-access policy outside the agent process, and can bind credentials only to approved endpoints. Sentry moves monitoring into an isolated DPU trust domain and is designed to quarantine agents that cross policy boundaries. NVIDIA says more than 100 organizations are working with the platform technologies, while OpenShell is available as open-source software and can be extended beyond NVIDIA CPUs.
Why it matters
Coding and autonomous agents increasingly need real credentials, network access and the ability to run arbitrary developer tools. Application-level prompts and model guardrails are weak boundaries when the agent itself can manipulate its environment. OpenShell makes the execution environment the enforcement point and keeps credentials away from the agent process; Sentry adds a second observer outside the host CPU. For builders, that creates a concrete alternative to trusting each agent harness to implement its own sandbox correctly.
OpenShell puts policy outside the agent
OpenShell isolates each agent and enforces filesystem, process and network rules below the harness. Outbound requests pass through policy checks, and provider credentials can be injected only for approved destinations rather than exposed directly to the agent.
Policy changes are themselves checked
NVIDIA says OpenShell includes a policy prover that uses formal verification to identify whether a proposed rule expands access beyond an allowed boundary. Riskier changes can therefore be held for human review instead of being accepted because an agent requested them.
Sentry adds an independent hardware observer
The Sentry reference design runs on BlueField-4 DPUs, outside the agent's host execution domain. NVIDIA says it correlates activity, tool access and policy decisions and can quarantine an agent in milliseconds if it attempts to move beyond its software boundary.
The runtime is already usable without the full NVIDIA stack
OpenShell is open source and supports local Linux, Apple Silicon macOS and experimental Windows WSL 2 workflows, with Docker, Podman and MicroVM-backed sandboxes. Its documented agent paths include Claude Code, Codex, OpenCode and GitHub Copilot CLI.
The strongest claims still need independent testing
The millisecond quarantine claim, minimal-overhead claim and large ecosystem adoption figures come from NVIDIA. The architecture is inspectable, but independent adversarial testing and production overhead data will matter more than launch-partner counts.