# NVIDIA moves AI-agent containment below the model layer with OpenShell and Sentry

NVIDIA's Open Agent Safety Platform combines an open-source runtime boundary with an out-of-band hardware watchdog. OpenShell can restrict files, processes, networks and credentials outside an agent's own process; Sentry adds independent BlueField-4 monitoring that NVIDIA says can quarantine an escaping agent in milliseconds.

The useful shift is architectural: agent permissions no longer have to depend only on the model or harness behaving correctly. OpenShell puts policy enforcement in the execution environment, while Sentry is designed to keep watching from a separate hardware trust domain.

- Status: Active
- Published: 2026-09-30T06:13:55+13:00
- Updated: 2026-09-30T06:13:55+13:00
- Categories: Artificial Intelligence, Cloud & Infrastructure, AI Agents, Compute & AI Infrastructure
- Tags: agent security, AI agents, BlueField, NVIDIA, OpenShell, sandboxing
- Canonical HTML: https://beyondthe.news/dossiers/nvidia-open-agent-safety-platform-openshell-sentry-agent-containment

## What changed

On September 28, NVIDIA launched Open Agent Safety Platform, combining the broadly available OpenShell secure runtime with a Sentry reference design for BlueField-4 DPUs. OpenShell runs agents inside isolated sandboxes, applies filesystem, process, network and provider-access policy outside the agent process, and can bind credentials only to approved endpoints. Sentry moves monitoring into an isolated DPU trust domain and is designed to quarantine agents that cross policy boundaries. NVIDIA says more than 100 organizations are working with the platform technologies, while OpenShell is available as open-source software and can be extended beyond NVIDIA CPUs.

## Why it matters

Coding and autonomous agents increasingly need real credentials, network access and the ability to run arbitrary developer tools. Application-level prompts and model guardrails are weak boundaries when the agent itself can manipulate its environment. OpenShell makes the execution environment the enforcement point and keeps credentials away from the agent process; Sentry adds a second observer outside the host CPU. For builders, that creates a concrete alternative to trusting each agent harness to implement its own sandbox correctly.

## OpenShell puts policy outside the agent

OpenShell isolates each agent and enforces filesystem, process and network rules below the harness. Outbound requests pass through policy checks, and provider credentials can be injected only for approved destinations rather than exposed directly to the agent.

## Policy changes are themselves checked

NVIDIA says OpenShell includes a policy prover that uses formal verification to identify whether a proposed rule expands access beyond an allowed boundary. Riskier changes can therefore be held for human review instead of being accepted because an agent requested them.

## Sentry adds an independent hardware observer

The Sentry reference design runs on BlueField-4 DPUs, outside the agent's host execution domain. NVIDIA says it correlates activity, tool access and policy decisions and can quarantine an agent in milliseconds if it attempts to move beyond its software boundary.

## The runtime is already usable without the full NVIDIA stack

OpenShell is open source and supports local Linux, Apple Silicon macOS and experimental Windows WSL 2 workflows, with Docker, Podman and MicroVM-backed sandboxes. Its documented agent paths include Claude Code, Codex, OpenCode and GitHub Copilot CLI.

## The strongest claims still need independent testing

The millisecond quarantine claim, minimal-overhead claim and large ecosystem adoption figures come from NVIDIA. The architecture is inspectable, but independent adversarial testing and production overhead data will matter more than launch-partner counts.

## Key details

- NVIDIA announced Open Agent Safety Platform on September 28, 2026.
- OpenShell is broadly available open-source runtime software for agent isolation and policy enforcement.
- OpenShell enforces filesystem, process, network and provider-access rules outside the agent process.
- Credentials can be bound to approved endpoints rather than exposed directly to an agent.
- Sentry is a reference design using BlueField-4 DPUs as an out-of-band monitoring and enforcement layer.
- NVIDIA says Sentry can quarantine boundary-escaping agents in milliseconds; this is a vendor claim.
- OpenShell documents support paths for Claude Code, Codex, OpenCode and GitHub Copilot CLI.
- NVIDIA says more than 100 organizations are working with the platform technologies.
- OpenShell can be extended to third-party compute platforms including Arm and Intel, according to NVIDIA.

## Builder takeaways

- Treat the agent runtime, not the model prompt, as the security boundary for filesystem, process, network and credential access.
- Keep long-lived credentials outside the agent process and inject them only into policy-approved requests where practical.
- Separate agent monitoring from the workload when higher-assurance containment is required.
- OpenShell is inspectable and usable without adopting the entire NVIDIA hardware stack, so builders can evaluate the runtime independently.
- Do not treat NVIDIA's quarantine latency or overhead claims as independently established until external testing appears.

## What to watch

- Independent security audits and escape testing against OpenShell.
- Measured overhead for real coding-agent and long-running-agent workloads.
- When Sentry/BlueField reference designs become deployable products rather than reference architecture.
- Whether agent vendors adopt a common policy format or continue shipping incompatible sandbox layers.
- Evidence that OpenShell's formal policy checks prevent practical privilege-expansion attacks.

## Uncertainties

- NVIDIA's millisecond-quarantine and minimal-overhead claims are vendor-produced.
- The launch-partner count does not establish how many organizations run the stack in production.
- Sentry availability and operational economics are less concrete than the downloadable OpenShell runtime.
- Kubernetes support in OpenShell is still described as experimental.

## Timeline

- **2026-09-28 — NVIDIA launches Open Agent Safety Platform:** NVIDIA announces OpenShell plus the Sentry reference design and says more than 100 organizations are working with the technologies.
- **2026-09-28 — OpenShell broadly available:** NVIDIA publishes the runtime, documentation and repository for agent sandboxing, policy enforcement and credential brokering.

## Sources

- [NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment](https://nvidianews.nvidia.com/news/open-agent-safety-platform) — NVIDIA · primary announcement · 2026-09-28T00:00:00+13:00. Launch scope, OpenShell/Sentry architecture, availability and ecosystem claims.
- [NVIDIA OpenShell](https://www.nvidia.com/en-us/ai/openshell/) — NVIDIA · primary product documentation · 2026-09-28T00:00:00+13:00. Runtime boundary, sandbox, policy prover and gateway architecture.
- [NVIDIA/OpenShell](https://github.com/NVIDIA/OpenShell) — NVIDIA · primary repository · 2026-09-28T00:00:00+13:00. Inspectable implementation, supported agents, platforms, provider/credential model and licence.
- [NVIDIA releases AI safety software it says could have stopped Hugging Face hack](https://www.reuters.com/legal/litigation/nvidia-releases-ai-safety-software-it-says-could-have-stopped-hugging-face-hack-2026-09-28/) — Reuters · independent reporting · 2026-09-28T00:00:00+13:00. Independent launch context and qualification of NVIDIA's security claims.

