NVIDIA has introduced a platform designed to control what autonomous AI agents can access and do, as companies give such software longer and more complex tasks. The Open Agent Safety Platform combines software controls with a design for separate hardware-based monitoring.
The launch addresses a practical concern for organizations using agents to write code, retrieve information and work across connected systems. An agent may need broad access to finish a legitimate assignment, but that same access can allow an error or an unexpected action to affect data and services beyond its intended task. NVIDIA says recent security incidents have shown the need to enforce limits while agents are running.
Jensen Huang, founder and CEO of NVIDIA, said: “AI’s extraordinary potential for society will only be realized if we solve AI safety. As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering. NVIDIA Open Agent Safety Platform brings together industry, researchers and public-sector organizations to share best practices, align on evaluation methods and foster international cooperation. Together, we can raise the bar for global AI safety.”
The platform centers on two components: OpenShell, software that sets and enforces an agent’s permissions, and Sentry, a monitoring system designed to operate separately from the agent’s computing environment. Their roles are different, and so is their availability. OpenShell is broadly available; Sentry is described in NVIDIA’s announcement as part of a reference system design.
Keeping Access Within Set Limits
OpenShell places an agent in a controlled environment and applies rules to its access to files, network destinations and external services. Those rules operate outside the agent’s workload. NVIDIA says they remain in effect even when an agent runs generated code, starts another process or changes its approach to a task.
A company could, for example, permit an agent to read information from a service while blocking changes through the same connection. NVIDIA’s technical demonstration shows a policy allowing a read request to the GitHub application programming interface and rejecting a write request. The example illustrates the type of control OpenShell offers; it is not evidence that every possible route to an unauthorized action has been closed.
Credentials receive separate treatment. OpenShell can keep a service’s real credentials outside the agent’s workload and use them only for approved requests. It also records policy decisions, giving operators a way to review what was allowed or denied. If an agent needs additional access, it can propose a policy change for review rather than grant itself permission.
Adding a Separate Watchdog
Sentry is intended to add a second line of control. NVIDIA says the system runs on its BlueField-4 data processing units, separate from the agent and the software hosting it. From there, Sentry is designed to monitor activity and enforce access rules independently.
NVIDIA claims Sentry can quarantine and stop an agent within milliseconds if it attempts to cross a software boundary. That is a company claim about the proposed system, not a verified guarantee that an agent cannot cause harm.
The separation is central to NVIDIA’s approach. OpenShell governs activity as the agent works; Sentry is designed to remain outside that environment and respond if the agent exceeds its limits. OpenShell does not require BlueField-4 hardware, allowing organizations to use the software without the additional Sentry layer.
Mike Nicolls, president at SpaceXAI, said: “As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past. Customers should be able to set those limits for Cursor and Grok and trust they will hold.”
Financial Firms Among Collaborators
The announcement names Citi and JPMorganChase among financial services organizations collaborating with NVIDIA on shared, open-source agent safety technologies. It also lists companies across enterprise software, cybersecurity, cloud infrastructure and robotics.
Financial institutions have a clear reason to examine controls of this kind: an agent’s useful work may involve internal data, software tools and services with different permissions. A boundary that determines which requests are allowed could help an organization limit an agent’s reach while preserving access needed for an approved task.
NVIDIA said Salesforce has integrated OpenShell with Slack so teams can view agent activity and review requests for more access. That arrangement offers one example of human oversight alongside technical controls.
Paul Smith, chief commercial officer of Anthropic, said: “Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments. Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software.”
Francis deSouza, CEO of Scale AI, added: “Scale AI is using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for our enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start. We support agentic security with clear boundaries that define what agents can do, and controls that keep them operating within those permissions.”
What Is Available Now
NVIDIA says OpenShell and related software resources are available to developers. The company describes the software as open source and says it can be extended to work with computing platforms beyond its own. Its technical blog identifies the current OpenShell release as version 0.1.0 and details its sandbox, policy and credential controls.
The broader safety proposition is still subject to real-world testing. A system can enforce the boundaries it has been given, but organizations must define those boundaries carefully and account for the services an agent is legitimately allowed to use. NVIDIA’s technical materials acknowledge that a rule may appear restrictive while another permitted route remains open.
NVIDIA’s release also cautions that some described products and features remain in various stages of development.




