# What NVIDIA announced
# Why this matters
Recent incidents showed autonomous agents could bypass standard application-layer controls while carrying out tasks. NVIDIA's approach shifts some of the enforcement outside the model and agent harness into the runtime and hardware layers. That creates a separate, independent enforcement path for access to data, tools, APIs and services.
# How the pieces work
OpenShell is an open-source runtime that creates a security boundary for agents running on CPUs. It applies sandboxed execution, kernel-level filesystem and process controls, credential management and policy checks. A supervisor paired with each sandbox checks outbound requests against defined policies and records agent actions for audit and review. NVIDIA says OpenShell can be extended to third-party compute platforms such as Arm and Intel.
# How organizations are using it
More than 100 organizations are working with the Open Agent Safety Platform. Named collaborators include Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce and ServiceNow. NVIDIA says organizations in financial services, energy and robotics are exploring the technology, including for systems that can act in the physical world.
One concrete integration example is Salesforce linking OpenShell to Slack so human reviewers can audit agent events and approve or reject permission escalations. That demonstrates how OpenShell can combine automated controls with operator oversight.
# What the platform is designed to prevent
The platform targets scenarios where agents autonomously escalate privileges, access systems and data outside their remit, or chain actions in ways that application-layer controls miss. By tracing agent activity, enforcing outbound policies and providing a hardware-backed quarantine capability, NVIDIA intends to reduce the window in which an agent can cause unintended or harmful actions.
# Availability
NVIDIA says Open Agent Safety Platform software, including OpenShell and related skills, is available through its developer resources and GitHub. Sentry requires BlueField-4 DPUs to provide the out-of-band monitoring and enforcement.
# Bottom line
Platform couples runtime controls with hardware monitoring to create multiple enforcement layers for autonomous agents. Its open-source runtime plus a hardware quarantine option aims to give organizations practical tooling to limit agent permissions, audit actions and quickly stop agents that break rules.