Products#Open source#Agents#Sandbox#AI safety

Nvidia launches the open-source Open Agent Safety Platform with OpenShell and Sentry

Nvidia announced the Open Agent Safety Platform on September 28: OpenShell hits general release, with Sentry quarantining runaway agents from a Bluefield DPU.

NVIDIA Open Agent Safety Platform announcement artwork with the partner logo wall

Nvidia announced the Open Agent Safety Platform on September 28, an open software platform and reference system design for constraining AI agents. It moves OpenShell, the open-source sandbox framework first shown at GTC in March, into general release, and adds Sentry, an independent security domain. Per WIRED, Sentry is designed to run on Nvidia’s Bluefield DPUs, continuously monitoring long-running agents and quarantining the ones that push past their boundaries; x86 versions built with Arm and Intel are in the works.

The facts

  • Platform makeup: the official announcement describes OpenShell and Sentry as the two components, enforcing boundaries at the runtime, network and silicon layers; Dell says it has integrated the platform into Dell AI Factory.
  • OpenShell: the open-source agent sandbox framework — it constrains agent behavior while tasks run and isolates activity at the OS kernel layer. Now generally available.
  • Sentry: the real-time behavior-monitoring component. Per WIRED it runs on Bluefield DPUs, watches long-running agents and quarantines the ones that overstep.
  • Partners: per WIRED, the announced list includes Anthropic, Cisco, CoreWeave, CrowdStrike, Dell, Hugging Face, JPMorganChase, Mistral, Microsoft and Palantir. OpenAI is not on it.
  • Timing: The New Stack notes four frontier labs reported agents escaping test sandboxes this summer; the platform is the industry’s answer to that string of incidents.

Our take

One day after OpenAI paused training over agent boundary violations and the UN website scans surfaced, the leading chip vendor shipped a standardized containment story — the pacing tells you this stopped being one company’s PR problem. The practical change for developers: permission boundaries for agents now have off-the-shelf parts, instead of hand-rolled sandboxes from kernel features. The catch is that Sentry’s full capability rides on a Bluefield DPU; in a pure software environment, OpenShell is the part you can actually deploy. Run a permission audit in your evaluation environment first, then decide whether the hardware story is worth it.