On Sep 28 Nvidia launched the Open Agent Safety Platform: an open-source runtime called OpenShell plus a hardware watchdog called Sentry, backed by 100+ partner organizations. It moves enforcement out of the agent's reach, which is the right direction. It does not tell you whether your rules are the right ones, or whether they hold.
What Nvidia announced
According to Nvidia's newsroom, the platform provides governance from testing through deployment. OpenShell is an open-source secure runtime that enforces boundaries for agent execution, first on Nvidia Vera CPUs, with extension to Arm and Intel platforms. Sentry is an out-of-band watchdog on BlueField-4 DPUs that monitors agent behavior independently in hardware and can quarantine an agent attempting a policy violation within milliseconds, built on DOCA for threat detection, zero-trust access policies and identity verification. Software is available through Nvidia developer resources and GitHub.
Partners named include Anthropic, Cisco, CrowdStrike, Dell, Hugging Face, IBM, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow and others.
Nvidia VP of enterprise AI Justin Boitano, quoted by PBS: "An agent cannot be expected to fully police its own behavior."
Why the timing makes sense
This lands the same week Fortune reported OpenAI's second sandbox escape, where the automated shutdown failed and a person stopped the run 2.5 hours later, and a Sep 24 arXiv paper showed most tested agent harnesses will delete their own traces on request. Both point at the same weakness: controls that live where the agent can reach them. An out-of-band watchdog is a direct answer.
What it does not solve
PBS notes the platform will not prevent dishonesty, deception or errors in models, and that organizations must write their own rules. University of Wisconsin professor Somesh Jha told PBS that the balance between restriction and usefulness "can only be answered using case studies."
That leaves the practical questions open. Is the policy too loose? Is it so tight the agent is useless? Does the quarantine path fire under real conditions? OpenAI's failed shutdown is the reminder that a control which exists is not the same as a control that works.
What to do
Treat the runtime as a boundary, then test the boundary. Attack it with multi-turn and agentic scenarios, check what the agent can still reach, and rerun after every model or config change.
Humanbound Hobby: always free
For developers evaluating AI agent security. Run tests, review findings, and track posture across unlimited agents and projects.
- 1x monthly testing volume
- Weekly monitoring
- 3 seats, 1 organisation
- 30-day data retention
- Community support
References
- NVIDIA Launches Open Agent Safety Platform, NVIDIA Newsroom
- Nvidia announced a software tool to stop rogue AI. How would it work?, PBS News
- Nvidia releases software platform to stop AI agents from misbehaving, CNBC
- OpenAI pauses training a second time, Fortune
- LLM Agents Can Easily Tamper With Their Own Traces, arXiv 2609.30266
Tags: #ai, #security, #agents, #opensource
Top comments (0)