NVIDIA introduces platform for managing AI agent security

OpenShell and Sentry apply runtime controls, activity monitoring and access policies across software, compute and robotics systems.

NVIDIA announced the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for managing AI security from agent testing through deployment. The platform provides governance and control across the software, hardware, compute and robotics systems used by AI agents.

Recent security incidents have shown that agents can bypass application-layer controls while performing assigned tasks. NVIDIA says organizations need configurable tools that can apply controls to agents during extended operations.

Open Agent Safety Platform supports controls across the agent stack

The NVIDIA Open Agent Safety Platform provides governance and control across the software that runs agents, the hardware and compute infrastructure that supports them and the robotics systems that perform tasks in the physical world. Organizations can deploy the platform’s components based on their operational requirements.

The platform includes NVIDIA OpenShell secure runtime software, which establishes boundaries for agents running on CPUs. OpenShell provides a runtime boundary for controlling how agents execute tasks across open and closed models. It is designed to operate outside the model and agent harness so that organizations can apply controls independently of the agent’s instructions.

OpenShell is designed to run on NVIDIA Vera, a CPU developed for agentic AI, with limited processing overhead. As open-source software, OpenShell can also be adapted for third-party compute platforms including Arm and Intel systems.

The NVIDIA Open Agent Safety Platform reference system design also includes NVIDIA Sentry, an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs. Sentry monitors agent behavior and can quarantine or stop an agent if it attempts to operate outside its defined software boundary.

Sentry runs independently in the DPU and applies security policies to agent activity. It combines threat detection, hardware-based governance and enforcement and data access protection within an isolated trust domain that is separate from the agent.

Sentry is built on NVIDIA DOCA software. DOCA provides programmable functions for inspecting agent requests and responses, generating attested telemetry, verifying agent identity and applying zero-trust access policies to data, tools, application programming interfaces and services.

Organizations working with NVIDIA on agent security

Anthropic and NVIDIA are working on additional security controls for the agent stack. Claude Managed Agents run the agent loop on a separate server from the sandboxes where tasks are executed. Integrations with OpenShell and BlueField allow enterprises to control agent access to those sandboxes.

SpaceXAI is using the NVIDIA Open Agent Safety Platform with Cursor coding agents and Grok models.

Scale AI is working with NVIDIA to incorporate platform technologies into the agent infrastructure layer of the Scale GenAI Portfolio.

Salesforce and NVIDIA have integrated OpenShell with Slack. Teams can use Slack to view agent activity and audit events and approve or reject requests for additional permissions.

SAP is integrating OpenShell with the Joule Studio runtime, which is part of the SAP Business AI Platform. The integration combines business oversight with runtime security. SAP is also contributing engineering work to OpenShell and working with NVIDIA on interoperability standards through the Open Secure AI Alliance.

Accenture, Armadin, Cadence, Cognition, CrowdStrike, Cisco, Dassault Systèmes, Deloitte, EY, Hugging Face, IBM, Irregular, Perplexity, Microsoft, SAP, Scale AI, ServiceNow, Siemens, Synopsys, OpenClaw, Palantir and Palo Alto Networks are among more than 100 organizations working with NVIDIA Open Agent Safety Platform technologies.

Robotics companies including Figure, Gecko Robotics and Skild AI are using OpenShell to add agent safety controls to autonomous systems that operate in physical environments.

Citi and JPMorganChase are working with NVIDIA on open-source technologies for agent security in financial services.

Energy organizations including Hitachi Energy, EPRI, NextEra Energy, Quanta Services, SPP, Schneider Electric, Siemens Energy and Worley are working with NVIDIA on technologies for energy and critical infrastructure applications.

Infrastructure software companies including Canonical, SUSE and Red Hat are integrating NVIDIA Open Agent Safety Platform technologies into operating system software. Red Hat runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA, an enterprise AI solution for developing, deploying and managing AI across hybrid cloud environments.

NVIDIA partners including Baseten, Cisco, CoreWeave, Dell Technologies, GMI Cloud, HPE, HP Inc., Irregular, Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure, Supermicro and Together AI offer AI infrastructure solutions that use or support NVIDIA Open Agent Safety Platform technologies. These solutions are intended to help customers apply security controls when running AI agents.

Availability
NVIDIA Open Agent Safety Platform software, including OpenShell and skills, are available through the NVIDIA developer resources page and GitHub.

Ecosystem contributions such as NVIDIA Open Agent Safety Platform support the mission of the Open Secure AI Alliance as well as the broader AI safety and security community. Initiated by NVIDIA alongside over 120 leading organizations and governed by the Linux Foundation, the Open Secure AI Alliance strengthens AI agent security through open research, skills and tools, as well as projects like the Shared AI Findings Exchange, or SAFE.

Written by

Puja Mitra

Puja Mitra has an MBA in Marketing and HR as well as an MA in Economics. As a Managing Editor, she has experience managing CAD, CAM, and CAE directories. She also handles design, BIM, manufacturing, digital transformation, and computing news. With over 14 years of editing experience, she has a particular interest in content and technical writing.