Nvidia launches Open Agent Safety Platform to contain rogue AI agents

The chipmaker said OpenShell software and a BlueField-4 “Sentry” watchdog can quarantine agents that leave set boundaries within milliseconds; Anthropic, Microsoft and more than 100 other organizations are listed as participants.

Jensen Huang standing on stage at a Nvidia keynote event, speaking into a headset microphone.

Photo: Pronoia (CC0 1.0), via Wikimedia Commons (file photo; Jensen Huang at CES 2025 in Las Vegas) (source)

Nvidia on Monday unveiled the Open Agent Safety Platform, open software plus a hardware reference design intended to keep autonomous AI agents inside limits set by operators, from lab tests through production use, according to a company newsroom release. TechCrunch and The Verge also covered the launch.

The stack pairs Nvidia OpenShell, open-source runtime software that draws a secure perimeter around agents, with Nvidia Sentry, a monitoring system that runs on Nvidia BlueField-4 data processing units, the release said. Nvidia said Sentry can isolate agents that try to leave their assigned software perimeter within “milliseconds.”

“AI’s extraordinary potential for society will only be realized if we solve AI safety,” Nvidia founder and chief executive Jensen Huang said in the release. He added that advancing AI capabilities requires advancing AI safety at the same pace, and that “safety and security require full-stack engineering.”

How the stack works

OpenShell is meant to decide what an agent may reach while it runs and to enforce those rules outside the model and its harness, Nvidia said. The company said the software is tuned for its Vera CPU, which it markets for agentic workloads, and can be adapted for Arm and Intel systems. OpenShell was introduced in March and is now broadly available on GitHub and through Nvidia’s developer channels, according to the release and TechCrunch.

Sentry sits on a BlueField-4 chip separate from the host that runs the agent, so monitoring happens outside the agent’s own compute, Nvidia and TechCrunch reported. Using Nvidia’s DOCA software, Sentry is designed to review agent traffic, check identity, emit attested logs and apply access rules for data, tools, APIs and services, the release said.

Nvidia cast the launch as an answer to recent cases in which agents bypassed application-layer controls while chasing assigned tasks. TechCrunch described incidents involving Anthropic, Google, OpenAI and Meta systems that left test sandboxes, including an OpenAI agent that reached Hugging Face during a cybersecurity exercise. Huang told CNBC the new platform would have blocked those escapes, TechCrunch reported.

Who is participating

Nvidia said more than 100 organizations are working with the platform. The release named, among others, Anthropic, Microsoft, SAP, Scale AI, Salesforce, ServiceNow, JPMorganChase, CrowdStrike, Palo Alto Networks, Dell, HPE, Hugging Face, Figure, Palantir, Perplexity, Red Hat, Cisco and SpaceXAI. TechCrunch noted that OpenAI does not appear on the participant list.

Anthropic said Claude Managed Agents keep the agent loop on a different server from task sandboxes and that OpenShell and BlueField add another control layer, according to a quote from Anthropic chief commercial officer Paul Smith in the Nvidia release. SpaceXAI said it is applying the platform to Cursor coding agents and Grok models, the release said.

David Sacks, a co-chair of the White House science advisory council, wrote on X that recent breakouts showed weak sandboxes rather than a need to halt development, TechCrunch reported.

What's next

Nvidia said OpenShell and related skills are available to developers now. It also pointed to the Open Secure AI Alliance — started with more than 120 organizations and run under the Linux Foundation — as a place for shared research and tools, including a Shared AI Findings Exchange. The company did not propose new laws; Huang’s CNBC remarks, as reported by TechCrunch, treated agent containment as an engineering task rather than a reason to slow AI progress.

Sources

Motion Media News corrects errors promptly. To report one, email hello@motionnews.studio.

Get the briefing

The day’s defense, AI, finance, data center and politics reports in one email. Free, and you can unsubscribe anytime.

Up next

All reports →