
What happened
NVIDIA announced the NVIDIA Open Agent Safety Platform, made of the open-source OpenShell runtime and the NVIDIA Sentry reference system on BlueField-4 DPUs, which it says can isolate or halt agents in milliseconds.
Why it matters
The platform enforces boundaries from outside the agent itself, so control holds even if the agent misbehaves or is compromised—a check the agent's own safety mechanisms cannot provide.
What to watch
Adoption hinges on whether the many listed partners actually ship integrations; Anthropic, Salesforce, and SAP each plan to embed OpenShell, and Figure in robotics.
WHO IT HITSEnterprise security and platform teams deploying AI agents will need to evaluate runtime isolation and hardware-level controls like these, since the agents' own safety mechanisms may not be enough.
Summaries like this, in your inbox every morning.
NVIDIA's new platform is built on two pieces. OpenShell is an open-source software runtime that runs an AI agent in an isolated environment, with policy controls over which data, tools, APIs, and services it may reach. Sentry is a reference system that runs on NVIDIA BlueField-4 DPUs and watches the agent continuously from an out-of-band environment separate from the agent. Together they aim to set and enforce a boundary around the agent from the outside, and NVIDIA adds that pairing OpenShell with its agent-oriented Vera CPU can achieve this with low overhead. OpenShell is not tied to NVIDIA CPUs, and work is underway to support Arm and Intel platforms.
The platform arrives as several vendors plan to build it in. Anthropic says it will connect Claude Managed Agents with OpenShell and BlueField to strengthen access control; Salesforce plans to integrate OpenShell into Slack for agent monitoring and permission approvals; SAP will embed OpenShell in its Joule Studio runtime. More than 100 organizations, including Microsoft, Red Hat, Cisco, CrowdStrike, and Scale AI, are adopting or supporting the related technology, with Figure using OpenShell in robotics. Notably, OpenAI, Google, and Meta are not among the participants.
The stakes look likely to hinge on execution rather than the announcement itself. The value depends on whether these integrations actually ship and whether enforcing policy at the CPU and DPU layer proves practical for companies running agents in production. For those teams, the outcome matters most where agents are given access to internal data and tools and the agent's own safety checks may not be sufficient.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
On Anthropic's ExploitBench, GLM-5.3 built a working Chrome V8 exploit in 50 of 410 attempts versus Mythos Pre…

Google is paying about 100 digital publishers for content used in AI Overviews, AI Mode, and Gemini, with paym…

A Qiita walkthrough trained a five-label car-damage classifier on Gemini Enterprise Agent Platform AutoML usin…

Lauren Tan says she shipped about 2,000 pull requests a month to production on the SpaceX AI Grok Bot team

At its September 29, 2026 DevDay, OpenAI announced more than 20 items, including dots, an agent running on GPT…

A student made granite-code:8b and granite3.2:8b write a TORCS racing AI in 13 parts, checked by Python test s…
