
What happened
NVIDIA announced the Open Agent Safety Platform, made up of NVIDIA OpenShell, which tracks and enforces what an AI agent sees, does and connects to on NVIDIA Vera CPU, and NVIDIA Sentry, which halts agents trying to move out of bounds within milliseconds on NVIDIA BlueField-4 DPU.
Why it matters
The two systems are combined to create layered software and hardware security, which may give operators a way to force agents to follow rules rather than trust them to behave.
What to watch
The platform's reach hinges on five principles NVIDIA says should govern agent systems, including that policy must be verifiable and monitoring must sit outside the agent's reach; NVIDIA also says agent runtimes and their policy languages must stay open and pluggable across providers.
WHO IT HITSEnterprises running AI agents that touch files, tools or network connections — and the security and platform teams accountable for them — would be the first to feel this, since the platform is pitched at blocking any action not allowed by policy.
Summaries like this, in your inbox every morning.
NVIDIA's pitch rests on a simple division of labor: OpenShell watches and constrains the agent where it runs, on the NVIDIA Vera CPU, while Sentry sits on the NVIDIA BlueField-4 DPU and cuts off agents that try to leave the permitted boundary. That combination is what NVIDIA describes as layered software and hardware security, and it addresses a specific worry — that an agent's own environment is not a safe place to put the control system.
The five principles NVIDIA lays out go further than the two products. Two of them are structural rather than technical: monitoring should happen out of band, meaning the agent need not know it is being watched, and control over the path to the model should yield both a good observation point and a kill switch. A third calls for verifiability before execution, so a policy can be shown not to escape the operator's intent. The last is about openness — agent runtimes and policy languages should be open so any provider can plug in, an argument that layers are owned separately by labs, companies and hardware providers.
Jensen Huang frames the whole thing around trust rather than raw capability, saying the most trusted AI must be built alongside the most capable. Whether that framing translates into adoption beyond the 100-plus industry partners NVIDIA cites likely depends on how readily third parties embrace the open runtime and policy language, and on whether agents can be governed without slowing the work they are meant to do.
Pick your industry and the AI tools you use, and get news related to your work every day.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
On Anthropic's ExploitBench, GLM-5.3 built a working Chrome V8 exploit in 50 of 410 attempts versus Mythos Pre…

Google is paying about 100 digital publishers for content used in AI Overviews, AI Mode, and Gemini, with paym…

A Qiita walkthrough trained a five-label car-damage classifier on Gemini Enterprise Agent Platform AutoML usin…

Alibaba's Qwen team open-sourced Qwen-Image-2.1 on September 20, 2026 — a 7B model generating 2048×2048 images…

Lauren Tan says she shipped about 2,000 pull requests a month to production on the SpaceX AI Grok Bot team

A student made granite-code:8b and granite3.2:8b write a TORCS racing AI in 13 parts, checked by Python test s…
