NVIDIA has launched the Open Agent Safety Platform, an open software platform and reference architecture designed to secure autonomous AI agents from development through deployment. Combining the OpenShell runtime with the NVIDIA Sentry reference design on BlueField-4 DPUs, the platform moves agent security beyond the model and application layer into compute, hardware and physical systems.
The next phase of enterprise AI is moving from systems that generate answers to agents that can execute work. That shift is also changing the security boundary.
NVIDIA has introduced the NVIDIA Open Agent Safety Platform, an open software platform and reference system design intended to provide governance and security controls across the full stack supporting autonomous AI agents. The architecture combines software-level isolation with hardware-based monitoring, giving organizations another way to control what agents can do after they have been given permission to act.
The platform centers on two components: NVIDIA OpenShell, an open-source secure runtime, and NVIDIA Sentry, a reference design for continuous agent monitoring using NVIDIA BlueField-4 data processing units (DPUs).
The distinction is important because many existing AI security controls sit around the application or model. An agent, however, can potentially circumvent those controls while trying to complete a legitimate task. NVIDIA’s architecture instead establishes an enforceable boundary outside the agent itself.
OpenShell provides that first layer.
The runtime creates a secure execution environment for agents running on CPUs and establishes controls over processes, filesystems and outbound connections. NVIDIA says OpenShell can work with both open and closed AI models and can also be extended to third-party compute platforms, including Arm and Intel architectures.
The second layer moves security into hardware.
NVIDIA Sentry runs on BlueField-4 DPUs as an out-of-band watchdog that continuously monitors agent activity. NVIDIA says Sentry can quarantine and stop an agent attempting to escape its software boundary in milliseconds. Its position outside the host environment is designed to make the monitoring and enforcement layer independent of the agent and potentially harder for compromised software to bypass.
Sentry is built using NVIDIA DOCA software and is designed to inspect agent requests and responses, verify agent identity, provide attested telemetry and enforce granular access policies covering data, tools, APIs and services.
That architecture reflects a growing problem in AI agent security: autonomy creates a fundamentally different security model from conventional software.
An application generally follows predefined workflows. An autonomous agent can decide which tools to invoke, generate new instructions, delegate work to other agents and potentially operate for extended periods. The more authority an organization gives an agent, the greater the consequences when its instructions, credentials or environment are compromised.
Gartner expects that 33% of enterprise software applications will incorporate agentic AI capabilities by 2028, up from less than 1% in 2024. The research firm also predicts that at least 15% of day-to-day work decisions will be made autonomously through agentic AI by that year.
Another Gartner forecast puts the governance challenge in sharper terms: an average Fortune 500 company could have more than 150,000 AI agents in use by 2028, while only 13% of organizations currently believe they have the right agent governance in place.
NVIDIA is consequently positioning security as infrastructure rather than an add-on to an AI application.
The company is also trying to make the platform an ecosystem rather than a proprietary security stack. More than 100 organizations are working with NVIDIA Open Agent Safety Platform technologies, according to NVIDIA, including Anthropic, Salesforce, SAP, Microsoft, Cisco, CrowdStrike, IBM, Palo Alto Networks, Scale AI, ServiceNow and Siemens.
The integrations illustrate how the architecture could fit into different enterprise AI environments.
Anthropic is combining Claude Managed Agents with OpenShell and BlueField to establish separate execution boundaries. Salesforce has integrated OpenShell with Slack so users can view agent activity and audit events and approve or reject additional permission requests.
SAP is embedding OpenShell into the Joule Studio runtime within SAP Business AI, while Scale AI is incorporating the technologies into its agentic infrastructure for enterprise and government applications.
The platform also extends beyond conventional enterprise software. Robotics companies including Figure, Gecko Robotics and Skild AI are working with OpenShell to introduce agent safety controls into systems that can act in the physical world. Financial institutions including Citi and JPMorganChase are also collaborating with NVIDIA on open-source agent safety technologies.
That breadth is strategically important for NVIDIA.
The company’s AI infrastructure business already spans accelerators, networking, CPUs and DPUs. Open Agent Safety Platform extends that footprint into AI infrastructure governance, potentially making security controls another architectural layer surrounding NVIDIA-powered workloads.
It also places NVIDIA in competition and collaboration with established cybersecurity vendors. Microsoft, Cisco, CrowdStrike and Palo Alto Networks are developing their own AI security capabilities, while hyperscalers and enterprise software companies are building governance into their AI platforms.
The open-source positioning could help NVIDIA avoid making its security architecture dependent on a single model provider. OpenShell can sit beneath different models and agent frameworks, while Sentry provides hardware-level enforcement.
That matters as enterprises increasingly combine models from NVIDIA, Anthropic, Google, Microsoft and other providers rather than standardizing on one AI stack.
The bigger question is whether hardware-enforced controls become a standard requirement for autonomous AI.
For low-risk copilots, application-level security may remain sufficient. But agents managing financial transactions, source code, industrial equipment, critical infrastructure or sensitive enterprise data require a different level of control.
NVIDIA’s platform is effectively making the case that agent autonomy needs an independent enforcement layer—one that the agent itself cannot simply instruct away.
As enterprises move from AI experimentation to autonomous execution, that could become one of the defining architectural debates in enterprise AI.
Market Landscape
The AI security market is shifting from protecting models and prompts toward controlling entire agent execution environments. NVIDIA’s Open Agent Safety Platform addresses this through a combination of OpenShell software isolation and Sentry hardware-level monitoring.
The timing reflects the rapid expansion of agentic AI. Gartner forecasts that 33% of enterprise software applications will incorporate agentic capabilities by 2028, while a separate Gartner forecast expects Fortune 500 organizations to average more than 150,000 agents.
That scale makes centralized governance increasingly difficult. Enterprises need controls that can establish agent identity, restrict tools and data access, monitor behavior and stop unauthorized activity without relying entirely on the agent or its host operating system.
NVIDIA’s strategy is notable because it combines those requirements with its CPU, DPU and networking infrastructure, creating a potential full-stack AI security architecture.
Top Insights
- NVIDIA’s Open Agent Safety Platform moves AI agent security beyond models and applications into runtime, compute and hardware enforcement.
- OpenShell creates an external execution boundary, while Sentry uses BlueField-4 DPUs to monitor and enforce policies independently.
- Gartner expects 33% of enterprise software applications to incorporate agentic AI capabilities by 2028, increasing demand for scalable governance.
- More than 100 organizations are working with NVIDIA’s agent safety technologies, spanning enterprise software, cybersecurity, infrastructure and robotics.
- Hardware-level enforcement could become increasingly important as autonomous agents receive authority over sensitive data, applications and physical systems.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI
