Nvidia has announced its Open Agent Safety Platform, combining software that restricts what AI agents can access with a separate watchdog that it says can quarantine and stop agents in milliseconds.
The launch, announced on 28 September, brings together OpenShell, Nvidia’s open-source agent runtime, and Sentry, a monitoring and enforcement layer running on BlueField-4 data processing units. The speed claim applies to that Sentry-based hardware design, not simply to installing OpenShell on a laptop.
For developers, the useful distinction is between telling an agent to follow rules and putting controls outside the agent that enforce those rules. But Nvidia’s announcement is not an independently verified containment benchmark, and DIY AI has not tested the millisecond claim.
OpenShell sets the boundaries; Sentry adds independent enforcement
OpenShell runs agents inside isolated environments and applies policies governing access to files, networks, processes and provider credentials. Nvidia’s documentation describes controls aimed at blocking unapproved data transfers, access to local secrets, unauthorised model endpoints and privilege escalation.
Sentry adds a separate security layer. In Nvidia’s reference architecture, it runs on BlueField-4 hardware outside the host environment the agent uses. Nvidia’s DOCA software connects this monitoring and enforcement layer with agent policies and identity controls.
Nvidia’s technical explanation places BlueField-4 on the compute node’s only route to the model in a Vera Rubin POD. That positioning is central to its proposed control mechanism: the agent should not be able to bypass the watchdog by changing the software environment it runs in.
These controls are relevant to the kind of boundary failures discussed in our coverage of the OpenAI agent that accessed Australia’s Medicare statistics portal. They do not establish that every possible deployment is escape-proof.
What the milliseconds claim still needs to show
In its launch announcement, Nvidia says Sentry can quarantine and stop an agent in milliseconds when it attempts to move outside its software boundary.
The announcement and accompanying architecture article do not provide a reproducible latency benchmark with a precise timing definition, workload, run count or distribution of results. A fast response after detection is not automatically the same as preventing an unauthorised action before it happens.
| Measurement | What a useful test would establish |
|---|---|
| Detection time | How long the system takes to recognise a prohibited action, measured from the first observable attempt. |
| Containment time | How long it takes after detection to remove the agent’s ability to continue, including relevant child processes and delegated work. |
| Prevented harm | Whether prohibited data transfers or external changes were completed before containment, rather than merely whether an alert appeared. |
Nvidia does report a separate OpenShell experiment. Agents with reduced safeguards were given up to two hours to persuade an AI reviewer to allow changes to a protected GitHub repository. The company says its combined policy-analysis and runtime controls prevented protected repository writes in those tests.
That is a vendor-reported access-control result, not a measurement of Sentry’s millisecond containment. The two should not be presented as interchangeable evidence.
What developers can integrate now?
OpenShell is available under the Apache 2.0 licence. Its public repository provides a command-line interface and SDKs for Python, TypeScript, Go and Rust. The SDKs connect applications to an OpenShell gateway, giving platform builders a programmatic route to the runtime rather than only an interactive developer tool.
Nvidia’s documentation lists Claude Code, OpenCode, Codex and GitHub Copilot CLI as example coding-agent workloads. OpenShell is an execution and permissions layer around these AI coding tools, not a replacement coding assistant or evidence that every agent framework has a dedicated integration.
The support matrix covers Linux on x86-64 and Arm, macOS on Apple Silicon through Docker Desktop, and experimental Windows support through WSL 2. Deployment options include Docker, Podman, Kubernetes and MicroVM-backed sandboxes, subject to the documented runtime and kernel requirements.
That gives developers a software-only entry point. It should not be confused with reproducing Nvidia’s separate BlueField-4-based Sentry design or inheriting its claimed containment speed.
An audit log is not necessarily a blocked action
One consequential detail sits in OpenShell’s security documentation. When application-layer request inspection is active, the documented default for the enforcement field is audit. In that mode, the proxy records rule violations but forwards the traffic.
The alternative, enforce, blocks requests that do not match the permitted rules. This distinction applies to inspected requests to reachable services; it does not mean OpenShell’s separate network and filesystem boundaries are disabled by default.
For example, a policy intended to make an API read-only does not prevent write operations when it only audits request rules. Similarly, approving access to a destination without suitable request-level restrictions can leave more actions available than an operator intended.
The implication is practical: a dashboard showing policy violations is not, by itself, evidence that those violations were stopped. Deployment configuration is part of the security claim.
Oversight and identity remain part of the system
Nvidia says Salesforce has integrated OpenShell with Slack so teams can review agent activity and approve or reject requests for additional permissions.
Separately, DigiCert says its AI Trust Manager now supports the platform, starting with OpenShell. Its contribution centres on cryptographic agent identities, verification and audit evidence. Those capabilities address who an agent is and how its activity can be attributed, rather than independently validating Nvidia’s containment speed.
Our assessment is that moving enforcement outside the model is the substantive development here. It gives operators a way to constrain actions without relying entirely on the agent interpreting instructions correctly. It does not make a permissive policy safe, undo a completed external action or remove the need to decide which permissions an agent should receive.
For now, the confirmed news is the platform launch, available OpenShell tooling and a hardware-backed containment design. Whether Sentry consistently stops relevant workloads within milliseconds, before damage occurs, remains a performance claim that requires reproducible testing.