
Picture an AI agent that can write code, call APIs, and keep working overnight — with a supervisor outside the agent that decides which doors open, which credentials never leave a vault, and which outbound request gets blocked before it lands. That’s the practical picture NVIDIA and partners are shipping around the Open Agent Safety Platform. Not a lecture about “rogue AI.” Runtime plumbing teams can actually plug into.
At the software layer, NVIDIA OpenShell (Apache 2.0, now in a 0.1.0 open-source cut) runs agents in sandboxed environments with kernel-level isolation. Operators write policies for files, networks, tools, and credentials. A supervisor outside the workload inspects outbound traffic. Credentials can be bound so the agent never sees the real key. NVIDIA’s technical walkthrough shows the pattern plainly — allow a read to an API, block a write through the same host — and records allow/deny decisions for audit. Cadence, Slack, and Gecko Robotics are among the early adopters NVIDIA names for chip design, enterprise automation, and physical-robot governance.
For shops that want a second, independent watchdog, NVIDIA Sentry rides BlueField-4 data processing units. In NVIDIA’s reference design, that DPU sits on the node’s path to the model, watching out-of-band and enforcing policy in silicon. NVIDIA’s product materials say Sentry can quarantine an agent that crosses its software boundary in milliseconds — containment speed as an engineering claim, not a morality play. OpenShell does not require BlueField-4; Sentry is the optional hardware-isolated layer when you already run (or plan) Vera/BlueField systems.
Anthropic’s Claude Managed Agents post is the customer-side layering story. Managed Agents keep the agent loop on a separate server from the sandbox and hold credentials in a vault so the agent never sees them. Customers who run Managed Agents with OpenShell can limit what the agent executes and reaches, review what it did, and confirm the limits are in place. Model safeguards stay inside the model; runtime controls sit outside — modular layers so a company can adopt what fits.
Ink, not pencil: OpenShell is open and usable without NVIDIA silicon. Sentry’s announced hardware home is BlueField-4, and the millisecond quarantine figure is NVIDIA’s stated containment claim from its platform materials — not an independent bake-off against every EDR stack. Frontier labs’ recent “agent broke out of the eval box” reports are the why-now backdrop NVIDIA cites. The product answer is policy, isolation, and out-of-band kill switches.
For a busy Monday: if your teams are about to give agents tickets, repos, and customer systems, ask whether credentials are vaulted, whether reach is policy-gated outside the agent, and whether you have a hardware or software path to interrupt drift — before the pilot becomes the production blast radius.
Why it matters
Agents that book travel, touch payroll data, or drive a robot on a factory floor need the same kind of trust layer browsers got when the web grew up: sandboxes, locks, and someone watching the network path who is not the page itself. Better runtime rails mean more useful agents can be trusted with real work — and fewer scary headlines about an assistant that wandered into the wrong system. Safety engineering here is how helpful automation ships without asking everyone to cross their fingers.
What’s next
Watch OpenShell’s GitHub cadence and CNCF Slack `#openshell-dev` for real deploy reports. Watch which enterprises pair Managed Agents’ vaulted credentials with OpenShell reach policy. And watch whether BlueField-4 shops turn on Sentry as a software update on Vera systems the way NVIDIA describes. The Sept. 28 package is still traveling through IT and security review queues — the interesting signal is who puts it in a production agent fleet, not who quotes the press release.
Sources: - https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/ - https://developer.nvidia.com/blog/add-runtime-controls-to-ai-agents-with-nvidia-openshell/ - https://claude.com/blog/giving-companies-more-control-over-their-ai-agents-with-nvidia - https://www.nvidia.com/en-us/solutions/ai/agent-safety/ (Sentry millisecond quarantine claim)