NVIDIA is pushing AI agent security deeper into the computing stack.
The company has launched the NVIDIA Open Agent Safety Platform, an open software and reference system designed to control autonomous AI agents while they operate. More than 100 organisations are working with NVIDIA on technologies around the platform, spanning AI developers, cybersecurity companies, cloud providers, enterprise software vendors and infrastructure specialists.
The timing matters. AI agents are no longer confined to answering questions inside chat windows. Increasingly, they can access files, call APIs, use software tools, interact with databases and carry out multi-step tasks with limited human intervention.
That creates a different security problem. Instead of simply asking whether an AI model produces a bad response, companies need to know what happens when an agent actually tries to do something.
NVIDIA’s answer is to put boundaries around the agent itself.
OpenShell Creates a Boundary Around AI Agents
At the centre of the platform is NVIDIA OpenShell, an open-source secure runtime designed to control what an AI agent can access and what actions it can perform while working.
Rather than relying entirely on safeguards built into a model or agent application, OpenShell establishes a separate runtime boundary. Administrators can govern access to networks, files, tools, credentials and external systems while an agent carries out its tasks.
That separation becomes more important as agents stay active for longer periods and gain access to more sensitive enterprise systems. An agent might be allowed to read a document but blocked from changing it. Another could query a database without being able to export sensitive information.
NVIDIA says OpenShell works across both open and closed AI models and can enforce policies regardless of how the underlying agent behaves. The software is optimised for NVIDIA Vera CPUs, although its open-source design allows it to be extended to other compute platforms.
NVIDIA Sentry Watches Agents From Outside the Host
OpenShell is only one part of the security architecture. NVIDIA has paired it with Sentry, an out-of-band monitoring system designed to run on NVIDIA BlueField-4 data processing units.
The idea is to separate monitoring from the same environment in which the agent is operating.
Instead of asking the host system to watch itself, Sentry operates from an isolated hardware domain and continuously observes agent activity. NVIDIA says the system can detect when an agent attempts to move beyond its defined software boundary and quarantine it within milliseconds.
That matters because a compromised host environment could potentially interfere with software-based security controls running inside it. By moving monitoring to separate hardware, NVIDIA is trying to create an enforcement layer that remains independent from both the agent and the operating environment.
NVIDIA DOCA software adds another layer to the system. It can inspect agent requests and responses, verify identities, produce attested telemetry and enforce zero-trust policies governing access to tools, data, APIs and services.
AI Agent Security Is Becoming a Full-Stack Problem
The announcement reflects a broader shift in how AI safety is being approached as autonomous systems become more capable.
Model-level guardrails still matter, but they are no longer the whole security picture. An AI agent may interact with databases, internal applications, cloud services, business software and other agents. A mistake can therefore move beyond a bad answer and become an actual action inside a live system.
That changes the stakes.
NVIDIA is treating agent security as an infrastructure problem as much as a model problem. Its approach reaches from agent software and runtime controls down to CPUs, DPUs and hardware-isolated monitoring systems.
Companies do not necessarily have to adopt the entire stack. The platform is being structured so organisations can use individual components depending on how their AI agents are deployed.
For enterprises preparing to give AI systems access to business-critical applications, that flexibility could become increasingly important.
More Than 100 Organisations Join NVIDIA’s Agent Safety Push
NVIDIA is not building the ecosystem alone. More than 100 organisations are involved in technologies connected to the Open Agent Safety Platform.
The group includes major AI companies, enterprise software vendors, cybersecurity specialists, infrastructure providers and cloud companies. Among those named by NVIDIA are Anthropic, Cisco, CrowdStrike, Dell Technologies, Hugging Face, IBM, Microsoft, Palantir, Perplexity, Red Hat, SAP, Salesforce, Scale AI, ServiceNow, Siemens and Palo Alto Networks.
Anthropic is one example of how the technology could be used. Its Claude Managed Agents architecture separates the main agent loop from the sandbox environments where tasks are executed. NVIDIA’s OpenShell and BlueField technologies can add another layer of controls around those execution environments.
Financial institutions are also involved. NVIDIA identified Citi and JPMorganChase among organisations collaborating on shared open-source agent safety technologies.
The participation of companies outside the traditional AI sector is significant. It suggests agent safety is rapidly becoming an enterprise infrastructure issue rather than something handled only by model developers.
Salesforce and SAP Bring OpenShell Into Enterprise Workflows
Some of the early integrations show what agent security could look like inside everyday enterprise software.
Salesforce and NVIDIA have integrated OpenShell with Slack, allowing teams to view agent activity and audit events while approving or rejecting requests when an agent needs additional permissions.
That kind of human checkpoint could become increasingly common as companies deploy agents capable of carrying out sensitive tasks.
SAP is also integrating OpenShell with its Joule Studio runtime inside the SAP Business AI Platform. The company is contributing engineering work to OpenShell while collaborating with NVIDIA on interoperability.
Infrastructure providers including Cisco, CoreWeave, Dell Technologies, HPE, Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure and Supermicro are also supporting technologies linked to NVIDIA’s platform.
This is where the announcement becomes more than another AI security framework. NVIDIA is attempting to create a common safety layer that can operate underneath agents developed by different companies and deployed across different enterprise environments.
Open Source Could Make Agent Safety More Portable
NVIDIA’s decision to release OpenShell as open-source software could make the technology useful beyond NVIDIA’s own infrastructure.
That matters because enterprise AI environments are already becoming fragmented.
A company might use one provider’s foundation model, another company’s agent framework, several SaaS applications and a mix of cloud and on-premise infrastructure. Security controls tied to a single model or platform may struggle to cover that entire environment.
Runtime-level governance offers another approach.
Instead of relying entirely on the agent to behave correctly, companies can control the environment in which the agent operates. Access to data, tools, networks and services can be restricted independently of the underlying model.
NVIDIA is also connecting this effort to the Open Secure AI Alliance, which the company says now includes more than 120 organisations and operates under Linux Foundation governance.
The alliance is focused on shared research, open tools and common approaches to AI agent security.
AI Agents Are Getting More Freedom, and Security Has to Follow
There is a simple tension behind NVIDIA’s announcement.
Useful AI agents need permissions. They need access to tools, data and business systems if they are expected to perform meaningful work.
Give them too little access and they become limited assistants. Give them broad access without independent controls and mistakes become much more consequential.
NVIDIA’s Open Agent Safety Platform attempts to solve that problem through multiple layers. Agents can be sandboxed, monitored, authenticated and restricted while independent infrastructure watches their behaviour.
The question now is how widely companies will adopt these controls as autonomous AI systems move deeper into enterprise workflows.
One thing is becoming harder to ignore: as AI agents gain the ability to take real actions, security can no longer sit only inside the model.
It has to exist around the agent too.
Sources
NVIDIA Newsroom — NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
https://nvidianews.nvidia.com/news/open-agent-safety-platform
Artificial Intelligence News — NVIDIA and Over 100 Partners Launch Open AI Agent Safety Platform
https://www.artificialintelligence-news.com/news/nvidia-over-100-partners-launch-open-ai-agent-safety-platform/

