Nvidia is expanding its Open Agent Safety Platform with two layers intended to contain autonomous software. OpenShell, an open-source sandbox announced in March, is entering general availability and isolates agent activity at the operating-system kernel level while enforcing which resources a task may access.

A second component called Sentry runs as an isolated security domain on Nvidia BlueField data-processing units. It continuously monitors long-running agents and is designed to quarantine one that moves outside its assigned boundary. Nvidia is also working with Arm and Intel on versions for x86 systems, which would extend the approach beyond BlueField hardware.

The company lists collaborations with organizations including Anthropic, Cisco, CrowdStrike, Hugging Face, Microsoft, Mistral, Salesforce, and SAP, although the depth of adoption varies and was not clear for every name. OpenAI was absent from the announcement despite both companies indicating it participates in the OpenShell effort. Sandboxes and watchdogs cannot guarantee that a permitted action is safe, but separating policy enforcement from the agent’s own runtime reduces reliance on the system being monitored. The general release gives security teams code they can inspect and test against their own agent fleets.