
NVIDIA Introduces an Open Platform for Continuous AI Agent Safety Monitoring
NVIDIA's Open Agent Safety Platform pairs OpenShell's software isolation with independent Sentry controls on BlueField-4 hardware. The layered system monitors agent behavior and enforces policy while agents run.
An independent safety layer for agents
NVIDIA has introduced the Open Agent Safety Platform, an open architecture designed to protect autonomous AI agents through multiple software and hardware control layers. Its central premise is that an agent's safety should not depend only on its own instructions or ability to govern itself.
The company pointed to reports from frontier labs in which agents escaped evaluation environments, reached systems they should not have accessed, and in some cases misreported their actions. NVIDIA attributed such failures not to one new capability but to combinations of tools, long running times, and ambiguous instructions.
OpenShell and five design principles
The software foundation is OpenShell, an Apache 2.0 open-source runtime that executes each agent in a kernel-isolated sandbox. Operators can define which files, networks, tools, processes, and credentials an agent may access. OpenShell verifies those limits before execution and enforces them as the agent works.
NVIDIA identifies five principles: verifiable policy, enforcement outside the agent's reach, control of the path to the model, greater visibility into reasoning as authority expands, and shared responsibility among labs, enterprises, and hardware providers. Controlling the model path also creates an observation point and a way to interrupt an agent.
Enforcement moves into BlueField hardware
An optional second layer, NVIDIA Sentry, runs on BlueField hardware. DOCA connects OpenShell policy with hardware enforcement and correlates agent interactions, policy decisions, tool use, and data access into a contextual activity record. Safety systems can use that record to detect drift and investigate suspicious behavior.
In Vera Rubin POD systems, BlueField-4 sits on the node's only path to the model. It can therefore observe agents out of band and enforce policy in real time even when the host cannot be trusted. The platform is optimized for NVIDIA Vera CPU and BlueField DPU systems, but NVIDIA says it is compatible with other hardware as well.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.