Nvidia moves AI agent containment out of the model and into the silicon
OpenShell is open source and runs on ordinary processors. Sentry, the watchdog that quarantines a rogue agent in milliseconds, needs a BlueField-4 card, and that is where the hardware bill starts
- OpenShell is published on GitHub under an Apache 2.0 license and governs five kinds of access: files, network, tools, processes and credentials.
- Nvidia names 14 infrastructure partners, including Cisco, Dell Technologies, HPE and Lenovo, as offering AI infrastructure that supports the platform.
- Three operating system vendors, Canonical, Red Hat and SUSE, are integrating the platform into their distributions.
- The Open Secure AI Alliance, governed by the Linux Foundation, was set up by Nvidia with more than 120 organizations.
For Dell, HPE, Lenovo and Cisco partners in the UK, agent containment is now a line on the AI server quote: a BlueField-4 DPU per node, sold as the thing that stops a runaway agent, with attach margin to match. The catch is that the software half is free, is being built into Ubuntu, Red Hat and SUSE and, by Nvidia’s own account, is often enough, so the DPU sale needs a customer with an auditor to satisfy rather than a fear to sell against.
Managed security providers are likely to see the managed layer come through Palo Alto Networks and CrowdStrike programs rather than from Nvidia, and standalone agent guardrail software now competes with a runtime that costs nothing.
“An agent cannot be expected to fully police its own behavior.”Justin Boitano, vice-president of enterprise AI, Nvidia, told VentureBeat
Nvidia launched the Open Agent Safety Platform on 28 September, pairing an open-source runtime with a reference hardware design that holds an AI agent inside limits set by its operator, not by the model. Nvidia says more than 100 organizations are working with the technology, among them Cisco, Dell Technologies, HPE, Lenovo, Palo Alto Networks and CrowdStrike.
The software half is OpenShell. It turns an operator’s instructions into policies that govern what an agent may touch: files, network, tools, processes and credentials. It is tuned for Nvidia’s Vera central processing unit (CPU) and can be extended to Arm and Intel platforms. The hardware half is Sentry, a watchdog that runs on a BlueField-4 data processing unit (DPU). Nvidia’s technical blog says the DPU sits on the node’s only path to the model, isolated from the host and out of the agent’s reach.
VentureBeat’s report from Nvidia’s press briefing carries two caveats the release does not. Justin Boitano, vice-president of enterprise AI at Nvidia, said that in many cases OpenShell on ordinary CPUs is good enough. The outlet adds that the policy prover, which checks permissions before they are applied, does not yet cover every policy feature.
Who ships it
Canonical, Red Hat and SUSE are building the platform into their operating systems. Salesforce has wired OpenShell into Slack for approving agents’ permission requests, and SAP is embedding it in its Joule Studio runtime. The release’s small print says many of the products are still in development, with no committed dates.
