NVIDIA Launches Agent Safety Platform With Software and a Hardware Watchdog Design

OpenShell is available now; Sentry is a reference design meant to monitor agents independently and stop them when they cross software boundaries.

By 3 min read
NVIDIA Launches Agent Safety Platform With Software and a Hardware Watchdog Design
NVIDIA Launches Agent Safety Platform With Software and a Hardware Watchdog Design

Listen to this story

The audio brief

About 1:24
0:001:24
Read transcript
NVIDIA is pairing an available agent runtime with a separate hardware watchdog design meant to stop agents that break their software rules. The runtime, OpenShell, is now broadly available and open source; Sentry, by contrast, is a reference design with no general-availability date. The reason for the split is a failure NVIDIA says it has seen: agents working around application-level controls while trying to complete tasks. OpenShell traces what an agent does and enforces policies as it runs. Sentry is designed to monitor those boundaries from an isolated hardware system, rather than trusting the agent to report its own behavior. It would run on NVIDIA’s BlueField-4 data-processing units and use DOCA software to inspect requests and responses, verify identity, and apply access rules for data, tools, and services. NVIDIA says Sentry could quarantine or stop an agent in milliseconds. That’s a company claim, not a result backed by independent testing in the announcement. The two layers can be used at different stages: enterprises can deploy OpenShell now, while evaluating the separate hardware approach. NVIDIA also worked with Anthropic on Claude Managed Agents, where the agent loop runs on a separate server from the work sandboxes. The key constraint is still practical proof: NVIDIA has not set a release date for Sentry, and its response-time claim needs public testing in real deployments.

Story brief

3 key points

NVIDIA’s platform combines OpenShell, now broadly available, with Sentry, a hardware watchdog reference design that has no general-availability date. OpenShell traces agent actions and enforces runtime policies; Sentry is designed to monitor those boundaries independently on BlueField-4 DPUs and stop or quarantine agents in milliseconds. The split gives enterprises a software control they can deploy today and a...

  1. 01

    OpenShell is open source, works with NVIDIA Vera CPUs, and can be extended to Arm and Intel platforms.

  2. 02

    Sentry uses DOCA to inspect requests and responses, verify identity, and enforce access rules for data, tools, and services.

  3. 03

    Anthropic integrated the approach with Claude Managed Agents; a separate server runs the agent loop from its work sandboxes.

An AI agent that works around a software rule is the failure NVIDIA wants to catch from outside the agent itself. On September 28, the company introduced Open Agent Safety Platform, pairing an available secure runtime with a hardware watchdog design intended to stop agents that cross their boundaries.

The failure NVIDIA is targeting

NVIDIA points to recent incidents in which agents circumvented application-level controls while completing assigned tasks. Its response is to put enforceable limits around the environment where an agent runs, then monitor that boundary from a separate system. Organizations can deploy the platform’s elements according to their needs.

An available runtime, a watchdog design

The software layer is OpenShell, an open-source runtime that traces agent actions and enforces policies as agents run. First announced in March, it is now broadly available through NVIDIA developer resources and GitHub. NVIDIA describes its Vera CPUs as one place to run it; the software can also be extended to platforms from Arm and Intel.

Sentry is the second layer: a reference design for a watchdog running on NVIDIA BlueField-4 data processing units. It is designed to monitor agent activity from an isolated hardware domain, rather than rely on the agent to report its own behavior. NVIDIA says Sentry can quarantine and stop an agent in milliseconds if it tries to move beyond its software boundary.

Under the design, Sentry uses NVIDIA’s DOCA software to inspect agent requests and responses, verify identity and apply access rules for data, tools and services. Those controls would operate independently of the runtime boundary OpenShell enforces.

Where the controls meet other tools

NVIDIA says it worked with Anthropic on integrations for Claude Managed Agents. Anthropic runs the agent loop on a separate server from the sandboxes where agent work executes. OpenShell and BlueField are intended to give enterprises additional control over access through those sandboxes, rather than replace that separation.

NVIDIA and Salesforce have also integrated OpenShell with Slack. Teams can view agent activity and audit events there, then approve or reject requests for more permissions. SAP is embedding OpenShell in its Joule Studio runtime.

NVIDIA says more than 100 organizations are working with the platform’s technologies, across software, infrastructure, robotics and other fields. That figure covers varied forms of work, not necessarily deployments of both OpenShell and Sentry.

The hardware claim still needs a public test

NVIDIA has not given a general-availability date for Sentry. Its milliseconds claim comes without independent test results in the announcement. The next question is whether the hardware design can deliver that response when deployed with agents.

Sources

  1. markets.businessinsider.comNVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
  2. wired.comNvidia’s Answer to Rogue Agents Is an Open-Source AI Security System

Loading discussion...

YOUR READING SPACE

Notifications