NEWS / SEP.2026
Nvidia launches an AI agent security platform with OpenShell and Sentry
On September 28, 2026, Nvidia launches Open Agent Safety Platform, an AI agent security platform combining OpenShell with a reference architecture incorporating Sentry. The Sentry monitoring software is optional and can cut off access to the model from a separate processor in the system presented.

Nvidia combines OpenShell and Sentry to contain AI agents
On September 28, 2026, Nvidia announced Open Agent Safety Platform, its AI agent security platform. It brings together OpenShell and a reference architecture incorporating Sentry, a monitoring software component. Nvidia says OpenShell is now widely available and introduces version 0.1.0.
OpenShell was already in preview on March 23, 2026. Containment and permissions therefore predate the platform's launch. The September 28 announcement expands access to OpenShell and introduces Sentry's separate monitoring.
Nvidia's documentation describes OpenShell as a runtime environment that isolates the agent and enforces permissions defined by the operator. These controls govern access to files and the network, as well as the use of tools and processes.
Nvidia compares this containment to that of browser tabs, whose resources are governed by the runtime environment. Permissions are enforced at the system level, in a layer outside the agent's program. They complement the instructions given to the model.
The actual credentials are kept outside the isolated environment and then injected into authorized requests. This allows the agent to use an authenticated service without receiving its actual keys.
OpenShell 0.1.0 also includes formal verification of the modeled permissions. Nvidia presents it as a way to identify permissions that exceed the defined security boundaries.
Sentry monitors from a separate processor
In the reference architecture published by Nvidia, OpenShell runs on Vera and Sentry on BlueField-4. BlueField-4 is a DPU, an infrastructure processor separate from the one hosting the agent. Sentry is based on DOCA and runs in a domain isolated from the host processor.
The Sentry layer is optional. In the system presented, BlueField-4 controls the only path between the machine hosting the agent and the model. The DPU can interrupt this access, providing a control point outside the agent's environment. Nvidia claims quarantine within milliseconds.
The interruption applies to access to the model. It does not guarantee that tools or processes already running will stop, or that response computation already underway will stop. The scope of protection depends on the paths actually placed under control.
OpenShell can be used without BlueField-4
OpenShell is distributed under the Apache 2.0 license and can be used without BlueField-4. Sentry monitoring in the architecture presented relies on this optional DPU.
Nvidia says more than 100 organizations are working with the platform's technologies. That figure does not establish that there are as many full production deployments. Among the uses cited by the company, Cadence uses OpenShell for chip design and Slack is building an on-demand agent platform on the software.
Reuters reports Nvidia's work with Arm and Intel to extend compatibility to their processors. These adaptations are presented as work in progress, without establishing that the integrations have already been delivered.