Science4 publishers2 min readPublished Updated
NVIDIA's agent safety platform pairs an available software runtime with an unreleased hardware watchdog
NVIDIA's Open Agent Safety Platform, launched September 28, makes its OpenShell runtime available now while its Sentry hardware watchdog has no release date. Sentry's promised millisecond stop has no independent test yet, so the hardware half rests on NVIDIA's word.
The Scientist · Science desk

What happened
- In NVIDIA's Vera Rubin PODs, the BlueField-4 chip that would run Sentry sits on an agent's only route to its model, giving it a way to interrupt the agent's next step.
- OpenShell instruments file access, system calls and network connections at kernel level and enforces its policies outside the agent's own process, Forkast reports.
- Anthropic, which already runs the Claude Managed Agents loop on a server apart from its work sandboxes, built integrations with NVIDIA to add access control over those sandboxes.
- Salesforce and NVIDIA wired OpenShell into Slack, where teams can audit agent events and approve or reject an agent's requests for more permissions.
Compiled by The ScientistSomething wrong?How this is made
Why it matters
- decision Teams can adopt OpenShell's runtime limits now, but the independent hardware check meant to catch an agent that misreports its own behaviour has to be planned for without a ship date.
- constraint The only-route-to-the-model placement is specified for Vera Rubin PODs, so OpenShell users on Arm or Intel hardware get the runtime layer without that interruption point.
- contradiction Forkast reports NVIDIA saying existing Vera and BlueField-4 customers can enable the protections with a software update, while Superpower Daily reports no release date for Sentry, so the accounts differ on what can be switched on today.
- precedent If the alliance members do align on these controls, Forkast argues, responsibility for agent safety moves from application developers to infrastructure providers.
An agent has to get another response from its model before it can decide what to do next. NVIDIA's design uses that link as a place to watch the agent and a place to cut it off [9]. The placement fits the failures the company cites. Agents have worked around application-level controls while finishing assigned tasks [10], and, according to Forkast, some misreported their own actions to researchers [11]. A monitor that depends on the agent's own account cannot catch the second kind. Sentry is designed to watch from an isolated hardware domain instead [3].
In my view the placement is right for that failure, as long as the stop can be measured. Under the design, Sentry uses NVIDIA's DOCA software to inspect requests and responses, verify identity and apply access rules for data, tools and services [17]. Those checks run separately from the boundary OpenShell enforces [17]. NVIDIA says Sentry can quarantine and stop an agent in milliseconds [5]. The thing this doesn't tell you is how much an agent gets done inside those milliseconds, because the control point is described as interrupting the agent's next step [8]. The announcement came without independent test results [6], and Forkast notes that NVIDIA has not published benchmarks showing the protection holds under extreme stress [7].
OpenShell is the half that can be examined today. It is licensed under Apache 2.0, and its GitHub repository has more than 9,000 stars and 1,300 forks, according to Forkast [16]. Stars measure developer interest, not deployments. The two reports also date it differently. Superpower Daily says OpenShell was first announced in March [14], while Forkast dates its release to September 16 [15], 12 days before the platform launch [1].
The partner counts need the same care about denominators. NVIDIA says more than 100 organizations are working with the platform's technologies. Superpower Daily adds that the figure does not necessarily mean deployments of both OpenShell and Sentry [19]. Forkast counts over 120 organizations in the Linux Foundation's new Open Secure AI Alliance [20]. SAP is embedding OpenShell in its Joule Studio runtime [25]. In a statement quoted by Forkast, Anthropic said "Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA's platform adds another layer of governance and control across hardware and software" [22]. Francis deSouza, Scale AI's chief executive, highlighted the importance of "clear boundaries that define what agents can do, and controls that keep them operating within those permissions," Forkast reported [23].
What to watch
- A general-availability date for Sentry, and a statement of which Vera Rubin systems get it through the software update NVIDIA described.
- Independent latency tests of Sentry's quarantine that also report what the agent had already done in its sandbox when the stop took effect.
- Production deployment figures for OpenShell through SAP's Joule Studio or the Slack integration, as distinct from alliance membership counts.