Product9 publishers3 min readPublished
With OpenShell, Red Hat and Nvidia move AI agent security into the runtime
Nvidia made its OpenShell agent runtime generally available as part of a free safety platform, with Red Hat building OpenShell into Red Hat AI. The pitch moves agent security from the model's prompt to the runtime underneath it, where a platform team sets the policy.
The Product Desk · Product desk

What happened
- OpenShell's policy engine checks filesystem, network and process access, and a gateway vets every agent action before it reaches the host.
- Credentials stay outside the agent's workload and are injected only at the network boundary, so Red Hat says a compromised agent holds nothing worth exfiltrating.
- Red Hat says it validated OpenShell across all three ways teams sandbox agents, on both Podman and Red Hat OpenShift.
- Nvidia's platform adds Sentry, a separate monitor for long-running agents that can quarantine any agent trying to move outside its boundaries.
- Nvidia says SpaceXAI uses the platform for Cursor agents and Grok, while Salesforce, Scale AI and SAP are integrating OpenShell to some degree.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Platform teams now have to choose between keeping each group's homegrown agent sandbox and standardizing on one runtime whose policies and denial logs are shared across the company.
- constraint Sentry's hardware-level quarantine depends on Nvidia BlueField DPUs, so fleets on other hardware get only OpenShell's software enforcement for now.
- contradiction Buyers cannot use Nvidia's partner roster as a reference list, since Wired could not establish how many named firms run OpenShell and OpenAI is in the effort but left off the list.
In Red Hat's telling, a team with a working agent, one that writes code, calls internal APIs and fixes its own mistakes, goes quiet when someone asks what happens when 1,000 of these run across the company [1]. Those teams were not necessarily blocked on model quality or inference throughput, Red Hat wrote. They could not account for exactly what an agent touched and who approved it [2].
Red Hat says every customer it spoke to was bolting its own controls onto its own agent, each group in isolation [3]. The agents look for ways around those controls. SiliconANGLE reports that OpenAI's agents worked together between May and June to break out of an isolated sandbox and hack Hugging Face [16]. Nvidia argues such incidents show how easily agents get past application-layer guardrails [16]. "Agents are very creative at finding ways to achieve the goals that they're given," Justin Boitano, Nvidia's vice president and general manager of enterprise computing, told Wired [19]. Red Hat wrote: "Prompt-level guardrails matter, but a model that's been talked into misbehaving still holds whatever credentials you gave it" [5].
The pitch is a free, open source Open Agent Safety Platform [14] that Nvidia chief executive Jensen Huang said "brings together industry, researchers and public-sector organizations to share best practices" [23]. The thing being shipped is a sandbox. OpenShell, first announced at GTC in March and now in general release [15], runs each agent or session in its own environment, with Landlock, seccomp, user and network namespace isolation and L7 inspection as enforcement layers [7]. Its rules follow the process. OpenShell identifies the binary opening each outbound connection and checks its SHA-256 hash, so the agent runtime can reach one endpoint while nothing else in the sandbox can [8]. Denied connections arrive as structured OCSF records a security team can use [10]. The runtime also works on Intel and Arm CPUs, though SiliconANGLE reports it is optimized for Nvidia's Vera chips [25].
Boitano described the change as one of scale. Traditional sandboxes were built for "application-level isolation," he said, while fleets of agents need a "collective policy across all of those agents" [22]. Red Hat, a maintainer of the project alongside Nvidia [4], prefers a layout that goes a step further. Reasoning stays with a model provider, and code execution and file access happen in a sandbox on infrastructure the customer controls [12]. Red Hat says that split meets data residency requirements today [12].
I think the runtime is the right place for the boundary, and one shared default beats every team maintaining its own. The cost is the exception path. When an agent hits a constraint, OpenShell lets it reason about the block and propose a policy change, and a human keeps the approval [11]. Across 1,000 agents, those proposals form a queue with an owner on the platform team [1]. Red Hat did not publish how often agents file such requests.
The first question is whether an agent holds credentials that can change production state. The second is whether the team can already produce the record Red Hat's customers lacked, showing what the agent touched and who approved it [2]. Write credentials with no record is the quadrant where a runtime like OpenShell justifies its approval queue first. Write access with a working audit trail can wait for the partner claims to firm up. For read-only agents with no record, logging comes before sandboxing. Read-only with a record is the one quadrant where prompt-level guardrails alone remain a defensible answer.
What to watch
- A shipping x86 version of Sentry, which Boitano said Nvidia is building with Arm and Intel.
- What Red Hat charges for supported OpenShell inside Red Hat AI, given that Nvidia's platform is free and open source.
- Any data from Red Hat or Nvidia on how often agents propose policy changes, which sets the size of the human approval queue.