Skip to content
NVIDIA Launches Open Platform to Secure Autonomous AI Agents

NVIDIA Launches Open Platform to Secure Autonomous AI Agents

Infosecurity-Magazine • September 28, 2026

NVIDIA has launched an Open Agent Safety Platform designed to place enforceable controls around autonomous AI systems from testing through deployment.

The platform combines OpenShell, an open-source runtime that traces agent activity and enforces policies, with Sentry, a hardware-based watchdog that independently monitors agents and can quarantine them in milliseconds, according to NVIDIA. The company announced the platform on September 28.

NVIDIA said the platform is intended to address incidents in which AI agents have bypassed application-layer controls while carrying out assigned tasks. It combines software controls with monitoring at the hardware and compute layers rather than relying on the model or agent harness alone.

OpenShell Adds Runtime Controls for AI Agents

OpenShell provides a runtime security boundary for agents running on CPUs, controlling their access to systems, data and services while recording their actions. NVIDIA said the software is now broadly available as open source and can be extended to third-party compute platforms from Arm and Intel.

The runtime combines sandboxed execution, controlled service access and credential management with policy enforcement. A supervisor paired with each OpenShell sandbox checks outbound requests against policy, while the sandbox applies kernel-level filesystem and process controls to the agent workload.

NVIDIA said OpenShell can also provide human oversight for agent activity. Salesforce, for example, has integrated it with Slack so users can review activity and audit events, and approve or reject requests for additional permissions.

More than 100 organizations are working with the Open Agent Safety Platform, including Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce and ServiceNow. NVIDIA said organizations in financial services, energy and robotics are also working with the technology, including for systems that can act in the physical world.

Sentry Adds Hardware-Based Agent Enforcement

Sentry is an optional hardware layer of the platform, using NVIDIA BlueField-4 data processing units (DPUs) as an out-of-band watchdog. NVIDIA said it continuously monitors agent behavior from an isolated trust domain and can quarantine or stop an agent that moves beyond its permitted boundaries in milliseconds.

The system is designed to operate independently of the agent itself, applying agent governance controls to requests involving data, tools, application programming interfaces (APIs) and services. NVIDIA said this provides a separate enforcement layer that remains outside the agent's software environment.

NVIDIA said Open Agent Safety Platform software, including OpenShell and related skills, is available through its developer resources and GitHub.

The launch comes amid growing concern over the behavior and permissions of autonomous systems. Guidance on agentic AI from the UK's National Cyber Security Centre (NCSC) previously warned that agents can have broad access to systems, data and tools and that rapid autonomous activity can make unexpected behavior harder to detect.

Image credit: credit: Sundry Photography / Shutterstock.com

GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise News 7 April 2026

GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise

NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names News 28 July 2026

NVIDIA’s Open Secure AI Alliance Is Missing Some Big Names

'AI Will Revolutionize Every Aspect of Connectivity,' Argue Cyber Experts News 26 November 2021

'AI Will Revolutionize Every Aspect of Connectivity,' Argue Cyber Experts

NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing News 6 August 2026

NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing

MSOE Opens Cyber-Learning Center Built with $34m Alumnus Donation News 13 September 2019

MSOE Opens Cyber-Learning Center Built with $34m Alumnus Donation

What’s Hot on Infosecurity Magazine?

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk

Emerging Ransomware Gang Uses Backup Destruction Threats to Pressure Victims

RemControl Banking Trojan Gives Attackers Remote Control of Android Devices

Researchers Identify AliExpress Phishing Domains Before Registration

Ransomware Attacks Reach Record High for 2026

Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes

Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records

ShinyHunters Claim Hack of Rival Ransomware Gang Clop

ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day

New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code

UK Government Shifts to Service-Led Cyber Governance After Stinging Audit

AI-Driven Cloud Threats and Defenses: Securing AI-Powered Environments

Your Security Awareness Programme Isn't Failing, It's Just Not Relevant

From APIs to Agents: How to Secure AI at Enterprise Scale

Frontier AI: How Cyber Defenders Can Harness the Defender’s Window

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust