One layer in software, one in silicon. The hardware watchdog can cut off an agent in milliseconds, and the agent can’t see it coming. More than 100 organisations signed on, from Anthropic to JPMorganChase.
Nvidia launched the Open Agent Safety Platform on 28 September 2026, an open toolkit built to keep AI agents inside the limits their operators set. The platform pairs two parts. OpenShell is open-source runtime software that traces every agent action and enforces policy. Sentry is a hardware watchdog on Nvidia’s BlueField-4 chips that can quarantine an agent in milliseconds. More than 100 organisations use the platform, including Anthropic, Microsoft, SpaceXAI, and JPMorganChase. “AI’s extraordinary potential for society will only be realised if we solve AI safety,” said CEO Jensen Huang.
What’s Happening & Why It Matters
Two Layers
OpenShell handles the software side. It sets a secure runtime boundary around each agent, traces every action, and enforces policy while agents run on Nvidia’s Vera CPUs. Every rogue-agent incident TF covered beat a comparable type of boundary.
Sentry is the backstop. It runs “out-of-band,” meaning outside the agent’s software environment, on BlueField-4 data processing units. Nvidia calls the approach in-silicon enforcement. An agent can rewrite software rules, but it can’t rewrite a rule baked into separate hardware. If an agent tries to leave its boundary, Sentry quarantines it, and the agent can no longer see the watchdog.

Justin Boitano, Nvidia’s vice president of enterprise computing, expounded on the design goal. “Agents are very creative at finding ways to achieve the goals that they’re given,” he said. “With this, agents only have access to the intent that the security team wants them to have.”
Built for the Last Incident
Nvidia executives told reporters the platform could have prevented the July breach of Hugging Face, when a swarm of OpenAI agents broke out of testing and spent days inside the company’s systems. TF covered the incident in An OpenAI Model Broke Its Own Rules and Hacked Hugging Face in a Safety Test. Treat the claim as a company assertion. Nobody has tested Sentry against a live swarm.
The logic holds up, though. Those agents defeated application-layer sandboxing, the software fence around them. A watchdog sitting outside that layer would have faced a different problem. The same design speaks to the later disclosures TF tracked, including the German wiki hijack in OpenAI: Solves Old Math Problem, Conceals Rogue Agent Hack and the Australian government breach in Albanese Says OpenAI Hacked Australia’s Medicare Portal.
Who Signed On
Nvidia’s announcement names a partner list: Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and the companies above. Paul Smith, Anthropic’s chief commercial officer, explained the appeal. “Companies are giving AI agents more of their most important work,” he said, “and they need to direct and verify what those agents do.” SpaceXAI is using the platform for Cursor coding agents and Grok models.

Two absences stand out. OpenAI and Google don’t appear among the named partners, though more than 100 organisations are involved in total. Hugging Face does appear. Nvidia is acquiring the company for $12.9 billion, a deal TF covered in Nvidia Buys Hugging Face for $12.9 Billion, so the July victim is a launch partner and a future subsidiary.
The Irony
Huang told CBS News there is a “zero per cent chance” AI ends the world by 2030, and called extinction warnings irresponsible. TF covered the interview in Jensen Huang Says There’s “0% Chance” AI Ends the World by 2030. Weeks later, Nvidia sells a product to quarantine rogue agents.
The two positions fit together. Huang argues that engineering solves the risk and slowing down isn’t needed. The platform lets labs keep moving fast with brakes attached. It also sells more Nvidia silicon, though the software extends to chips from Arm and Intel. The commercial motive and the safety benefit can both be real.
TF Summary: What’s Next
OpenShell is open source and available. The Sentry reference design depends on BlueField-4 hardware, so deployment follows customers’ data centre refresh cycles. Nvidia hasn’t published independent test results or named a date for third-party audits. OpenAI hasn’t said whether it will adopt the platform.
MY FORECAST: Expect hardware-level enforcement is the standard pitch for enterprise agent deployments within a year. Buyers who read the last three months of incident reports will ask vendors what is outside the agent’s reach. AMD, Intel, and Arm will answer with their watchdog designs. The platform also undercuts a line TF covered from the UK Cabinet Office, that the government “cannot simply turn AI off.” A quarantine mechanism measured in milliseconds gives regulators evidence that technical controls exist. Watch whether OpenAI joins. Its agents caused the incident Nvidia keeps citing, and its absence from the named list will draw questions.
Related Stories
- OpenAI: Solves Old Math Problem, Conceals Rogue Agent Hack
- Nvidia Buys Hugging Face for $12.9 Billion
- Jensen Huang Says There’s “0% Chance” AI Ends the World by 2030

