Two layers of control
OpenShell, first announced at Nvidia’s GTC conference in March, isolates agents while they work and restricts their activity at the operating-system kernel level. Sentry is intended to add another boundary: continuous monitoring on Nvidia’s BlueField data processing units, with the ability to isolate agents that try to cross the limits set for them.
Nvidia says Sentry will let customers apply security policies through OpenShell. Justin Boitano, Nvidia’s vice president and general manager of enterprise computing, says the point is to give teams a single policy for groups of agents, rather than treating each application separately. Agents can find creative ways to pursue their goals, he says; Sentry is meant to restrict them to resources approved by a security team.
Nvidia is working with Arm and Intel on an x86 version of Sentry. Boitano says that once the platform runs on those architectures, it will be able to work on any instruction-set architecture.
The company also lists partnerships with:
Nvidia says SpaceXAI uses Open Agent Safety Platform for Cursor agents and Grok models. Anthropic and Nvidia are “building security into Claude Managed Agents,” the company says. Salesforce, Scale AI and SAP have confirmed that they are integrating OpenShell to some degree.
But the announcement does not make clear whether every company on Nvidia’s list has deployed the platform, or whether the list refers to broader collaboration. OpenAI is absent from the list. Both companies confirmed that OpenAI is involved in work on OpenShell, but neither explained why it was left out of the announcement.
The standard-setting question
OpenShell’s launch preceded OpenAI’s report that its agents had hacked Hugging Face by several months. Earlier this month, Nvidia agreed to buy Hugging Face for $12.9 billion. The sequence gives the safety pitch a pointed backdrop: Nvidia is promoting tools for controlling agents while expanding its role in the ecosystem where those agents are built and used.
Nvidia also launched an industry coalition for AI safety in July; it now includes more than 120 companies. One of its initiatives is the Shared AI Findings Exchange (SAFE). Last month, Boitano said SAFE should be governed independently, so no single company or part of the industry controls its findings.
My read is that Nvidia is not just offering a sandbox; it is trying to shape the rules that sit around AI systems, from chips to software. That ambition makes independence more than a governance detail. The same company is a major supplier of the hardware the technology industry depends on and a central force behind open-source safety efforts.
The underlying controls are not new. Security engineers have long argued that agents should be isolated and monitored. Recent cases suggest those basics may not be consistently applied, even by leading AI labs. Niels Provos, an experienced security engineer and researcher who introduced his own open-source framework for these problems in February, argues that tools for adding constraints are useful—and at minimum challenge the idea that agents cannot be controlled.
What remains unclear is whether tools like OpenShell and Sentry will become routine safeguards, or whether adoption will lag behind the push to deploy agents. Nvidia can supply a framework; it cannot make the industry use it.
Daily AI news
Every day we pick what actually matters in AI and explain it plainly — no hype, no filler. Subscribe if you want to follow where the industry is going.
Only what matters — every day
Follow on X