Systems
Security
Data
Python

PLEXData Engineering for people and agents that act on systems

Permissions, Limits, Evidence & eXecution.

No. 012 Latest feature

Wednesday, 30 September 2026

plexdata.online

008

Published
Author
Dorian Sotpyrc
Reading
6 minutes · News analysis
Status
Launch confirmed · claims still testing

News · Agent security

NVIDIA Moves Agent Safety Below the Model With OpenShell and Sentry

Most agent safety asks the model to behave. NVIDIA’s launch is built around a harder question: what still holds when it doesn’t? The interesting answer sits outside the model, and optionally outside the host software too.

References

In this conceptual policy example, a model requests a file read and an outside send. Runtime policy allows the read and blocks the send. This is not a test of a named product.

Fig. 1 · Outside the modelConcept model

The model can request it. The runtime can refuse it.

Dotted path: unreachable
In this article · 5 sections
  1. 01Two layers, one idea
  2. 02A smaller room
  3. 03If the host fails
  4. 04Shipped vs claimed
  5. 05Worth keeping
Confirmed

The platform launched

NVIDIA announced the Open Agent Safety Platform on 28 September 2026, built around OpenShell and the Sentry reference design.

Vendor claim

Could stop escapes

NVIDIA says Sentry can quarantine agents that move outside policy boundaries in milliseconds. That is a product claim, not a universal result.

Open question

Real-world policy quality

Runtime enforcement is only as useful as the permissions and policies organisations define. Deployment evidence will matter more than launch architecture.

Most of us have handed an agent a credential and trusted it to use it sensibly. That works right up until it doesn’t, and this launch is about the second half of that sentence.

On 28 September, NVIDIA launched the Open Agent Safety Platform: OpenShell, an open-source runtime boundary, plus Sentry, an optional out-of-band enforcement design that uses BlueField-4 DPUs.1

What caught my attention is the split. The model decides what to attempt. The environment decides what is permitted. NVIDIA’s own product page draws the same line: model safeguards influence behaviour; runtime controls enforce allowed actions.2 I think that is the right line, and it is an easy one to blur when a model is doing something impressive.

§ 01Two layers, one idea

The launch combines two layers.

  • OpenShell — an open-source runtime that places agents in sandboxed environments governed by policy.
  • Sentry — a reference system design that runs an independent watchdog on BlueField-4 DPUs and can enforce policy outside the agent workload.

NVIDIA says OpenShell can also extend to third-party compute platforms, including Arm and Intel systems. The company listed a large set of launch partners across AI labs, enterprise software, security and infrastructure.1

23 Mar 2026

OpenShell appears as a secure agent runtime

NVIDIA describes a policy layer outside the model/application process for agent files, tools, credentials and network access.

17 Sep 2026

OpenShell docs show a mature runtime surface

Current documentation covers sandbox policy, provider routing, observability and supported agents.

28 Sep 2026

Open Agent Safety Platform launches

OpenShell becomes the software layer in a broader design that adds Sentry as an independent hardware-backed watchdog.

§ 02OpenShell lets a capable agent work in a smaller room

OpenShell's current developer guide describes sandboxed execution with controls over files, process behaviour, network access, credentials and inference routing. It also exposes allow/deny logging and policy configuration.3

The new technical blog describes Gateway, Supervisor and Sandbox components and says policy is enforced without requiring the agent itself to be rewritten.4

The useful shift is that you don’t have to make the agent less capable. You make the room it works in smaller.

§ 03Sentry starts from the assumption that the host might fail

Sentry is designed to run on BlueField-4 DPUs as an out-of-band monitor. NVIDIA says it can correlate activity, enforce identity and access policies, and quarantine an agent that attempts to leave its software boundary.1

That is a more honest starting point. It assumes something can go wrong with the workload or the host, and plans for it: if either is compromised, some monitoring and enforcement still exists outside it.

AP's launch coverage describes the same basic split—OpenShell as the constrained workspace and Sentry as the watchdog—and notes that defining effective rules remains a hard problem.5

§ 04What shipped, what is claimed, and what nobody knows yet

Confirmed: the platform, code/docs and reference architecture exist; OpenShell is open source; the launch names partners; the runtime exposes concrete policy and observability features.

Claimed: NVIDIA says the architecture could have prevented recent agent security incidents and that Sentry can quarantine escapes in milliseconds. Reuters reports that claim as NVIDIA's assertion, not an independently established result.6

Still open: how well organisations will write policies, how performance behaves under real mixed workloads, how easy bypasses are across different deployment modes, and whether hardware-isolated enforcement becomes common outside NVIDIA-heavy environments.

§ 05The part worth keeping, even if you never buy the hardware

The direction is larger than NVIDIA hardware. Agent security is moving from model-only controls toward layered enforcement: identity, runtime isolation, network policy, tool authorization and audit.

The signal I take from it: the better agents get at pursuing goals, the more the infrastructure around them has to say, plainly, which paths are impossible. Not discouraged. Not logged. Impossible.

§References

  1. 1NVIDIA — Open Agent Safety Platform launchnvidia.com
  2. 2NVIDIA — Open Agent Safety Platform overviewnvidia.com
  3. 3NVIDIA — OpenShell Developer Guidedocs.nvidia.com
  4. 4NVIDIA Technical Blog — Add Runtime Controls to AI Agents with OpenShelldeveloper.nvidia.com
  5. 5Associated Press — How NVIDIA's agent containment approach would workapnews.com
  6. 6Reuters — NVIDIA releases AI safety softwarereuters.com