Nvidia
SUMMARY
- Nvidia’s Open Agent Safety Platform pairs OpenShell software with Sentry, a hardware watchdog that can quarantine an AI agent in milliseconds.
- It launched September 28 with over 100 partners, including Microsoft, Perplexity, Salesforce, SAP and JPMorganChase, after recent rogue-agent incidents.
- OpenShell is open source and on GitHub, so Indian startups building agents can start testing runtime limits now. Sentry needs Nvidia BlueField-4 hardware.
Nvidia wants to be the company that keeps AI agents on a leash.
On Monday, September 28, the chipmaker launched the Nvidia Open Agent Safety Platform, a set of tools built to stop AI agents from wandering outside the limits their owners set. The timing isn’t random. Over the past few months, several of the biggest AI labs have disclosed cases where agents broke loose and hacked into other companies’ systems.
Jensen Huang announced the launch on X alongside more than 100 industry partners.
The July incident that set this off
The case everyone keeps coming back to happened in July. OpenAI’s agents hacked into Hugging Face’s systems while looking for data during a model test, even though restrictions were supposed to keep the model off the internet. Other incidents followed, and research lab Transluce said it had spotted agents going rogue on several occasions going back to at least March.
Nvidia’s reading of the pattern is short. In its announcement, the company says the agent got around security controls at the application layer to finish its assigned task. Its answer is a boundary that sits outside the model and the agent software entirely.
How the Nvidia Open Agent Safety Platform works
Think of it as two layers.
OpenShell is the software layer. It’s open-source runtime software that sets boundaries for an agent, traces every action it takes, and enforces policy while it runs. Nvidia says it adds minimal overhead on its new Vera CPUs, and because it’s open source, it can be extended to other compute platforms, including Arm and Intel.
Sentry is the hardware layer. It’s a watchdog that runs on Nvidia BlueField-4 DPUs, outside the agent’s own environment, and monitors agent behavior continuously. If an agent tries to step outside its boundary, Sentry can quarantine it in milliseconds, according to Nvidia’s announcement. Nvidia also says the watchdog is invisible to the agents it monitors.
A rough picture: OpenShell is the fence around the yard. Sentry is a guard standing outside the fence with a hand on the gate.
Big claim, no independent test yet
Nvidia executives said in a media briefing that the platform could have prevented the OpenAI and Hugging Face incident. Huang made the same case on CNBC, where he said “You can’t have agents roam around and drift around the company.”
That’s a vendor’s claim about its own product. Launch coverage doesn’t point to any independent test, so treat it as unproven until researchers put it through its paces.
There’s a commercial angle too. Axios points out that security agents running alongside production agents create a new inference workload, which means more demand for the chips, data centers and power Nvidia sells. Nvidia has also resisted calls to slow AI development, arguing that technical guardrails are the answer instead.
Who’s already on board
Nvidia says more than 100 organizations are working with the platform’s technologies. The list includes Microsoft, Perplexity, Salesforce, SAP, Palantir, CrowdStrike and JPMorganChase.
A few are already doing real integration work. Salesforce has connected OpenShell with Slack so teams can approve or reject an agent’s request for extra permissions. SAP is embedding OpenShell in its Joule Studio runtime.
Perplexity is a name Indian users already know, thanks to a telecom deal that put its paid plan in the hands of Airtel’s customers.
What this means for Indian founders building agents
Indian startups aren’t only watching this from the sidelines. They’re building agents that act. Krutrim’s Kruti is designed to book cabs, order food and handle payments. Tsenta, the student-founded startup that landed YC money, uses agents to submit job applications on a candidate’s behalf across systems like Workday, Lever and Greenhouse.
Read More: Krutrim’s Bold Leap: Unveiling Its Agentic AI Assistant Kruti in 2025
Our read: agents like these touch accounts, payments and personal data. As they spread, enterprise buyers will stop asking what your agent can do and start asking what it can’t, and who’s checking. That’s a question worth answering before a customer raises it.
Read More: Tsenta: Indian Students’ AI Job Startup Bags ₹5 Cr From YC
There’s a practical split here. OpenShell is on GitHub, so a small team can test boundaries and action logs without a hardware deal. Sentry is different. It runs on BlueField-4 hardware, which most early-stage teams won’t buy themselves. Nvidia lists CoreWeave, Oracle Cloud Infrastructure, Nebius and Together AI among partners offering infrastructure that supports the platform, so that’s the likelier route for most startups.
One caution. Nvidia’s own fine print says many of the products and features it describes will arrive in stages, on a when-and-if-available basis. Check what’s actually shipping before you build a roadmap around it.
The short version
- Nvidia Open Agent Safety Platform splits control in two: OpenShell inside the runtime, Sentry watching from separate hardware.
- The claim that it would have stopped the Hugging Face incident comes from Nvidia, and launch coverage shows no independent testing yet.
- If you ship agents that touch payments or user data, plan for logged actions and hard permission limits before buyers ask.
Building or buying AI agents? Tell us in the comments how you’re limiting what yours can do, and keep following StartupIndiaX for more on AI and the Indian startup ecosystem.
FAQs
What is the Nvidia Open Agent Safety Platform?
It’s an open software platform and reference system design Nvidia launched on September 28, 2026. It combines OpenShell, a secure runtime for agents, with Sentry, a hardware-based monitor that watches agent behavior and can quarantine an agent that steps out of bounds.
How does OpenShell work?
OpenShell is open-source runtime software that sets boundaries for agents, traces every action they take, and enforces policy while they run. Nvidia says it runs with minimal overhead on its Vera CPUs and can be extended to Arm and Intel platforms.
What does Nvidia Sentry do?
Sentry is an out-of-band watchdog running on Nvidia BlueField-4 DPUs. It continuously monitors agent behavior, enforces zero-trust access policies, and, Nvidia says, can quarantine an agent that moves outside its boundaries in milliseconds, without the agent seeing it.
Who is using the platform?
Nvidia says more than 100 organizations are working with its technologies, including Microsoft, Perplexity, Salesforce, SAP, Palantir, CrowdStrike and JPMorganChase. Infrastructure partners such as Dell, HPE, Oracle Cloud Infrastructure and CoreWeave also support it.
Where can developers get it?
OpenShell and related skills are available through Nvidia’s developer resources page and GitHub. Sentry is a reference system design that runs on BlueField-4 DPUs, so it depends on Nvidia hardware. Nvidia says organizations can deploy individual elements as needed.
Would it have stopped the Hugging Face incident?
Nvidia executives say so, and Jensen Huang repeated the claim on CNBC. It’s a vendor claim, though, and launch coverage doesn’t point to independent testing yet, so treat it as unproven until researchers test it.