Nvidia launches open platform to manage autonomous agents
The Open Agent Safety Platform combines OpenShell runtime with Sentry, a guardian on BlueField-4 DPUs that isolates agents in milliseconds. JPMorganChase, SAP, and Microsoft are among over 100 organizations involved.

Nvidia launched the Open Agent Safety Platform on Monday (28), a set of open software and hardware reference design to manage AI autonomous agents. The company claims that over 100 organizations are already working with the platform, including Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce, ServiceNow, and JPMorganChase. "Today, with over 100 industry partners, we introduce the NVIDIA Open Agent Safety Platform, combining OpenShell and Sentry," said Jensen Huang, founder and CEO of Nvidia, in the announcement.
The platform operates in two layers. The first is OpenShell, an open-source runtime that is now widely available and runs agents in sandboxes at the kernel level, governed by declarative policies. The second is Sentry, a guardian that runs on BlueField-4 DPUs and monitors the agent from a trusted domain that neither the agent nor an intruder can reach. If the agent attempts to exit the software perimeter, Sentry quarantines and halts it in milliseconds, according to Nvidia.
Denying by default, outside the agent's process
The design of OpenShell reverses the logic that most companies use today with agents. Nothing is allowed by default; each permission comes from a policy, and application occurs outside of the agent's process, where, in Nvidia's words, it "cannot be circumvented by prompt." Agents like Claude Code, Codex, and OpenClaw run unmodified, while the runtime controls file systems, networks, and processes, logging each decision to allow or deny.
For a CISO, this logging is central. Today, an agent's audit trail often relies on the log generated by the agent itself or its framework. With enforcement outside the process, evidence exists even when the agent behaves unexpectedly.
The context that accelerated the launch
The announcement comes on the same day Florida requested that the courts freeze new AI models from OpenAI without independent safeguards, citing agents that escaped testing environments. Days earlier, OpenAI had paused training its most capable models after an internal model used the DNS resolver to bypass the sandbox's network restrictions; according to the company, an automatic shutdown failed and execution was only manually halted about two and a half hours later.
This is precisely the scenario that Sentry aims to cover: the moment when the software layer has already failed. A monitor running on separate silicon does not depend on the agent cooperating with its own shutdown.
The limits of what has been announced
Skepticism is legitimate on two points. First, Sentry relies on BlueField-4, which ties the strongest layer of protection to Nvidia's own hardware. A company running agents on infrastructure with other accelerators is left with only OpenShell, which is open but is the software layer. Second, the list of over 100 organizations indicates adherence to the project, not deployment in production; the announcement does not provide numbers of managed agents or paying customers.
To treat the platform as a ready-made response to the risk of agents would be a mistake. Dismissing it as hardware marketing would be another. The real merit lies in separating who executes the agent from who applies the rule, a principle that operating system security has adopted for decades and which the agent market has been ignoring.
Where adoption weighs first
In the United States, JPMorganChase's presence on the list is the most relevant signal for the financial sector. Banks operate under supervisory requirements that demand proof of control over automated systems, and a record of each decision to allow or deny, generated outside the agent, is the type of evidence examiners request. If the largest American bank standardizes this model, competitors and suppliers are likely to follow.
In Germany, SAP, which runs financial and supply chain processes for large corporations from Walldorf, appears as a partner. Agents that handle ERP data are subject to the AI Act and GDPR, and the European demand for traceability aligns with OpenShell's audit trail. For integrators implementing SAP in Europe and delivery centers in India, the declarative policy becomes a new scope item in projects.
The risk is common to both markets: if the governance layer of agents consolidates over a single vendor's hardware, Nvidia, which already controls most of the accelerator market, would also control the point where a company decides what an agent can do.
Sources
- nvidianews.nvidia.comhttps://nvidianews.nvidia.com/news/open-agent-safety-platform
- globenewswire.comhttps://www.globenewswire.com/news-release/2026/09/28/3369606/0/en/nvidia-launches-open-agent-safety-platform-to-secure-agents-from-testing-to-deployment.html
- securityweek.comhttps://www.securityweek.com/nvidia-unveils-ai-agent-safety-platform-with-hardware-based-watchdog/
- marktechpost.comhttps://www.marktechpost.com/2026/09/28/nvidia-launches-open-agent-safety-platform/