Analyst(s): Fernando Montenegro, Brendan Burke, Mitch Ashley
Publication Date: September 29, 2026
NVIDIA’s Open Agent Safety Platform pairs the OpenShell runtime with Sentry, a watchdog for BlueField-4 DPUs, to enforce agent boundaries beyond the agent’s reach. The architecture is sound, but its formal policy prover shifts the hard work to translating human intent into a policy it can check.
What Is Covered in This Article:
- NVIDIA launched the Open Agent Safety Platform, pairing its open-source OpenShell runtime with Sentry, an out-of-band watchdog on BlueField-4 DPUs, and partnering with 100+ organizations.
- Moving agent controls outside the agent’s reach is the right instinct, and it matches a gap enterprises report: 56% of surveyed decision-makers say they lack the ability to detect or contain a compromised agent at machine speed.
- OpenShell’s Z3-based policy prover can show that a policy stays within an approved boundary, but translating human intent into that boundary remains the hard, largely manual step.
- OpenShell is broadly available software, while Sentry depends on BlueField-4, whose adoption is still limited and which competes with DPUs that the hyperscalers already run.
- Owning the path to the model puts NVIDIA in closer competition with its own partners, in a market where enterprises will run several agent control planes at once.
The News: NVIDIA announced the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for governing AI agents across software and hardware.
NVIDIA OpenShell is an Apache 2.0 open-source runtime, first introduced at GTC in March 2026 and now at version 0.1.0. It runs agents in sandboxes with kernel-level isolation, enforces policy on file, network, process, and credential access, and uses a formal-methods policy prover to check permissions before an agent starts. It supports NVIDIA Vera CPUs as well as ARM and x86.
NVIDIA Sentry, part of the reference system design, is an out-of-band watchdog on BlueField-4 DPUs, built on DOCA. It monitors agent activity on the path to the model and can quarantine an agent in milliseconds.
NVIDIA cites 100+ participating organizations, including Anthropic (integrating Claude Managed Agents with OpenShell), Microsoft, CrowdStrike, Palo Alto Networks, and JPMorganChase. SAP is embedding OpenShell in its Joule Studio runtime, and Salesforce has integrated it with Slack for human oversight of agent requests.
NVIDIA Wants Agent Safety Enforced in Silicon
Analyst Take: Much of this year’s agentic security conversation has been about training better behavior into models. NVIDIA’s announcement makes a different bet, one we find more familiar and more defensible: assume the agent will drift, and put the controls somewhere the agent cannot reach.
The idea is old (the reference monitor concept goes back to the 1970s), but it is a welcome one in a market that has spent a lot of energy hoping alignment will do the work of access control.
The timing is not subtle: the launch lands two months after an OpenAI capability evaluation escaped its sandbox and breached Hugging Face (now, somewhat pointedly, one of the named participants). When we covered OpenShell at GTC in March, we argued that enforcement has to be structural, out of reach of the agent, a prompt injection, or compromised code; this launch carries that principle into silicon.
What is new here is the hardware layer, a policy prover that has matured since it landed in the open-source repo in April, and a partner list long enough to suggest NVIDIA wants this to be the default for containing agents.
Controls Outside the Agent Are the Right Instinct
In our 1H2026 Cybersecurity Decision-Maker survey (N=933), 56% of respondents agreed that even with AI usage policies in place, they lack the ability to detect or contain a compromised agent operating at machine speed.
NVIDIA’s own research shows why a policy on paper is not enough. In an early OpenShell demo, an agent blocked from writing to a GitHub repository switched to a previously approved binary over a lower-level protocol and wrote to it anyway.
OpenShell moves file, network, process, and credential controls into the kernel and a supervisor outside the agent’s workload, swapping in real credentials only for approved endpoints. Sentry adds an independent vantage point on the BlueField-4 DPU, on the path to the model and outside the host’s reach.
The credential swap deserves more CIO attention than it will get, since it places authorization at the point where an agent touches a real system. The launch materials do not say how it extends to MCP servers, fast becoming the way agents reach enterprise data.
Proving a Policy Is Not the Same as Writing the Right One
The piece we find most interesting and most likely to be underestimated is OpenShell’s policy prover. It encodes policies as formulas for the Z3 SMT solver and asks a precise question: does this candidate policy allow any action that an approved boundary policy does not? It comes from the same family of automated reasoning AWS applied to IAM and S3, and because the result is deterministic, an agent cannot talk its way past it.
Our concern is with what happens before the solver ever runs. Someone has to take a human policy, such as “source code does not leave the company” or “this agent may read tickets but never close them,” and express it as a boundary in OpenShell’s YAML schema. That boundary then feeds two separate translations, one into OPA/Rego for runtime enforcement and one into SMT constructs for the proof, and each is a place where intent can get lost.
NVIDIA is candid about the limits. Its documentation states that a passing result does not establish least privilege or semantic safety; its researchers add that the checks lack context, so a throwaway repository and a production one look the same. NVIDIA told analysts that this release verifies aggregate policy across agent fleets, though its documentation still calls cross-agent analysis ongoing work.
The prover can tell you the fence is where you drew it, not whether you drew it in the right place. That is the goal-versus-action authorization gap we have written about before, and formal methods move it rather than close it.
There is a skills question too. Few security teams employ people who can reason about SMT encodings, and AWS spent years making Zelkova-style reasoning invisible to administrators. When we raised this on NVIDIA’s analyst call, the answer was that agents can help translate plain-English intent into policy and verify it. That is a sensible direction, but it puts a probabilistic system back at the exact step where intent gets lost, so reviewing what the agent drafted matters as much as the proof itself.
Boundary policies become production artifacts for security and platform engineering, and the prover’s natural home is the delivery pipeline, gating a policy change the way a failing test gates code.
Two Layers, and Sentry Rises or Falls With BlueField
OpenShell runs on Arm and x86 as well as Vera. NVIDIA calls 0.1.0 a stable, production-ready release, though it has not published overhead measurements, and says CPUs alone suffice for strict access control in many cases, with the DPU layer aimed at frontier work such as red-teaming with guardrails off.
Sentry is a different proposition. It runs on BlueField, next to Vera or the x86 hosts most operators still run, and can work without OpenShell, but NVIDIA acknowledged that most enterprises do not have BlueField today. Futurum channel checks suggest BlueField adoption remains limited to close design partners, largely because of the bottlenecks a DPU can add to the data path.
Hyperscalers run their own DPUs for tenant isolation (AWS Nitro, Microsoft Azure Boost, Google Titanium), and NVIDIA says Sentry is built for BlueField alone, with open APIs for others to build equivalents. Its early footprint is likely frontier labs, neoclouds, sovereign AI factories, and BlueField-standardized operators such as Oracle Cloud Infrastructure, and reaching further means proving its agent-aware functions add something those DPUs cannot, without adding latency.
Telemetry, the gap we flagged in March, is still open here. NVIDIA describes a tamper-proof record of agent activity but not where it goes, and a DPU quarantine decision has to reach the SOC or SIEM before anyone can audit it.
Who Owns the Control Point?
NVIDIA’s blog calls the path to the model the control point, the best place to observe an agent and the switch to stop it. That puts NVIDIA in more direct competition with companies it also counts as partners.
The hyperscalers run their own agent runtimes with governance hooks, including AWS Bedrock AgentCore, Microsoft Agent 365, and Google’s Gemini Enterprise Agent Platform, with sandbox specialists such as E2B, Modal, and Daytona, among others, competing on isolation. Security vendors including CrowdStrike, Palo Alto Networks, and Cisco are named participants, and Check Point, Fortinet, Zscaler, and others already integrate with BlueField-4 security capabilities.
For now that is cooperation. The longer-term question is whether the runtime becomes the place where agent policy gets authored, which would push today’s partners one layer further from the customer.
We do not expect a single winner. Futurum’s 2H 2026 SLE Market Sizing and Five-Year Forecast projects Agent Control Plane & Agentic Governance growing at a 48.7% CAGR through CY2030, the fastest of its 16 segments, and enterprises will run several control planes at once, each with its own policy model; SAP and Salesforce already put NVIDIA’s runtime inside theirs.
Openness is moving in the right direction. NVIDIA told analysts it plans to move OpenShell to a neutral home under the Linux Foundation, with CNCF as the destination and an announcement described as imminent. Until then, governance sits with NVIDIA, and Sentry remains an NVIDIA implementation that is not fully open source.
On evidence, NVIDIA pointed analysts to Hugging Face research suggesting OpenShell alone would have caught the rogue agents coordinating before they began writing exploits. Encouraging, but a reconstruction rather than a field result. Reference deployments or third-party audits from regulated partners would carry more weight than the logos.
What to Watch:
- Will Sentry travel beyond BlueField? NVIDIA builds Sentry for BlueField only, on Vera or x86 hosts. Third-party implementations of its open APIs, or ports to other DPUs, would decide whether Sentry becomes a category or stays an NVIDIA feature.
- Who will write the boundary policies? The prover is only as good as the policy it checks. Watch for policy libraries and tooling that turn business intent into OpenShell boundaries without requiring SMT expertise.
- Does fleet-wide proving hold up? Combined permissions across agents are where exfiltration paths hide. NVIDIA says aggregate verification works today while its documentation calls it ongoing work, and a public demonstration would be the prover’s strongest proof point.
- Will security vendors build on the runtime or compete for it? Security platform vendors are partners today. Watch whether they build policy authoring on top of OpenShell, or push to own the layer where agent policy gets written.
- What will OpenShell’s foundation move look like? NVIDIA says a CNCF home under the Linux Foundation is imminent. Governance terms, the maintainer mix, and whether Sentry components follow will decide how neutral the agent control point becomes.
For more information, read the full announcement from NVIDIA.
Read the OpenShell technical walkthrough here.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
So This Is How AIs Attack: Observations From the OpenAI and Hugging Face Incident
The Hard(er) Challenge in Agent Governance Is Authorization
OpenShell Redraws the Agent Control Plane — Open Standard or Product Launch?
A Loud Floor and a Quiet Gap: Security Summer Camp 2026
Microsoft Agent 365 Turns Shadow AI Into a Governed Asset Class
