NVIDIA has launched the NVIDIA Open Agent Safety Platform, an open software platform for AI agent security that pairs the OpenShell secure runtime with Sentry, an out-of-band watchdog on BlueField-4 DPUs. The system is designed to prevent "drift," a failure mode where agents circumvent application-layer controls, by placing safety enforcement outside the agent's reach.
- OpenShell provides isolated sandboxes for agents using Docker, Podman, MicroVM, or Kubernetes, with hot-reloadable network and provider rules.
- Sentry runs on BlueField-4 DPUs to inspect requests, provide attested telemetry, and enforce zero-trust access while remaining isolated from the host.
- The platform claims up to 80% faster sandbox performance on NVIDIA Vera CPUs compared to traditional CPU infrastructure.
- OpenShell is available under Apache 2.0 for Linux, macOS, and Windows WSL 2, with built-in support for Claude Code, Codex, and GitHub Copilot CLI.
The platform aims to address agent safety by ensuring controls cannot be disabled by a compromised runtime, with over 100 organizations including Anthropic and SpaceXAI working with the system.