What does Nvidia's Open Agent Safety Platform actually do?

It puts a fence around an AI agent and posts a guard outside the fence. Nvidia announced the system on September 28 to stop agents from acting outside the limits someone set.

The problem is real: agents that write code, use software and carry out tasks on their own can also wander outside the boundaries a developer intended. The platform has two parts. OpenShell creates a secure runtime around an agent and controls what it can reach. Sentry sits apart from that runtime, on Nvidia's BlueField-4 chip, and watches what the agent is doing. Nvidia says that if an agent tries to move outside its boundaries, Sentry can quarantine it in milliseconds.

Think of it like hiring someone and handing them a badge that only opens certain doors, plus a security desk that can lock those doors the moment something looks wrong. Nvidia built a version of that for software workers instead of human ones.

Why put the safety check on separate hardware?

Because an agent that has gone rogue can't be trusted to police itself. Sentry runs on its own chip, apart from the agent it watches.

That separation is the point. It lets Sentry act even if the agent's own environment is compromised. Nvidia didn't stop at software. OpenShell enforces the runtime boundary with help from Nvidia's Vera CPU, built for agentic AI. Sentry uses the separate BlueField-4 chip as what Nvidia calls an out-of-band watchdog. The same design extends into robotics, where an agent's mistake stops being a wrong answer on a screen and becomes a physical action.

That is the part worth sitting with. Nvidia spread the safety controls across chips, runtime software and robotics tools instead of shipping one program. Each piece works better with the others.

How Nvidia has expanded past selling GPUs
What AI needed What Nvidia added
Faster computing GPUs
Moving data between chips at scale Networking
General-purpose compute for AI factories CPUs and full rack systems
Physical AI and robotics Robotics infrastructure
Boundaries for autonomous agents Open Agent Safety Platform

Who is already using it, and why does that list matter?

Because the companies signing on aren't experimenting with a chatbot. They're the ones with the most to lose if an agent acts outside its lane.

Nvidia says more than 100 organizations are working with the platform. Anthropic is integrating it with Claude Managed Agents. Salesforce connected OpenShell to Slack so people can see what an agent is doing and approve more access. SAP is building it into Joule Studio. ServiceNow, Microsoft, CrowdStrike, Cisco, Palo Alto Networks and Palantir are involved, alongside Citi and JPMorganChase on the banking side.

The list gets more telling from there. Hitachi Energy, NextEra Energy, Schneider Electric, Siemens Energy, EPRI and Quanta Services are working with the platform, along with the robotics company Figure. Those are firms running power grids, utilities and physical equipment, the kind of system where an agent's mistake carries real-world consequences, not a wrong spreadsheet cell.