What does Nvidia's Open Agent Safety Platform actually do?
It puts a fence around an AI agent and posts a guard outside the fence. Nvidia announced the system on September 28 to stop agents from acting outside the limits someone set.
The problem is real: agents that write code, use software and carry out tasks on their own can also wander outside the boundaries a developer intended. The platform has two parts. OpenShell creates a secure runtime around an agent and controls what it can reach. Sentry sits apart from that runtime, on Nvidia's BlueField-4 chip, and watches what the agent is doing. Nvidia says that if an agent tries to move outside its boundaries, Sentry can quarantine it in milliseconds.
Think of it like hiring someone and handing them a badge that only opens certain doors, plus a security desk that can lock those doors the moment something looks wrong. Nvidia built a version of that for software workers instead of human ones.
Why put the safety check on separate hardware?
Because an agent that has gone rogue can't be trusted to police itself. Sentry runs on its own chip, apart from the agent it watches.
That separation is the point. It lets Sentry act even if the agent's own environment is compromised. Nvidia didn't stop at software. OpenShell enforces the runtime boundary with help from Nvidia's Vera CPU, built for agentic AI. Sentry uses the separate BlueField-4 chip as what Nvidia calls an out-of-band watchdog. The same design extends into robotics, where an agent's mistake stops being a wrong answer on a screen and becomes a physical action.
That is the part worth sitting with. Nvidia spread the safety controls across chips, runtime software and robotics tools instead of shipping one program. Each piece works better with the others.
| What AI needed | What Nvidia added |
|---|---|
| Faster computing | GPUs |
| Moving data between chips at scale | Networking |
| General-purpose compute for AI factories | CPUs and full rack systems |
| Physical AI and robotics | Robotics infrastructure |
| Boundaries for autonomous agents | Open Agent Safety Platform |
Who is already using it, and why does that list matter?
Because the companies signing on aren't experimenting with a chatbot. They're the ones with the most to lose if an agent acts outside its lane.
Nvidia says more than 100 organizations are working with the platform. Anthropic is integrating it with Claude Managed Agents. Salesforce connected OpenShell to Slack so people can see what an agent is doing and approve more access. SAP is building it into Joule Studio. ServiceNow, Microsoft, CrowdStrike, Cisco, Palo Alto Networks and Palantir are involved, alongside Citi and JPMorganChase on the banking side.
The list gets more telling from there. Hitachi Energy, NextEra Energy, Schneider Electric, Siemens Energy, EPRI and Quanta Services are working with the platform, along with the robotics company Figure. Those are firms running power grids, utilities and physical equipment, the kind of system where an agent's mistake carries real-world consequences, not a wrong spreadsheet cell.
Nexairi Dispatch
Get the next AI move before it turns into a workflow problem.
Join the free newsletter for concise AI news, practical checklists, and the decisions practitioners need to make next.
Free. No spam. You will also get the Nexairi Dispatch.
Isn't giving away OpenShell for free a strange business move?
Not if the goal is bigger than one product. OpenShell is open source and Nvidia says it can extend to Arm and Intel chips, not only Nvidia's own hardware.
That looks generous at first. It reads differently once you notice what Nvidia gains either way. If OpenShell becomes the way agent security works across the industry, Nvidia doesn't need every chip under it to carry an Nvidia label. It gets to help set the standard the rest of the industry builds around, and Sentry, the part running on Nvidia's own hardware, is where the paid business sits.
What this changes for a customer already using Nvidia
A company already running Nvidia GPUs, Nvidia networking and Nvidia CPUs doesn't face a hard decision when Nvidia offers agent security next. It's a natural add, especially if the security system works better because it uses a BlueField chip sitting outside the agent's own environment. That is a different kind of business than selling the fastest chip on the market. The GPU gets Nvidia into a data center. Each additional layer built on top gives that customer one more reason to stay rather than switch to a competitor.
Whether the Open Agent Safety Platform brings in $1 billion or $10 billion in direct revenue is not the number to watch yet, and nobody outside Nvidia knows that figure today. The pattern is the more useful signal. Nvidia keeps finding a problem the AI industry created and building the next layer underneath the fix.
Picture a bank that already runs Nvidia GPUs for model training and Nvidia networking to move data between them. When that bank's compliance team asks how it will stop an AI agent from touching an account it shouldn't, the easiest answer on the table is the vendor already inside the building. Switching to a rival's safety tool means introducing a new piece of hardware, a new support contract and a new set of engineers who have to learn it. Staying with Nvidia means one more line item on an invoice they already pay.
None of this makes Nvidia's tool worse at its actual job. Agent security is a real need, and a hardware watchdog that runs apart from the agent it watches is a sound design regardless of who sells it. The two things can both be true: the platform solves a genuine problem, and it happens to be built in a way that keeps the customer buying from one company for one more layer of the stack.
What should you check before trusting an agent-safety claim?
Ask whether the safety check runs apart from the agent it watches, or inside the same environment. A guard sharing a cell with the prisoner isn't much of a guard.
Nvidia built Sentry to avoid exactly that, running it on separate hardware so a compromised agent can't shut off the thing watching it. If your company is evaluating AI agents for anything that touches money, infrastructure or physical equipment, ask the vendor the same question: where does the safety check actually run, and who controls it. Then watch whether other chipmakers answer with their own version, or whether Nvidia's design becomes the one everyone builds to.
Sources
Related Articles on Nexairi
Jim Smart is the founder and editor in chief of Nexairi. A Business Intelligence Developer with experience building data systems for Verizon, U.S. Army operations, and enterprise finance teams, Jim spent years turning complex data into decisions that executives could act on — dashboards, forecasting models, and automation pipelines across telecom and government contracting. He founded Nexairi to apply that same clarity to AI: making emerging technology understandable and actionable for the operators, accountants, and business owners who need it most. Jim holds GenAI certifications from the University of South Florida Bellini College of AI and completed Springboard's Data Science Career Track.
