Independent , Honest and Dignified Journalism

Nvidia Launches Open Agent Safety Platform as AI Security Concerns Grow

OpenShell and Sentry are designed to place enforceable controls around autonomous AI systems as businesses expand their use of agentic technology.

SAN FRANCISCO, Sept 29: Nvidia has introduced a new security platform aimed at giving organisations greater control over artificial intelligence agents as businesses increasingly deploy systems capable of performing tasks with limited human intervention.

The company announced the Nvidia Open Agent Safety Platform on September 28, describing it as an open software platform and reference system designed to strengthen security from the testing stage through deployment. The initiative brings together software controls, computing infrastructure and hardware-based monitoring to establish boundaries around AI agents.

The move comes as technology companies and enterprises experiment with AI systems that can browse websites, access databases, write and execute code, retrieve information and interact with external services. Unlike conventional chatbots, these systems can carry out sequences of actions after receiving a goal, increasing both their usefulness and the potential consequences of an error or unauthorised action.

Nvidia’s platform is built around two main components: OpenShell, an open-source runtime designed to establish limits on what an AI agent can access and do, and Sentry, a hardware based monitoring system intended to independently watch agent activity.

OpenShell provides a security boundary around agents while they perform tasks. According to Nvidia, the software can trace agent actions and enforce policies during execution. The company said the technology is intended to provide a layer of control outside the AI model itself, allowing organisations to determine which resources, tools, applications and services an agent can use.

The distinction is important because AI agents are increasingly being given access to systems that contain sensitive information or perform consequential operations. A conventional model can generate an incorrect answer, but an autonomous agent may be able to act on an incorrect instruction or unexpected interpretation.

Nvidia said OpenShell can be extended to work with computing platforms from other manufacturers, including Arm and Intel. That could allow organisations to use the software boundary without relying exclusively on Nvidia processors.

The second part of the system, Sentry, takes a different approach. Nvidia described it as an out-of-band watchdog running on its BlueField-4 data processing units. The system is designed to monitor agent activity independently of the software environment in which the agent operates.

According to Nvidia, Sentry can identify an agent attempting to move outside its permitted boundaries and quarantine or stop it in milliseconds. The company says the hardware-based arrangement creates an independent security layer that is separate from the AI agent itself.

Sentry uses Nvidia’s DOCA software to inspect requests and responses, verify agent identity, provide telemetry and enforce access policies involving data, tools, application programming interfaces and services. The company said the system is designed around a zero-trust approach, in which permissions are restricted rather than assuming that an agent should automatically have broad access.

The announcement also highlights how AI security is moving beyond conventional model testing. As autonomous systems become more capable, developers are increasingly concerned not only with what a model generates but also with what it can do after receiving access to external tools.

Nvidia said more than 100 organisations are working with technologies associated with the Open Agent Safety Platform. The participants listed by the company include AI developers, cybersecurity firms, cloud companies, enterprise software providers and technology manufacturers. They include Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI and ServiceNow.

The platform also has implications for physical AI and robotics. Nvidia said its approach covers not just software agents but the hardware, computing systems and robotic platforms used to execute actions in the physical world.

That broader scope reflects the changing nature of AI deployment. Companies are increasingly exploring systems that can make decisions across multiple stages of a process rather than simply responding to individual prompts. Such systems may interact with enterprise applications, manipulate digital files or eventually control machines and other equipment.

Nvidia’s announcement comes amid heightened attention to incidents involving autonomous AI systems. Recent reports have described AI agents accessing websites and attempting actions beyond their intended tasks, adding pressure on developers to establish stronger technical safeguards.

The company has presented its approach as an engineering solution rather than relying solely on user instructions or organisational policies. The basic idea is to place controls around an AI system that remain active even when the underlying model is making decisions autonomously.

The development also reflects a broader shift in enterprise cybersecurity. Traditional security systems have largely been designed around human users, applications and known network activity. AI agents introduce another category of digital actor that can make decisions, call tools and continue working through multiple steps.

For businesses, this creates questions about identity, permissions and accountability. Organisations need to know which agent is acting, what it has been authorised to access and whether its actions remain within the original task.

Nvidia’s platform attempts to address these issues by combining software-level restrictions with independent hardware enforcement. OpenShell provides the runtime boundary, while Sentry adds an additional monitoring layer outside the agent’s software environment.

The company said the platform is available through Nvidia’s developer resources and GitHub, allowing developers and organisations to examine and use the software components.

The announcement arrives at a time when AI developers are also facing growing pressure to demonstrate that increasingly capable systems can be deployed safely. Technology companies are testing autonomous agents for software development, customer service, cybersecurity, research and business operations.

As those applications expand, the question is shifting from whether AI can complete a task to how organisations can ensure that the system completes only the task it has been authorised to perform.

Nvidia’s latest platform is therefore aimed at a specific challenge emerging alongside the growth of agentic AI: maintaining a reliable boundary between an AI system’s capabilities and the permissions it is actually allowed to use.

The effectiveness of such safeguards will depend on how broadly they are adopted and how well they work against new forms of attacks and unexpected agent behaviour. Nvidia’s launch nevertheless signals increasing industry attention on security controls that operate continuously rather than only during the development or testing phase.

WhatsApp Channel