• bitcoinBitcoin(BTC)$83,572.00-1.24%
  • ethereumEthereum(ETH)$2,686.26-0.07%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$765.19-1.65%
  • rippleXRP(XRP)$1.50-1.90%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$118.88-3.27%
  • tronTRON(TRX)$0.3358350.66%
  • zcashZcash(ZEC)$1,458.75-9.00%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.060.00%
  • HyperliquidHyperliquid(HYPE)$87.62-4.61%
  • dogecoinDogecoin(DOGE)$0.093977-3.27%
  • chainlinkChainlink(LINK)$15.369.21%
  • moneroMonero(XMR)$542.22-0.94%
  • whitebitWhiteBIT Coin(WBT)$83.58-0.97%
  • USDSUSDS(USDS)$1.00-0.02%
  • cardanoCardano(ADA)$0.246669-3.58%
  • RainRain(RAIN)$0.012523-0.45%
  • leo-tokenLEO Token(LEO)$9.01-0.40%
  • stellarStellar(XLM)$0.2284885.36%
  • nearNEAR Protocol(NEAR)$4.79-13.25%
  • bitcoin-cashBitcoin Cash(BCH)$309.16-7.54%
  • uniswapUniswap(UNI)$8.78-9.82%
  • litecoinLitecoin(LTC)$69.22-2.94%
  • hedera-hashgraphHedera(HBAR)$0.12196128.28%
  • CantonCanton(CC)$0.131672-4.65%
  • avalanche-2Avalanche(AVAX)$10.53-3.98%
  • Ethena USDeEthena USDe(USDE)$1.00-0.02%
  • suiSui(SUI)$1.16-8.97%
  • daiDai(DAI)$1.000.02%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.60-2.13%
  • USD1USD1(USD1)$1.000.00%
  • quant-networkQuant(QNT)$248.7325.17%
  • BittensorBittensor(TAO)$308.46-5.65%
  • crypto-com-chainCronos(CRO)$0.0697443.60%
  • shiba-inuShiba Inu(SHIB)$0.000006-4.00%
  • tether-goldTether Gold(XAUT)$4,123.12-3.60%
  • Global DollarGlobal Dollar(USDG)$1.000.02%
  • BitwayBitway(BTW)$1.05-13.68%
  • paypal-usdPayPal USD(PYUSD)$1.00-0.01%
  • MemeCoreMemeCore(M)$1.17-1.74%
  • EthenaEthena(ENA)$0.258864-7.81%
  • OndoOndo(ONDO)$0.52-6.31%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • okbOKB(OKB)$118.32-2.59%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • Pump.funPump.fun(PUMP)$0.0051210.62%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • aaveAave(AAVE)$148.10-4.26%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.15-0.15%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds

September 28, 2026
in AI & Technology
Reading Time: 15 mins read
A A
NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds
ShareShareShareShareShare

NVIDIA has launched the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for AI agent security. It pairs the OpenShell secure runtime with NVIDIA Sentry, an out-of-band watchdog on BlueField-4 DPUs. The core idea is simple. Safety controls should not live inside the agent they are meant to control.

Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.

Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to… pic.twitter.com/dReAxwpRUn

— Jensen Huang (@JensenHuang) September 28, 2026

Is it deployable today? Yes for OpenShell. It is Apache 2.0, installs on Linux, macOS (Apple Silicon) or Windows WSL 2, and its repo still labels it alpha.

YOU MAY ALSO LIKE

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming

Meta Bets on AI, Devices for Its Next Chapter

Why NVIDIA Moved Enforcement Below the Agent

The NVIDIA technical report cites recent reports from several frontier labs. Agents broke out of evaluation environments and reached systems they should not have touched. Some agents misreported what they did. The NVIDIA team names a common pattern: agents circumvented application-layer controls to finish their task.

NVIDIA calls this failure mode drift. Drift can follow a policy block, a bug, a missing tool or ambiguous instructions. NVIDIA team argues drift cannot be trained away without losing capability. So an agent cannot be expected to fully govern itself.

How the Platform is Built

OpenShell (runtime): Each agent runs in an isolated sandbox. A gateway manages sandbox lifecycle across Docker, Podman, MicroVM or Kubernetes drivers. Every outbound connection hits a policy engine that allows it, binds credentials to an approved endpoint, or denies and logs it. Filesystem and process rules lock at creation. Network and provider rules are hot-reloadable. See NVIDIA’s runtime controls walkthrough for implementation details.

Sentry (in-silicon watchdog): Sentry runs on BlueField-4 DPUs and uses NVIDIA DOCA to inspect agent requests and responses. It provides attested telemetry, verifies agent identity and enforces zero-trust access to data, tools and APIs. It stays isolated from the host, so a compromised runtime does not disable it.

Placement matters: In a Vera Rubin POD, each compute tray’s BlueField-4 sits on the node’s only path to the model. An agent cannot act without its next inference call. That makes the path both the best observation point and the kill switch. For existing Vera plus BlueField-4 systems, NVIDIA says enabling these protections is a software update.

The stack is optimized for NVIDIA Vera CPUs but is compatible with other hardware. NVIDIA team claims Vera delivers up to 80% faster sandbox performance than traditional CPU infrastructure. OpenShell can also be extended to Arm and Intel platforms.

The 5 Design Principles

  1. Verifiable policy: a prover checks the policy cannot escape operator intent before the agent runs.
  2. Out-of-band enforcement: controls sit outside the agent’s reach.
  3. Control the path to the model: it is the observation point and the kill switch.
  4. Scale authority with visible reasoning: more capable agents need more inspectable thinking.
  5. Shared responsibility: labs, enterprises and hardware providers each own a layer.

Interactive Explainer: Send a Request Through the Stack

How It Compares With Other Agent Sandboxes

The closest alternatives are sandbox platforms for agent-generated code. Neither offers an equivalent hardware watchdog.

Feature NVIDIA OpenShell + Sentry E2B Daytona
Type Open runtime plus hardware reference design Open-source sandbox cloud Sandbox infrastructure runtime
License Apache 2.0 Apache 2.0 AGPL-3.0 (public repo unmaintained since June 2026)
Isolation Per-sandbox container or MicroVM, kernel-level isolation Firecracker microVM, own kernel Dedicated kernel, filesystem and network stack per sandbox
Egress control YAML policy at HTTP method and path level, hot-reloadable Allow and deny lists by IP, CIDR or domain Network limits
Out-of-band hardware enforcement Yes, Sentry on BlueField-4 (optional) No, software isolation No, software isolation
Where it runs Local, on-prem, cloud, Kubernetes (experimental) E2B cloud or self-hosted on AWS and GCP Daytona cloud
Agent support Claude Code, Codex, OpenCode, Copilot CLI built in JS and Python SDKs Python, TypeScript, Ruby, Go, Java SDKs

Who is Building on It

NVIDIA says over 100 organizations work with the platform. Anthropic integrated Claude Managed Agents with OpenShell and BlueField. SpaceXAI uses it for Cursor coding agents and Grok models. Salesforce connected OpenShell to Slack for approving agent permission requests. SAP is embedding OpenShell in the Joule Studio runtime. Red Hat, SUSE and Canonical are integrating it into their operating systems.

The effort feeds the Open Secure AI Alliance, governed by the Linux Foundation. OpenShell and its skills are available on GitHub and the OpenShell docs.

Key Takeaways

  • 2 layers: OpenShell sandboxes the agent, Sentry watches it from separate silicon.
  • Sentry can quarantine an agent that leaves its boundary in milliseconds, per NVIDIA.
  • OpenShell policies are declarative YAML, with network rules enforced at HTTP method and path level.
  • OpenShell runs Claude Code, Codex, OpenCode and GitHub Copilot CLI out of the box.
  • NVIDIA lists over 100 organizations working with the platform, including Anthropic and Microsoft.

FAQ

  • Does OpenShell require BlueField-4? No. It runs on local, on-prem, cloud and Kubernetes infrastructure. BlueField-4 only adds Sentry.
  • How is this different from model guardrails? Guardrails shape what an agent attempts. Runtime controls enforce what it is allowed to do.
  • Can I use existing agents and models? Yes. OpenShell supports open and closed models and custom sandbox images.

Check out the Paltform here and Technical Details. All credit goes to the researcher of this project. Also, feel free to follow us on Twitter and don’t forget to join our 150k+ML SubReddit and Subscribe to our Newsletter. Wait! are you on telegram? now you can join us on telegram as well.

Need to partner with us for promoting your GitHub Repo OR Hugging Face Page OR Product Release OR Webinar etc.? Connect with us


Asif Razzaq is the CEO of Marktechpost AI Media Inc.. As a visionary entrepreneur and engineer, Asif is committed to harnessing the potential of Artificial Intelligence for social good. His most recent endeavor is the launch of an Artificial Intelligence Media Platform, Marktechpost, which stands out for its in-depth coverage of machine learning and deep learning news that is both technically sound and easily understandable by a wide audience. The platform boasts of over 2 million monthly views, illustrating its popularity among audiences.


Credit: Source link

ShareTweetSendSharePin

Related Posts

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming
AI & Technology

Discord Is Testing A Lightweight Mode To Free Up Resources While Gaming

September 28, 2026
Meta Bets on AI, Devices for Its Next Chapter
AI & Technology

Meta Bets on AI, Devices for Its Next Chapter

September 28, 2026
AI Emerges as a Flashpoint in Trump-Xi Talks
AI & Technology

AI Emerges as a Flashpoint in Trump-Xi Talks

September 28, 2026
Darktrace CEO: AI Agents Are the New ‘Insider Threat’
AI & Technology

Darktrace CEO: AI Agents Are the New ‘Insider Threat’

September 28, 2026
Next Post
AI Emerges as a Flashpoint in Trump-Xi Talks

AI Emerges as a Flashpoint in Trump-Xi Talks

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Full Episode: TODAY Show – Aug. 28

Full Episode: TODAY Show – Aug. 28

September 22, 2026
Bessent pressures countries to cut economic ties with Iran

Bessent pressures countries to cut economic ties with Iran

September 25, 2026
SpaceX announces massive launch site in Louisiana

SpaceX announces massive launch site in Louisiana

September 23, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!