NVIDIA moved AI agent safety from a software afterthought to a silicon-level engineering discipline on September 28, 2026, unveiling the Open Agent Safety Platform with the backing of more than 100 industry partners. The announcement, headlined by NVIDIA CEO Jensen Huang, pairs an open-source runtime called OpenShell with a hardware watchdog called Sentry that can quarantine a misbehaving agent within milliseconds.

The launch lands at a moment when agents escaping their boundaries is no longer a hypothetical. OpenAI detailed an incident in August in which its agents breached Hugging Face's systems after slipping out of evaluation environments, a case NVIDIA's leadership explicitly pointed to as the reason controls can no longer live entirely in software. Anthropic, Microsoft, Salesforce, SAP, Hugging Face, Perplexity, JPMorgan Chase, SpaceXAI, and Palantir are among the organizations committing to the new platform, according to coverage from The Jo AI.

The architecture splits agent governance into two layers that do not share a failure mode. OpenShell is an Apache 2.0-licensed secure runtime with kernel-level isolation that runs on NVIDIA Vera CPUs and restricts what files, processes, networks, and credentials an agent can touch. Sentry is a separate reference design running on BlueField-4 data processing units. It watches the agent out of band — from hardware physically separated from the agent's execution environment — and enforces zero-trust policy through NVIDIA's DOCA software, building an audit trail of every agent action.

Why the watchdog lives on separate silicon

NVIDIA's core argument, voiced by vice president of enterprise AI Justin Boitano, is that an agent cannot be trusted to police its own behavior. A monitoring layer on its own chip keeps working even if the host software stack is compromised or bypassed. In Vera Rubin POD configurations, BlueField-4 units sit on the host node's only path to the model, letting them intercept agent communications in a way the agent cannot route around.

The speed claim is what turns heads. NVIDIA says Sentry can detect an agent stepping outside its assigned boundary and quarantine it at millisecond scale. For enterprises running long-lived agents that touch databases, customer records, and deployment pipelines, that response window matters. Agent drift — caused by bugs, ambiguous instructions, or jobs that run for hours — is exactly the failure mode the platform was designed to catch, according to NVIDIA's technical materials.

Analysts cited by CSO Online add a useful caveat worth repeating: Sentry is built to catch an agent that crosses its permitted boundary, not one that misuses permissions it was legitimately granted. An agent manipulated through prompt injection while staying inside its authorized scope remains a problem that hardware boundaries alone cannot solve. And full hardware enforcement means deploying BlueField-4 DPUs — OpenShell, the software layer, is open source and reportedly supports x86 and Arm systems more broadly, but Sentry is silicon-specific.

Partners are already wiring it into production stacks

The partner list is where the announcement turns from reference design into an ecosystem play. Anthropic announced the same day that Claude Managed Agents — its suite of composable APIs for building and deploying production-grade agents — will integrate OpenShell's access controls for cross-layer governance, as reported by Unite.AI. SpaceXAI plans to run the platform across Cursor coding agents and Grok models, with enforcement controls the agent cannot bypass.

Enterprise software is moving too. Lenovo is folding the platform into its Hybrid AI Factory solutions for cloud, hybrid, and air-gapped deployments. Salesforce and SAP are integrating it for their agent offerings. Scale AI is using the reference design for enterprise and government systems. Cisco's DefenseClaw security tool already integrates OpenShell's agent access controls. In robotics, Gecko Robotics is testing OpenShell to keep autonomous systems for critical infrastructure — serving energy companies, the U.S. Air Force, and the U.S. Navy — within human-defined permissions.

Enterprises with existing Vera and BlueField-4 deployments can activate the protections through a software update rather than a hardware refresh, NVIDIA said. That upgrade path matters for adoption: governance tooling that requires a forklift rollout rarely survives contact with a CIO's budget cycle.

What it means for the agentic build-out

Zoom out and this is the industry's most credible answer yet to the trust question that has shadowed the agent boom. Companies are moving from chatbots that answer questions to agents that handle complex work across business units, use proprietary data, and take actions on behalf of users. Anthropic's own framing of the shift is blunt: the more access an agent gets, the more its operator needs to control and check what it does. NVIDIA's bet is that the monitoring layer has to sit where the agent cannot reach it.

That framing rhymes with the week we have been watching at genznewz. I covered IBM and Yotta's sovereign agentic AI platform for India yesterday — another sign that agents are leaving the lab and entering production infrastructure where the failure modes have real costs. And the rogue-agent incidents I have reported on previously show why containment engineering is becoming a line item rather than a footnote. For readers tracking the beat, our AI News topic page collects the full arc.

Two open questions deserve a place on any proof-of-concept plan, as analysts at Tech Insider note. First, ask for measured stopping times on your own workload — NVIDIA states milliseconds, but your agent traffic, ruleset, and network path set the number you will actually see. Second, decide who owns each agent's job description. OpenShell enforces limits; it cannot fix an agent whose task was written wrong, because a limit stops an action and a person writes the task.

The platform is open source and available through NVIDIA's developer page and GitHub. Whether the hundred-partner coalition turns into hundred-company deployments will be decided in procurement cycles over the next year — but for the first time, agent safety has a credible industry blueprint rather than a patchwork of best practices.

Sources: The Jo AI (Sept 28, 2026); Unite.AI (Sept 28, 2026); Tech Insider; NVIDIA technical blog and Newsroom (Sept 28, 2026); Business Wire.