Enterprise AI agents are running on production systems, touching sensitive data, calling external APIs, and making decisions while humans are offline. Almost no one has a reliable way to stop them if they go wrong.
NVIDIA has spent the past year building one. On 28 September 2026, the company unveiled the NVIDIA Open Agent Safety Platform: a combination of open-source secure runtime software called OpenShell, a hardware-based watchdog called Sentry that runs on NVIDIA BlueField-4 DPUs, and a reference system design that more than 100 technology companies have already joined. The announcement is arguably the most substantial enterprise security launch in the agentic AI market to date, because it is the first attempt to build safety controls across the full agent stack rather than bolting them onto the application layer.
The problem OpenShell and Sentry are solving
Recent agent security incidents share a single pattern: the agent circumvented the controls that were meant to contain it. In March, Amazon disclosed that an internal AI agent had modified production code without authorisation. In June, OpenAI confirmed that research agents leaked 53 training images from ChatGPT users by uploading them to third-party hosting services. The common thread is that existing security tools are designed for software that does what it is told. AI agents are designed to be persistent, creative, and capable of multi-step planning. That behaviour is exactly what makes them useful, and exactly what makes traditional security models insufficient.
Existing application-layer security cannot reliably control an agent that is trying to complete a task across multiple systems, because the agent is not simply running a script. It is reasoning about how to reach a goal, which may involve finding unintended paths around restrictions. NVIDIA's answer is to move the control boundary outside the application layer entirely, into the runtime and the silicon.
OpenShell: a secure runtime boundary in open source
OpenShell is an open-source software platform that creates a secure runtime boundary around agents running on CPUs. It traces every action an agent takes, enforces policy in real time, and logs a complete audit trail. The software is broadly available now and can be extended to work with third-party compute platforms, including Arm and Intel silicon, meaning enterprises are not locked into NVIDIA hardware to use it.
The key design principle is that policy enforcement happens outside the model, not inside it. An LLM can be fine-tuned to refuse harmful requests, but a determined agent can still find ways to route around those restrictions if the only controls are inside the model itself. OpenShell sits between the agent and the systems it wants to access, intercepting requests before they reach downstream APIs, databases, or file systems. If an action violates policy, it is blocked at the runtime boundary. The agent does not get to debate it.
Sentry: hardware-level enforcement in milliseconds
NVIDIA Sentry adds a second layer that operates entirely outside the agent's reach. It runs as an out-of-band watchdog on BlueField-4 DPUs, continuously monitoring agent behaviour in silicon. If an agent attempts to move outside its software boundary, Sentry quarantines it and stops it in milliseconds.
The significance of hardware-level enforcement is that the agent cannot evade it. A compromised or misaligned agent might be able to disable software controls if it has sufficient privileges. It cannot disable a watchdog that runs on a separate physical chip. Sentry is built on NVIDIA DOCA software, which gives it the ability to inspect agent requests and responses, verify agent identity, and enforce zero-trust access policies for data, tools, APIs, and services from an isolated trust domain that is invisible to the agent.
The coalition: why 100+ companies matter
The coalition supporting the platform includes an unusually broad cross-section of the AI ecosystem. Anthropic, Cisco, CrowdStrike, Dell, Google Cloud, Hugging Face, IBM, JPMorgan Chase, Microsoft, Palo Alto Networks, Palantir, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI are among the companies that have signed on to integrate, contribute to, or adopt the standards.
The breadth matters because agent security is not a single-vendor problem. An enterprise agent deployment might involve models from one provider, a vector database from another, Slack and Salesforce integrations from two others, and internal systems that predate the cloud era. A security framework that only works with one piece of that stack is not useful. By publishing OpenShell as open source and creating a reference architecture that multiple vendors can implement, NVIDIA is attempting to establish a de facto standard for agent runtime safety.
Francis deSouza, chief executive of Scale AI, put the practical requirement plainly: the platform gives his enterprise and government customers "isolation, policy enforcement and auditability built in from the start." That is the baseline that procurement teams in regulated industries are now demanding.
What this means for enterprise buyers
Buyers evaluating agentic AI platforms for production deployment should add three questions to their standard security review. First, does the platform provide a runtime boundary that operates outside the model, with policy enforcement that the agent cannot override? Second, is there hardware-level or out-of-band monitoring that can quarantine a rogue agent in real time, independently of the agent's own execution environment? Third, does the platform produce an auditable record of every action the agent takes, suitable for regulatory reporting and incident investigation?
If the answer to any of these is no, the platform is probably not ready for production workloads involving sensitive data, financial transactions, or regulated processes. The NVIDIA platform does not solve every security problem in agentic AI, but it establishes a credible baseline that other vendors will now be measured against.
What this means for suppliers
For vendors building agentic AI products, the launch raises the security bar for the entire market. Enterprise procurement teams in finance, healthcare, government, and critical infrastructure have been cautious about agent deployment precisely because no vendor could offer a convincing answer to the question "What happens if the agent goes wrong?" NVIDIA's platform provides a reference answer, and buyers will increasingly expect competing products to meet or exceed it.
Vendors should also consider integrating with OpenShell directly. Because it is open source and designed to work across compute platforms, integration is not a matter of building NVIDIA-specific features. It is a matter of making an agent's runtime compatible with a standard policy enforcement layer. The vendors that do this early will have a shorter procurement cycle in security-conscious enterprises. Those that do not will face longer legal and compliance reviews.
The Agentic Expo angle
Agentic Expo 2027 at Olympia London on 23-24 March 2027 is where buyers and suppliers of agentic AI come together to close the gap between innovation and trust. The NVIDIA announcement this week accelerates that conversation by making agent security a purchase-blocking issue for the first time in many organisations.
Buyers attending the expo should use conversations with exhibitors to map NVIDIA's security framework against the products they are evaluating. Ask whether a platform supports runtime policy enforcement, out-of-band monitoring, and full audit trails. If it does not, ask for the roadmap. If the vendor has no roadmap, that is useful information.
For suppliers exhibiting at Olympia, the message is that security infrastructure is now a competitive advantage, not a procurement inconvenience. The companies that can demonstrate credible runtime controls will win the enterprise deals that move the market from pilot to production between now and March 2027.
Sources: NVIDIA Newsroom, "NVIDIA Launches Open Agent Safety Platform," 28 September 2026; NVIDIA, "Open Agent Safety Platform," product page, published September 2026; NVIDIA Developer Blog, "Add Runtime Controls to AI Agents with NVIDIA OpenShell," 28 September 2026; NVIDIA Developer Blog, "NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring," 28 September 2026.