NVIDIA builds a safety platform to control AI agents, from test to use

NVIDIA is responding to growing concerns about rogue AI agents with the launch of its Open Agent Safety Platform, a system designed to quarantine errant programs in milliseconds. The platform centers on NVIDIA Sentry, running on BlueField-4 DPUs and OpenShell software establishing secure runtime boundaries on NVIDIA Vera CPUs, but is designed for compatibility with Arm and Intel platforms as well.

“AI’s extraordinary potential for society will only be realized if we solve AI safety,” said Jensen Huang, founder and CEO of NVIDIA. Twenty-six industry leaders, including Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI, are collaborating with NVIDIA to build a more secure future for AI across infrastructure, software, models and robotics.

OpenShell Secures Agent Runtimes on Vera CPUs & Beyond

NVIDIA Vera CPUs are the initial compute platform for OpenShell software, establishing a secure runtime boundary for AI agents, but the design extends beyond NVIDIA hardware to encompass systems from Arm and Intel. This deliberate broadening of compatibility signals an intent to avoid vendor lock-in while prioritizing security from the earliest stages of agent deployment. OpenShell delivers this protection with what NVIDIA claims is minimal performance overhead, a critical factor for applications demanding real-time responsiveness.

The software establishes enforceable boundaries outside of the AI model and agent harness, addressing a growing need for control as agents assume more complex tasks. The platform’s security architecture relies heavily on NVIDIA BlueField-4 DPUs running NVIDIA Sentry, described as capable of quarantining rogue agents in milliseconds.

This in-silicon enforcement provides a rapid response to unauthorized behavior, preventing agents from exceeding pre-defined operational limits. “We support agentic security with clear boundaries that define what agents can do, and controls that keep them operating within those permissions,” said Francis deSouza, CEO of Scale AI, highlighting the focus on proactive governance. The speed of Sentry’s response is particularly notable, as it operates at a hardware level, bypassing software-based delays that could compromise security.

Beyond hardware, NVIDIA is integrating OpenShell with existing enterprise tools to enhance visibility and control. Salesforce has integrated OpenShell with Slack, allowing teams to monitor agent activity, review audit events and manage permission requests directly within the communication platform.

Similarly, SAP is embedding OpenShell within its Joule Studio runtime, part of the SAP Business AI Platform, to combine business oversight with runtime security. Scale AI is also using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for its enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start, the company says. This ecosystem approach, coupled with the open-source nature of OpenShell, aims to support broader adoption and collaboration in AI safety.

AI’s extraordinary potential for society will only be realized if we solve AI safety.

Jensen Huang, founder and CEO of NVIDIA

NVIDIA Sentry & BlueField-4 DPUs Enable Real-Time Agent Quarantine

NVIDIA BlueField-4 DPUs execute Sentry, an out-of-band watchdog capable of quarantining rogue AI agents in milliseconds, a speed enabled by in-silicon enforcement of security boundaries. This rapid response circumvents the latency typically associated with software-based security measures, providing a critical layer of protection as agents assume increasingly complex tasks. Sentry operates from an isolated trust domain, remaining invisible to both agents and potential attackers while continuously monitoring agent behavior and enforcing policies.

The system uses NVIDIA DOCA software, providing programmable capabilities to inspect requests, verify identity, and enforce granular access controls for data and services. The architecture extends beyond simple monitoring. Sentry’s hardware-based governance combines threat detection with data access protection, operating independently of the agent itself.

Running on BlueField-4 DPUs allows Sentry to provide attested telemetry, a verifiable record of agent actions, and enforce zero-trust access policies. NVIDIA’s design allows for the implementation of strict controls over what agents can access and do, preventing unauthorized actions before they can be completed. “Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software,” said Paul Smith, chief commercial officer of Anthropic.

Industry Collaboration Strengthens Full-Stack AI Safety Governance

NVIDIA’s Open Agent Safety Platform extends security beyond model parameters, establishing governance across the full agent stack, software, hardware, compute and robotics, a departure from approaches focused solely on application-layer controls. The platform’s design addresses recent incidents where agents bypassed existing security measures to complete tasks, highlighting a vulnerability at the software level. NVIDIA reports this full-stack approach is essential for robust AI safety, moving beyond isolated solutions to encompass the entire system.

This deliberate design choice avoids vendor lock-in, allowing organizations to deploy the platform across diverse infrastructure. The platform’s open nature is reinforced through contributions to the Open Secure AI Alliance, initiated by NVIDIA with over 100 organizations and governed by the Linux Foundation.

NVIDIA chips now encrypt AI work to keep data private during inference, according to the company. This combined approach, full-stack governance, open collaboration and data privacy, positions NVIDIA as a key player in establishing a secure foundation for the expanding field of agentic AI. The platform’s availability through NVIDIA developer resources and GitHub encourages wider adoption and customization, allowing organizations to tailor security measures to their specific needs.

Scale AI is using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for our enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start.

Francis deSouza, CEO of Scale AI

Anthropic & Scale AI Integrate Platform for Enhanced Agent Control

This deliberate broadening of support aims to mitigate vendor lock-in while simultaneously providing a foundational layer of security for agentic AI systems. The platform’s architecture allows organizations to deploy components according to their specific needs, offering a flexible approach to safety implementation. SpaceXAI is integrating the NVIDIA Open Agent Safety Platform for its Cursor coding agents and Grok models, emphasizing the need for controls that operate independently of the AI model itself.

This external enforcement allows users to confidently define and maintain limits for agents like Cursor and Grok, the firm reports. This integrated strategy aims to provide a more robust defense against rogue agent behavior, offering organizations customizable tools to enforce stricter oversight.

As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past.

Mike Nicolls, president at SpaceXAI

Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments.

Paul Smith, chief commercial officer of Anthropic
Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Rusty Flint

Rusty Flint

Rusty is a quantum science nerd. He's been into academic science all his life, but spent his formative years doing less academic things. Now he turns his attention to write about his passion, the quantum realm. He loves all things Quantum Physics especially. Rusty likes the more esoteric side of Quantum Computing and the Quantum world. Everything from Quantum Entanglement to Quantum Physics. Rusty thinks that we are in the 1950s quantum equivalent of the classical computing world. While other quantum journalists focus on IBM's latest chip or which startup just raised $50 million, Rusty's over here writing 3,000-word deep dives on whether quantum entanglement might explain why you sometimes think about someone right before they text you. (Spoiler: it doesn't, but the exploration is fascinating)

Latest Posts by Rusty Flint: