NVIDIA has split its new AI-agent safety stack across two enforcement points: OpenShell governs files, system calls, network access and credentials inside a sandbox, while Sentry runs on a separate BlueField-4 data processing unit to observe and quarantine agents outside the host CPU and GPU. The arrangement matters because a policy guard that shares the same execution environment as the agent can fail with that environment; an independently powered enforcement path does not share every failure mode.
Featured image: NVIDIA.
What NVIDIA announced
The company introduced the combined NVIDIA Open Agent Safety Platform on September 28. OpenShell itself is open source, and its public repository describes a policy model that checks every file access, system call and outbound network connection. Sentry is the hardware-isolated part: NVIDIA says it monitors agent behavior from BlueField-4 and can quarantine an agent that crosses a declared boundary in milliseconds.
Two boundaries, not one oversized sandbox
OpenShell puts each agent in an isolated sandbox and applies policy at the kernel level. A rule can constrain accessible paths, allowed system calls and network destinations. Credentials are not exposed directly to the agent; OpenShell injects them only into requests bound for approved endpoints. Its policy prover also evaluates proposed changes before they take effect, flagging expansions such as a newly reachable host, credential or API method for human review.

That software layer is useful, but it still sits close to the workload it controls. Sentry moves the second decision point onto a BlueField-4 DPU, which has its own processor and software domain. In NVIDIA’s architecture, the DPU can inspect the agent’s activity independently of the CPU or GPU running the agent. A compromised host therefore cannot be assumed to have final authority over its own safety monitor.
This is a familiar systems-security pattern: keep the reference monitor smaller and more isolated than the workload. What is new here is the packaging around autonomous agents. Rather than treating a model refusal as the control, the platform constrains the operating-system and network actions available after a model has decided what it wants to do.
What OpenShell 0.1.x actually exposes
The current OpenShell repository lists Linux and Apple-silicon macOS as supported host paths, with Windows through WSL 2 marked experimental. It requires Docker, Podman or host virtualization. A minimal installation creates a sandbox with two commands:
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo
For Kubernetes deployments, NVIDIA’s documentation adds an important condition: the cluster network interface must enforce NetworkPolicy. That caveat prevents a common configuration error in which policy objects exist but the data plane does not actually block traffic.
OpenShell also ships anonymous operational telemetry by default. NVIDIA says it excludes sandbox names, hostnames, file paths, prompts, credentials, provider names, model names and user content. Operators can disable collection with OPENSHELL_TELEMETRY_ENABLED=false on the gateway or server.telemetryEnabled=false in a Helm deployment.

The security claim is architectural, not yet a benchmark
NVIDIA’s launch describes quarantine in milliseconds, but it does not publish a common test workload, measured detection distribution or false-positive rate for that claim. The company also lists broad industry support, yet participation is not the same as a production deployment with independently reported incident data. Those gaps do not negate the isolation model; they define what still needs evidence.
A deployment review should therefore separate three questions. First, does the OpenShell policy cover every path by which the agent can affect the system? Second, does the underlying runtime and cluster networking enforce those rules rather than merely store them? Third, can Sentry still observe and cut off the relevant I/O path when the host is degraded or compromised?
TechCrunch’s launch report confirms the division of labor: OpenShell forms the software boundary, while Sentry monitors from a separate BlueField-4 processor. That external account also notes that OpenShell was announced earlier in 2026; the September release is the combined platform, not the first appearance of the sandbox runtime.
What to watch next
The important evidence will come from implementation details and failure reports: which system calls and network paths remain outside coverage, how policy updates behave under load, what Sentry can inspect without exposing sensitive payloads, and whether quarantine remains reliable when the host is intentionally hostile. For now, NVIDIA has made the boundary clear. Agent safety is being treated as an operating-system and I/O-control problem, with a second enforcement point that does not trust the machine running the agent.

