Nvidia Takes AI Agent Security to the Chip With OpenShell, Sentry

TechnologyDigital
29 Sep 2026 • 6:00 PM MYT
The Storm Media
The Storm Media

Bringing Taiwan's voice to the world.

Image from: Nvidia Takes AI Agent Security to the Chip With OpenShell, Sentry
Nvidia founder and CEO Jensen Huang. Nvidia unveiled its Open Agent Safety Platform on September 28, extending AI agent security controls into CPUs, DPUs and robotics. (Photo: Liu Wei-hong)

Nvidia unveiled a new security platform on September 28, 2026, that pushes safety controls for artificial intelligence agents out of software applications and down into the chips that run them, aiming to stop autonomous systems the moment they overstep their bounds.

The Open Agent Safety Platform combines an open-source execution environment called OpenShell with a hardware-based monitoring system called Sentry, extending oversight of AI agents beyond the model and application layer into central processing units, data processing units and even physical robots. When an agent crosses a defined safety boundary, the system can isolate and halt it within milliseconds, Nvidia said.

The launch reflects a shift in what AI agents are now being asked to do. Rather than simply answering questions, agents are increasingly given access to company databases, the ability to call application programming interfaces, permission to modify code, and in some cases control over physical machines such as robots. Nvidia said recent security incidents have shown that agents pursuing an assigned task can sidestep the safety controls built into the applications around them, meaning restrictions on what a model will say, or limits set within an agent's own framework, are not always enough to contain a system that runs autonomously for extended periods.

OpenShell Draws Hard Lines Around What Agents Can Touch

OpenShell is designed to track everything an agent does and restrict its access to data, tools and systems according to a company's own policies. It works with both open and closed AI models, and Nvidia built it so that enforcement sits outside the model and the agent framework, rather than depending on the agent to police itself.

Nvidia said OpenShell runs with low overhead when paired with its Vera CPU, a processor designed for agentic AI workloads. But the software itself is open source, meaning it can also run on Arm and Intel-based systems. OpenShell is available now through Nvidia's developer resources and on GitHub.

Sentry Polices Agents From Outside Their Own Software

The platform's second layer, Sentry, runs on Nvidia's BlueField-4 data processing unit and monitors agent behavior out of band, meaning it operates from a trust zone the agent itself cannot reach or interfere with, unlike security tools that share the same software environment as the agent they are watching.

Built on Nvidia's DOCA software, Sentry inspects an agent's requests and responses, verifies its identity, generates verified telemetry, and enforces granular zero-trust access rules across data, tools, application programming interfaces and services. The result, Nvidia said, is a system that tracks not just what a model says, but whose identity an agent is acting under, which tools it calls, what data it touches, and whether it can be stopped the instant it oversteps.

Salesforce, SAP And Anthropic Are Already Building It In

Nvidia said more than 100 organizations are already working with technology tied to the Open Agent Safety Platform. Salesforce has integrated OpenShell with Slack, letting teams monitor agent activity and audit events directly inside Slack and approve or deny requests from agents for additional permissions.

SAP has embedded OpenShell into the Joule Studio execution environment within its Business AI Platform. Anthropic has combined the isolation architecture behind its Claude Managed Agents with OpenShell and BlueField, adding a software-and-hardware governance layer on top of its own agent workspaces.

In finance, Citigroup and JPMorgan Chase are taking part in agent-safety collaborations aimed at the sector's especially sensitive data. Robotics firms Figure, Gecko Robotics and Skild AI are using OpenShell to extend the same safety controls to autonomous systems that take physical actions in the real world.

Nvidia and more than 120 other organizations have also formed the Open Secure AI Alliance, which will be governed by the Linux Foundation and is intended to promote information-sharing on agent safety through open research, shared tools and a program called the Shared AI Findings Exchange.

An Open Standard That Still Runs On Nvidia Silicon

By making OpenShell open source and compatible with Arm and Intel hardware, Nvidia is signaling that it does not want to confine the security architecture to its own processors, a strategy that could lower the barrier to enterprise adoption and give Nvidia outsized influence over how the industry eventually standardizes agent identity, telemetry and permissions.

Full hardware-layer protection, however, remains closely tied to Nvidia's own Vera CPU, BlueField-4 DPU and DOCA software. That makes the Open Agent Safety Platform more than a security product. It is also a vehicle for Nvidia, whose supply chain runs deep through Taiwan's chipmaking industry, to extend its reach across the data center, from the GPUs that train and run models to the chips that execute, monitor, govern and, when necessary, shut down the agents built on top of them.

For enterprises, the calculus around AI agents is shifting accordingly. The question is no longer only whether a model might generate an inappropriate answer, but what an agent is able to do, what data it can reach, and whether it can be stopped immediately if it goes off script. How well OpenShell and Sentry integrate with companies' existing identity management, security operations and compliance systems will help determine whether Nvidia succeeds in turning agent safety into a standard piece of AI infrastructure.

Original Article In Chinese


Social Media Links & Editor Tag - Penny

Social Media Links & Editor Tag - Penny


Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved