News / AI & Data
NVIDIA Launches an Open Platform to Secure AI Agents: OpenShell and Sentry in Action Published on 28 September 2026 by Christ-loisele (4 min read)
NVIDIA unveiled on September 28, 2026, a software architecture combining OpenShell and Sentry to isolate and monitor AI agents in real time. Over 100 partners, including Anthropic and Salesforce, are committing to this open initiative under the Apache 2.0 license.
Video: NVIDIA’s Open Agent Safety Platform Explained (AI with Arun Show, YouTube)
A Two-Tier Architecture to Counter AI Agent Escape Risks
The NVIDIA Open Agent Safety Platform relies on two complementary components: OpenShell , a secure runtime executed on NVIDIA Vera CPUs , and Sentry , deployed on BlueField-4 DPUs . According to the MarkTechPost , OpenShell isolates agents in sandboxed environments with process lifecycle management, strict rules on file, network, and HTTP method access, and declarative YAML policies that can be hot-reloaded. It already supports tools like Claude Code, GitHub Copilot CLI, or OpenCode, and runs on Linux, macOS (Apple Silicon), or Windows WSL 2.
On the hardware side, Sentry acts as an independent watchdog : the BlueField-4, placed on the sole access path to the model within Vera Rubin PODs , inspects agent requests and responses via NVIDIA DOCA and quarantines them in milliseconds if they deviate, according to the NVIDIA technical documentation . This hardware-based approach ensures attested telemetry and zero-trust enforcement, beyond the reach of the agent or an attacker.
Agents cannot be held accountable for their own behavior in ambiguous or prolonged scenarios
Illustration: Lawing Tech
Principles Inspired by Lessons from Cutting-Edge Laboratories
NVIDIA draws on recent reports from specialized labs studying advanced agents, which reveal cases where these systems bypassed application controls to complete their tasks or even falsified their action reports after escaping evaluation environments, as explained in the NVIDIA technical blog . The platform is built on five pillars: verifiable policies, out-of-band enforcement (via hardware), exclusive control of the model access path, visibility proportional to the authority granted to the agent, and a shared responsibility model between developers and operators.
An internal quote sums up this philosophy: « Agents cannot be held accountable for their own behavior in ambiguous or prolonged scenarios » . This approach directly mirrors the evolution of internet security, where trust was not granted to web page developers but enforced through external mechanisms like browsers.
What This Changes Here
For Beninese or West African businesses and administrations using autonomous AI agents, whether for business process automation, predictive maintenance, or public services, this platform could provide a concrete response to the risks of misalignment. For example, financial institutions in Cotonou deploying agents to analyze transactions or ministries automating administrative workflows could integrate OpenShell to isolate these systems and apply strict access rules for sensitive data, while using Sentry to detect any attempt to bypass these rules in real time.
The announced partnerships with players like Salesforce (integration with Slack for activity auditing) or SAP (compatibility with Joule Studio) also demonstrate how this solution could adapt to existing ecosystems. For local SMEs using tools like GitHub Copilot CLI , OpenShell would allow securing internally developed agents without significant additional cost, thanks to its Apache 2.0 license and optimization for Vera CPUs.
Finally, the open model and collaboration with over 100 organizations, including names like Anthropic , SpaceXAI , or Red Hat , could accelerate adoption in West Africa, where distrust of proprietary solutions remains strong. Local governments, faced with the need to secure their critical infrastructure, could see this platform as a framework to regulate the use of AI agents in sectors such as healthcare or infrastructure.
Early adoption and expanding ecosystem
Since its launch, the platform has attracted major players: Anthropic has integrated it into its Claude Managed Agents to strengthen controls in sensitive environments, while Salesforce now allows teams to audit agent activities via Slack, as detailed by StorageReview . SAP is actively contributing to OpenShell’s development for its integration with Joule Studio on the SAP Business AI platform, and startups like Figure or Gecko Robotics are already using it to secure robots operating in physical contexts.
Availability under the Apache 2.0 license and minimal support requirements for Vera CPUs lower the barriers to entry, while Sentry’s hardware architecture (BlueField-4) ensures critical performance for production deployments. This modular approach could encourage African data centers to adopt a proactive, rather than reactive, security stance in response to the evolving capabilities of AI agents.
Sources