Skip to content
Rush Commerce
AI & Automation4 min read

Nvidia puts AI agent containment in the silicon

Nvidia's Open Agent Safety Platform pairs open-source OpenShell with a Sentry watchdog on BlueField-4 DPUs that kills out-of-bounds agents in milliseconds.

Three days ago Jensen Huang told Ezra Klein not to ship agents you cannot contain. Today Nvidia shipped the containment. The Open Agent Safety Platform, announced this morning, moves AI agent containment out of the prompt and into the runtime and the network card — an open-source sandbox layer plus a hardware watchdog that quarantines a misbehaving agent in milliseconds. The interesting part for a small shop is not the silicon. It is that the boundary is finally a thing you configure instead of a thing you ask a model to respect.

What actually happened

Per Nvidia's announcement, the platform has two halves.

OpenShell is open-source software that "provides a secure runtime boundary for controlling how autonomous AI agents execute tasks across open and closed models." It runs fleets of agents in isolated sandboxes with infrastructure-level controls — trace every action, enforce policy outside whatever guardrails the model itself carries. It is tuned for Nvidia's Vera CPUs but extensible to Arm and Intel platforms, and it ships through Nvidia's developer resources and GitHub.

Sentry is the part that has no software equivalent. SiliconANGLE describes it as an out-of-band watchdog running on BlueField-4 DPUs — the network chip, not the host. It combines threat detection, hardware-based governance, and data-access protection. If an agent tries to cross its software boundary, Sentry quarantines and stops it in milliseconds. Out-of-band matters: a watchdog on the host can be talked out of watching. One on the NIC cannot.

More than 100 organizations signed on, including Anthropic, Cisco, CrowdStrike, Dell, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI. Huang's framing: "Safety and security require full-stack engineering."

Why agent containment matters for your business

You will not buy a BlueField-4, and that is fine. The hardware half of this is for people running agent fleets in their own racks. The pattern is what transfers: a control plane that sits outside the agent and can stop it, with no cooperation from the model required.

Prompt-level guardrails are a request, not a boundary. We have watched a well-behaved agent walk past its instructions the moment a tool returned unexpected output. The containment that held was a container with no credentials and no egress — not a paragraph in a system prompt.

Your version of this is boring and cheap. Scoped API tokens per agent, not one master key. An egress allowlist so the agent can reach your database and nothing else. A hard cap on tool calls per task. A kill switch you have actually tested. That is 90% of Sentry's job for the price of an afternoon.

OpenShell being open source is the part to watch. If the sandbox and policy format land in the open, your platform vendor can adopt them and you inherit the controls without buying Nvidia hardware. That is worth more to a ten-person shop than any of the announcement's silicon.

"Milliseconds" is a detection claim, not a damage claim. An agent that issues one destructive DELETE does the harm inside that window. Containment limits blast radius; it does not replace backups, dry-run modes, or requiring a human to confirm the irreversible step.

Key takeaways

  • Nvidia announced the Open Agent Safety Platform on September 28: OpenShell (open-source agent runtime sandbox) plus Sentry (hardware watchdog)
  • OpenShell enforces policy and traces agent actions outside the model's own guardrails; tuned for Nvidia Vera CPUs, extensible to Arm and Intel
  • Sentry runs out-of-band on BlueField-4 DPUs and quarantines agents that cross their software boundary in milliseconds
  • Over 100 partners signed on, including Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, Hugging Face, and JPMorganChase
  • The transferable idea is an enforcement layer outside the agent — scoped tokens, egress allowlists, tool-call caps, a tested kill switch
  • Fast detection shrinks blast radius; it does not undo a destructive action already issued

Could you stop one of your agents right now? Every agent we ship runs with its own scoped credentials, an egress allowlist, a tool-call ceiling, and a kill switch we test before launch — because the containment layer is the deliverable, not a hardening pass afterward. See how we scope agent permissions, or bring us the agent you are nervous about.

Sources: NVIDIA Newsroom, SiliconANGLE.

  • #ai-agents
  • #agent-safety
  • #nvidia
  • #sandboxing
  • #open-source
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.