An AI agent that can use tools and a computer can also become powerful enough to interfere with software-level controls around it. Nvidia’s answer is to move part of the safety boundary somewhere the agent does not control: an independent infrastructure layer that can monitor and quarantine the workload.1, 2

IN BRIEF

Nvidia’s Open Agent Safety platform combines OpenShell runtime controls with a Sentry reference architecture that can use BlueField infrastructure to monitor and quarantine agents independently of the host CPU. Nvidia says this out-of-band layer can react in milliseconds. The broader idea is that an agent should not be able to modify or reason around its final containment mechanism.1, 2

What Nvidia is claiming. Quarantine response: Milliseconds — Nvidia-reported response target for boundary-breaking agents in the Sentry reference architecture.. OpenShell: Open source — Nvidia released the agent runtime as open source and says it can work beyond Nvidia compute.. Values and their context are also available as HTML below.
What Nvidia is claiming. Values and their context are also available as HTML below.1, 2
Three layers in Nvidia’s agent-safety design1, 2
LayerJobControl boundary
Agent applicationPlans and performs workProbabilistic software
OpenShell runtimeConstrains tools, network and environmentSoftware policy around the agent
Sentry / BlueField layerMonitors boundary violations and can quarantineOut-of-band infrastructure outside the host CPU

The safety control sits outside the model

Model alignment asks the agent to behave correctly. Runtime policy restricts what it can reach. Nvidia’s Sentry concept adds another boundary: independent monitoring that the host workload cannot simply rewrite when something goes wrong.2

What Nvidia is claiming

Milliseconds
Quarantine response1, 2

Nvidia-reported response target for boundary-breaking agents in the Sentry reference architecture.

Open source
OpenShell1

Nvidia released the agent runtime as open source and says it can work beyond Nvidia compute.

This solves a different problem from identity and verification

S&C’s Okta agent-identity analysis asks who the agent is and what it is allowed to do. Google PageBreak asks whether an agent’s finding can be proved. Sentry is about containment when an executing agent crosses a boundary.

A hardware watchdog does not make the agent safe by itself

The reference architecture still depends on correct policies, useful telemetry and integration with the systems the agent uses. A fast quarantine path can limit damage after a violation is detected. It does not prove that every unsafe action will be recognized in advance.2

The layered-control model

  • Identity establishes which agent is acting and who owns it.
  • Runtime policy limits the tools, network and environment available to the agent.
  • Independent monitoring watches for boundary violations outside the agent’s control.
  • Quarantine stops or isolates the workload when the defined boundary is crossed.

As agents gain more authority, safety may look less like one smarter model and more like traditional defense in depth. The notable part of Nvidia’s design is that the final veto can live somewhere the agent cannot negotiate with it.

Sources and methodology

Sources checked September 29, 2026. Dates and periods for individual figures are stated beside them.

  1. NVIDIA: Open Agent Safety platform ↗Accessed 2026-09-29
  2. NVIDIA Developer: Open Agent Safety reference architecture ↗Accessed 2026-09-29
Scope and assumptions

Millisecond quarantine and safety-effectiveness claims are Nvidia-reported for a newly introduced reference architecture.

Containment depends on policy and detection coverage; an independent watchdog does not guarantee every unsafe action will be recognized.

Continue reading

If an AI Agent Can Act Like an Employee, It Needs an Identity →

Google’s Security Agent Found 500+ XSS Bugs. The Trick Was Proving the Exploit →

Meta’s AI Can Send Emails and Make Purchases. What Should You Let It Touch? →