NVIDIA Launches Open Agent Safety Platform: OpenShell, Sentry on BlueField-4, and In-Silicon Guardrails with 100+ Partners
NVIDIA has introduced the Open Agent Safety Platform alongside more than 100 cybersecurity and cloud partners. The full-stack reference design pairs OpenShell kernel-level software sandboxing with Sentry, an out-of-band hardware watchdog operating on BlueField-4 DPUs via DOCA. Because BlueField-4 and DOCA sit outside the host CPU and GPU memory space, enterprise security teams can monitor, isolate, and quarantine autonomous agents in milliseconds without risking software-layer tampering.
The Software Guardrail Problem in Autonomous AI
Enterprises deploying autonomous AI agents face a structural vulnerability: traditional software guardrails run inside the same host operating system and memory space as the models they monitor. When an agent receives malicious instructions via indirect prompt injection or executes unauthorized shell commands, it can disable in-process monitoring daemons, alter system audit logs, or manipulate its own authorization tokens.
To solve this vulnerability, NVIDIA introduced the Open Agent Safety Platform alongside more than 100 global cybersecurity, cloud, and consulting partners. The platform enforces physical and cryptographic separation: OpenShell handles host-level sandboxing, while Sentry runs as an out-of-band watchdog on NVIDIA BlueField-4 DPUs using the NVIDIA DOCA software framework.
Because the BlueField-4 DPU and DOCA runtime operate on independent silicon outside host CPU and GPU memory, compromised agents cannot access, tamper with, or blind the monitoring subsystem.
Architectural Anatomy: The Three Core Layers
The platform divides agent governance into three interlocking layers:
+---------------------------------------+
| Enterprise Security Ops |
| CrowdStrike / Palo Alto / Datadog |
+-------------------+-------------------+
|
(Telemetry & Policies)
|
+----------------------------------------v----------------------------------------+
| NVIDIA Vera Rubin Node / Host OS |
| |
| +--------------------------------------------------------------------------+ |
| | NVIDIA OpenShell (Isolated Software Runtime Sandbox) | |
| | | |
| | +---------------------+ Policy Interceptor +--------------------+ | |
| | | Autonomous Agent | ---------------------> | Kernel Sandbox | | |
| | | (Tools, Shell, DB) | | (Namespaces, eBPF)| | |
| | +---------------------+ +---------+----------+ | |
| +------------------------------------------------------------|-------------+ |
+---------------------------------------------------------------|----------------+
| (800 Gb/s PCIe / Network Path)
+---------------------------------------------------------------v----------------+
| NVIDIA BlueField-4 DPU (Hardware Isolated Silicon - Outside Host Reach) |
| |
| +--------------------------------------------------------------------------+ |
| | NVIDIA Sentry (Out-of-Band Hardware Watchdog) | |
| | | |
| | +----------------------+ In-Silicon Telemetry +------------------+ | |
| | | DOCA Packet & Token | -----------------------> | Millisecond | | |
| | | Deep Inspection | | Quarantine Unit | | |
| | +----------------------+ +------------------+ | |
| +--------------------------------------------------------------------------+ |
+--------------------------------------------------------------------------------+
Layer 1: NVIDIA OpenShell (Open-Source Runtime Sandbox)
NVIDIA OpenShell is the host-side execution environment. It abstracts agent instructions into verifiable security policies before any system call touches physical infrastructure.
Key operational characteristics of OpenShell:
- Kernel-Level Sandboxing: Uses Linux namespaces, cgroups v2, and custom eBPF filters to confine agent processes.
- Dynamic Credential brokering: Agents never receive persistent cloud API keys or database passwords. OpenShell provisions ephemeral, cryptographically signed tokens valid only for specific endpoints and single-digit minute windows.
- Deterministic Egress Enforcement: Outbound network requests are filtered against an enterprise allowlist. Attempts to ping unauthorized external IP addresses or establish reverse TCP tunnels are blocked at the socket layer.
- Cross-Platform Compatibility: OpenShell runs natively on NVIDIA Vera CPUs and extends support to third-party Arm and x86-64 server architectures.
Layer 2: NVIDIA Sentry on BlueField-4 DPUs (Hardware Watchdog)
While OpenShell secures the local host, NVIDIA Sentry provides independent verification. Sentry runs directly on the ARM compute cores embedded within the NVIDIA BlueField-4 DPU.
In modern AI cluster architectures (such as the NVIDIA Vera Rubin NVL72 and POD deployments), the BlueField-4 DPU sits directly on the physical I/O path connecting server nodes to the high-speed network and model storage:
| Metric / Parameter | BlueField-3 (Predecessor) | BlueField-4 (Open Agent Platform) |
|---|---|---|
| Network Throughput | 400 Gb/s InfiniBand / Ethernet | 800 Gb/s InfiniBand / Ethernet |
| DPU Processing Core | 16x ARM Neoverse V2 Cores | 32x High-Performance Neoverse Cores |
| Security Telemetry Bandwidth | 80 GB/s internal bus | 256 GB/s coherent interconnect |
| Quarantine Latency | 45 milliseconds | < 3 milliseconds (In-Silicon) |
| Memory Isolation | Physical PCIe isolation | Dual-Root hardware enclave & secure boot |
Why Physical Separation Matters
If an attacker compromises an autonomous agent through an automated jailbreak, the agent may attempt to terminate security agents with commands like pkill crowdstrike or modify /etc/hosts.
Because Sentry runs on the BlueField-4 DPU:
- The host operating system possesses zero memory-mapped access to the DPU operating environment.
- Even if an attacker achieves root access on the host Linux kernel, the BlueField-4 DPU continues executing Sentry unhindered.
- Upon detecting malicious policy violations (such as attempts to exfiltrate database records or scrape sensitive network subnets), Sentry drops network packets in hardware and severs the agent communication channel within 3 milliseconds.
Layer 3: NVIDIA DOCA Framework (Data Center on a Chip)
NVIDIA Sentry is compiled and orchestrated using NVIDIA DOCA, the unified software architecture for BlueField DPUs.
DOCA exposes programmable pipelines that inspect both network packets and model inference streams in flight:
- Token Stream Inspection: DOCA inspects model requests and completions as they traverse network buffers, identifying leaked social security numbers, API keys, or prompt-injection attack signatures.
- Hardware-Attested Telemetry: Security events are signed using the BlueField-4 embedded Root of Trust (RoT). Security Information and Event Management (SIEM) platforms receive cryptographically tamper-proof audit trails.
- Microsegmentation: DOCA enforces zero-trust network access (ZTNA) rules, isolating individual agent instances so a compromised financial agent cannot communicate with an HR repository on the same physical rack.
100+ Partner Ecosystem Integration
NVIDIA designed the Open Agent Safety Platform as an open specification rather than a closed proprietary silo. The initiative launches with over 100 global cybersecurity, software, and systems integration partners:
- Endpoint & Threat Intelligence Leaders: CrowdStrike (Falcon platform sync), Palo Alto Networks (Prisma Cloud runtime governance), Fortinet, Trend Micro, and Cisco.
- Observability & Telemetry Providers: Datadog, Dynatrace, Splunk, and Elastic.
- Enterprise System Integrators: IBM Consulting, Accenture, Deloitte, Wipro, and Slalom.
- Cloud Service Providers: Integration roadmaps announced across AWS, Microsoft Azure, Google Cloud, and Oracle Cloud Infrastructure (OCI).
Implementation Guide: Configuring OpenShell on Enterprise Nodes
Enterprise engineering teams can initialize OpenShell via standard container runtimes:
# /etc/nvidia/openshell/policy-agent.yaml
apiVersion: safety.nvidia.com/v1alpha1
kind: AgentSandboxPolicy
metadata:
name: enterprise-finance-agent
spec:
runtime:
type: openshell-microvm
memoryLimitMb: 8192
cpuLimitCores: 4
isolation:
allowRawSockets: false
enforceEphtokenRenewalMinutes: 5
blockedSyscalls:
- ptrace
- bpf
- mount
- reboot
networkEgress:
allowedDomains:
- "api.internal.bank.com"
- "storage.googleapis.com"
denyAllOther: true
sentryIntegration:
dpuDevice: "bluefield4-0"
heartbeatIntervalMs: 50
quarantineOnPolicyBreach: true
Deploying this configuration creates a dual-boundary perimeter: OpenShell traps unauthorized syscalls before execution, and the BlueField-4 DPU verifies that all outbound traffic matches signed hardware policies.