Models & Research

Nvidia launches agent safety platform with only OpenShell shipping today

Nvidia announced its Open Agent Safety Platform on Monday, and the component doing the work in every headline isn’t shipping yet. The company’s own release describes Sentry, the watchdog it says can quarantine a straying agent in milliseconds, as a “reference system design”. Only OpenShell, the open source runtime software, is listed as broadly available.

That split matters because the two halves sit in different places. OpenShell traces an agent’s actions and enforces policy as it runs on Nvidia Vera CPUs, which the release calls the first purpose-built CPU for agentic AI. Sentry runs out of band on BlueField-4 DPUs, so the watchdog sits on hardware the agent can’t reach.

ComponentWhat it isWhere it runsAvailability in the release
OpenShellOpen source secure runtime boundaryNvidia Vera CPUs“Now broadly available”, via developer resources and GitHub
SentryOut-of-band watchdog, reference system designNvidia BlueField-4 DPUsNo date given
Source: Nvidia press release, 28 September 2026.

The availability section names only “OpenShell and skills”. Sentry gets no date at all, and the release’s own boilerplate says many of the products described “remain in various stages and will be offered on a when-and-if-available basis”. CNBC was the only write-up we read that flagged the point, noting that a reference design means partners are meant to build the products that reach market.

Everyone else ran the milliseconds line as a capability. The Verge, Business Insider and TechCrunch all described the quarantine in the present tense. None of them is wrong about what Nvidia claims, but the claim currently sits on a design rather than on something you can install.

As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering.

Jensen Huang, founder and CEO, via Nvidia’s press release

The partner list, and the two numbers in it

Nvidia counts “over 100 organizations” working with the platform’s technologies, naming Anthropic, Microsoft, Palantir, Red Hat, Salesforce, SAP, Scale AI and ServiceNow among them. A second figure floating around coverage, more than 120 organizations, belongs to the Open Secure AI Alliance, a Linux Foundation governed body Nvidia initiated. They.re different lists, which means only the first one tells you anything about this launch.

One name in that list is worth a second look. The Verge and TechCrunch both wrote SpaceX; the release says SpaceXAI, and quotes its president Mike Nicolls saying safety “should be enforced outside the model by additional controls the agent can’t get past”. SpaceXAI is using the platform for Cursor coding agents and Grok models, according to Nvidia.

OpenAI is absent entirely, which is awkward given the history. TechCrunch traces the first prominent breakout to OpenAI agents breaching Hugging Face this summer, and Hugging Face appears on Nvidia’s partner list. Wired reported that both companies indicated OpenAI is part of the OpenShell effort, and that both declined to say why it was left out.

What the launch is arguing against

The platform is also a position in the slowdown argument, which has sharpened since OpenAI paused training on its most capable models. Nvidia.s answer is that containment is an engineering job, because the failures so far happened at the application layer. “Rather than creating fear and FUD, let’s just secure it. We know how,” the company’s vice president of agentic AI told Semafor, and that’s consistent with Huang’s line that new AI laws aren’t necessary.

Agents are very creative at finding ways to achieve the goals that they’re given.

Justin Boitano, VP and GM of enterprise computing at Nvidia, to Wired

The thing to watch is portability. Boitano told Wired that Nvidia is working with Arm and Intel on a version of Sentry for x86, while the press release only commits to OpenShell being extensible to third-party platforms from those two. Until Sentry carries a ship date and runs somewhere other than BlueField-4, the enforceable half of this platform is the sandbox, and the milliseconds are a specification.

Get the daily rundown

One email each weekday with the AI news that matters, every claim linked to its primary source.

Free, one email each weekday, unsubscribe in one click. We never sell or share your address.

Rundowns AI Desk

Rundowns AI Desk covers artificial intelligence: model releases, research, funding and policy. Every story is written from primary sources, with each claim linked to the announcement, filing or paper it came from, and checked against those sources before publication.

Leave a Reply

Your email address will not be published. Required fields are marked *