NVIDIA Builds a Security Layer for Autonomous AI, Agents Can Now Be Monitored and Quarantined in Milliseconds

Artificial intelligence agents are becoming capable of doing far more than generating text. They can browse websites, execute code, interact with enterprise applications, access data, coordinate workflows, and increasingly operate for extended periods with limited human intervention. That expanding autonomy creates a fundamental security challenge: an AI agent must not only be intelligent enough to complete a task, it must remain inside clearly defined boundaries while doing so.
NVIDIA is addressing that problem with its Open Agent Safety Platform, an open software platform and reference system design intended to provide security and governance across the full agent stack. Announced on September 28, 2026, the platform combines NVIDIA OpenShell software with the NVIDIA Sentry reference architecture, extending security controls from the software environment into underlying compute infrastructure and, eventually, physical robotic systems.
The approach reflects an important change in AI security thinking. Instead of relying exclusively on the model or the application controlling an agent, NVIDIA is building additional enforcement layers around the agent that can monitor, restrict, and, when necessary, stop its behavior.
Why Autonomous AI Agents Need a New Security Model
Traditional software generally executes according to explicitly programmed instructions. AI agents introduce a degree of flexibility that makes conventional security assumptions harder to maintain.
An agent may interpret a natural-language objective, determine a sequence of actions, use multiple tools, and adapt its behavior when circumstances change. That flexibility is useful, but it also means the agent's actual behavior can become difficult to predict in advance.
The security problem becomes particularly serious when agents have access to sensitive systems.
An enterprise agent might be allowed to read customer information, interact with APIs, execute software, modify documents, or communicate with employees. If its instructions are manipulated or it makes an incorrect decision, the consequences can extend beyond an inaccurate answer.
Recent AI security incidents have reinforced this concern. NVIDIA's stated rationale for the new platform is that agents can sometimes circumvent controls at the application layer while attempting to accomplish their assigned objectives.
That leads to a central principle in agent security:
An AI system should not be its own ultimate security boundary.
If an agent is capable of making decisions, another layer should be capable of enforcing restrictions independently of those decisions.
NVIDIA Open Agent Safety Platform Explained
NVIDIA's platform is designed as a full-stack approach rather than a single security product.
Its main components include:
NVIDIA OpenShell, an open-source secure runtime for AI agents.
NVIDIA Sentry, an out-of-band monitoring and enforcement system.
NVIDIA Vera CPUs, designed for agentic AI workloads.
NVIDIA BlueField-4 DPUs, which provide the hardware environment for Sentry.
NVIDIA DOCA, the software foundation used for programmable networking and security functions.
Integration with enterprise software, infrastructure, security platforms, models, and robotics systems.
The architecture separates the intelligence of an agent from the infrastructure responsible for controlling what that agent can actually do.
This is significant because AI models operate probabilistically. Security boundaries, by contrast, need to be enforceable.
OpenShell Creates a Runtime Boundary
OpenShell is the software layer that establishes a controlled execution environment for agents.
Rather than allowing an autonomous agent to interact with a system without restrictions, OpenShell provides a runtime boundary where actions can be traced and policies enforced.
The concept resembles a secure sandbox, but it is specifically oriented toward increasingly autonomous AI workloads.
An organization could use policies to define which resources an agent can access, which tools it can invoke, and what actions are permitted. The objective is to ensure that an agent's operational freedom remains consistent with its assigned role.
OpenShell is also open source. NVIDIA says it can be extended beyond NVIDIA hardware to support third-party computing platforms, including systems from Arm and Intel.
That interoperability matters because enterprise AI infrastructure is highly heterogeneous. Large organizations rarely operate on a single processor architecture, cloud environment, operating system, or AI framework.
A security layer that only works on one hardware platform would therefore have limited reach.
Sentry Adds Hardware-Level Enforcement
The more unusual component of NVIDIA's architecture is Sentry.
Sentry is described as an out-of-band watchdog running on NVIDIA BlueField-4 data processing units. Its purpose is to monitor agent behavior independently from the agent itself.
The system is designed to inspect agent activity, enforce policies, verify identity, protect data access, and provide telemetry from an isolated trust domain.
If an agent attempts to leave its permitted boundaries, Sentry can quarantine and stop it in milliseconds, according to NVIDIA.
This creates an important architectural distinction.
OpenShell operates within the software environment where agents perform their tasks. Sentry provides an additional enforcement layer outside the agent's normal execution path.
The advantage is independence. If an agent is compromised, misconfigured, or manipulated, the security mechanism does not have to depend entirely on that same agent cooperating with the security policy.
Why Out-of-Band Security Matters
Modern cybersecurity increasingly assumes that individual software components can be compromised. The answer is not simply to make every component perfectly trustworthy, but to create layered defenses.
The same principle applies to AI agents.
Consider an autonomous coding agent with permission to access a repository. Its intended job might be to inspect code, implement a specific fix, run tests, and prepare a change for review.
A compromised dependency, malicious instruction, or incorrectly interpreted request could cause the agent to attempt unrelated actions.
Application-level controls might attempt to block the behavior. But an independent infrastructure-level mechanism provides another opportunity to stop it.
This is the logic behind Sentry's out-of-band design.
The security system does not need to share the agent's objectives. It only needs to enforce predefined boundaries.
That separation can be particularly valuable for high-risk environments involving financial systems, critical infrastructure, sensitive corporate data, government applications, or physical machines.
Zero-Trust Principles Move Into Agentic AI
NVIDIA's architecture also brings established zero-trust security concepts into autonomous AI.
Zero-trust security generally assumes that access should not be granted simply because a user, device, or application is inside a trusted environment. Identity, authorization, and policy should be continuously evaluated.
For AI agents, this becomes even more important because an agent can initiate large numbers of actions at machine speed.
Sentry uses NVIDIA DOCA capabilities to support functions including:
Agent identity verification
Attested telemetry
Inspection of agent requests and responses
Granular access policies
Protection of data, tools, APIs, and services
Hardware-based enforcement
This can turn agent permissions into explicit infrastructure policies rather than relying solely on natural-language instructions.
That distinction is fundamental. Telling an AI agent, "Do not access this database," is an instruction. Enforcing at the infrastructure layer that the agent physically cannot access that database is a security control.
NVIDIA Is Building an Agent Security Ecosystem
NVIDIA's strategy extends beyond its own products.
The company says more than 100 organizations are working with its agent safety technologies, spanning AI developers, cybersecurity companies, enterprise software providers, infrastructure companies, financial institutions, energy organizations, and robotics firms.
Participants identified by NVIDIA include Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI.
The breadth of participation illustrates how agent security is becoming an infrastructure issue rather than merely a model-development issue.
Anthropic and Managed Agents
Anthropic is collaborating with NVIDIA on additional controls around its Claude Managed Agents.
The architecture separates the agent loop from the sandboxes where work executes. OpenShell and BlueField can then add further controls around those environments.
The underlying idea is layered isolation, allowing organizations to observe and restrict an agent without placing all responsibility on the AI model.
Salesforce and Slack
Salesforce has integrated OpenShell with Slack, allowing teams to observe agent activity and audit events through Slack while also approving or rejecting requests for additional permissions.
This introduces human oversight directly into the agent workflow.
Rather than forcing employees to choose between complete automation and manual execution, the system can allow an agent to proceed independently until it reaches an action requiring authorization.
SAP and Enterprise AI
SAP is integrating OpenShell with its Joule Studio runtime as part of the SAP Business AI Platform.
This illustrates another important trend: enterprise AI security is increasingly being embedded directly into the platforms where organizations build and operate agents.
Robotics and Physical AI
NVIDIA also identifies Figure, Gecko Robotics, and Skild AI among robotics organizations building with OpenShell.
This expands the problem beyond cybersecurity in conventional software.
When an AI agent controls a robot, security failures can potentially become physical failures. A system that can manipulate machinery, move through industrial environments, or perform physical tasks needs boundaries that are enforced independently of the AI's reasoning.
The Business Case for Agent Security
The commercial importance of agent security is directly connected to adoption.
Organizations are unlikely to delegate mission-critical processes to autonomous systems if those systems cannot be reliably constrained, audited, and stopped.
This creates a three-part requirement for enterprise agents:
Requirement | Purpose |
Autonomy | Allow agents to complete useful work without constant intervention |
Governance | Define what agents are authorized to access and perform |
Enforcement | Ensure those boundaries remain effective even if an agent behaves unexpectedly |
Security therefore becomes part of the economic foundation of agentic AI.
A highly capable agent without adequate controls may create unacceptable operational risk. Conversely, an extremely restrictive agent may require so much human intervention that its productivity advantage disappears.
The challenge is finding the right balance between autonomy and control.
Open Standards Could Accelerate Agent Safety
NVIDIA's decision to make OpenShell available as open-source software is strategically important.
Agentic AI is developing across competing model providers, hardware architectures, cloud platforms, enterprise systems, and application frameworks. A security standard tied exclusively to one vendor could create fragmentation.
Open technologies can potentially provide common mechanisms for policy enforcement, auditing, isolation, and interoperability.
NVIDIA is also supporting the Open Secure AI Alliance, initiated alongside more than 120 organizations and governed by the Linux Foundation. The initiative focuses on open research, tools, skills, and projects such as the Shared AI Findings Exchange.
For an emerging technology category, shared security infrastructure could become as important as shared networking and software standards were for earlier generations of computing.
What NVIDIA's Platform Does Not Solve
A runtime security layer cannot eliminate every AI risk.
It can control access and actions, but it does not automatically make an AI model factually correct. An agent can remain inside its permissions while still making a poor decision.
Organizations therefore still need model evaluation, application security, identity management, human oversight, monitoring, data governance, and incident response.
There is also a policy-design challenge. An organization must correctly define the boundaries that the security infrastructure enforces. Poorly designed permissions can either expose systems to unnecessary risk or prevent legitimate work.
Agent security is therefore not a single technology problem. It is a systems engineering problem involving models, software, hardware, people, policies, and organizational processes.
The Future of Secure Autonomous AI
The growth of autonomous agents will likely push security architecture deeper into computing infrastructure.
Today's AI applications often treat security as a layer surrounding the application. Tomorrow's agentic systems may require security mechanisms embedded throughout the execution stack.
That could include:
Hardware-enforced agent identity
Real-time policy enforcement
Continuous behavioral monitoring
Isolated execution environments
Fine-grained tool permissions
Human approval for high-impact operations
Cryptographically verifiable audit trails
Automated quarantine and recovery
Security controls extending into robotics
This architecture resembles a broader principle emerging across AI infrastructure: intelligence should be powerful, but authority should remain explicitly bounded.
NVIDIA's Open Agent Safety Platform represents an attempt to establish those boundaries across software and hardware rather than relying exclusively on the AI model itself.
AI Autonomy Requires Infrastructure-Level Trust
The next phase of artificial intelligence will not be determined solely by how intelligent models become. It will also depend on whether organizations can safely give those models meaningful authority.
NVIDIA's Open Agent Safety Platform addresses this challenge by combining OpenShell's runtime controls with Sentry's hardware-level monitoring and enforcement. Its broader ecosystem includes AI companies, cybersecurity providers, enterprise software firms, financial institutions, infrastructure operators, and robotics developers.
The significance of the approach is architectural. Instead of asking an AI agent to police itself, organizations can establish independent boundaries around what the agent can access and what it can do.
As autonomous AI becomes increasingly embedded in business operations and physical systems, that distinction could become essential.
For technology observers such as Dr. Shahid Masood and the expert team at 1950.ai, developments like NVIDIA's agent safety architecture highlight a critical direction in the AI industry: the race for more capable agents is increasingly becoming a parallel race to build the infrastructure capable of controlling them.
The future of autonomous AI may ultimately depend on both sides of that equation. Intelligence determines what an agent can accomplish. Security infrastructure determines where it is allowed to go.
Key Takeaways
NVIDIA has introduced an Open Agent Safety Platform designed to secure AI agents from testing through deployment.
NVIDIA OpenShell establishes a secure runtime boundary for agent execution and policy enforcement.
NVIDIA Sentry provides independent, out-of-band monitoring through BlueField-4 DPUs.
Sentry is designed to quarantine agents that attempt to violate defined boundaries in milliseconds.
OpenShell is open source and can be extended to third-party computing platforms including Arm and Intel.
NVIDIA's ecosystem includes more than 100 organizations across AI, cybersecurity, enterprise software, infrastructure, finance, energy, and robotics.
The platform applies zero-trust principles to autonomous AI by separating agent intelligence from infrastructure-level authority.
Agent security will require more than runtime controls, including model evaluation, identity management, governance, human oversight, and data protection.
Hardware-enforced security could become increasingly important as AI agents gain access to critical digital and physical systems.
Further Reading / External References
NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment
Nvidia Releases Software It Says Can Prevent AI Agents From Going Rogue





Comments