Singapore – NVIDIA has launched an open software platform and reference system design that aims to secure AI agents from testing through to deployment. The company says the NVIDIA Open Agent Safety Platform, announced on 28 September 2026, offers full-stack governance across the software, hardware, computer, and robotics systems that run agents.
The move follows recent security incidents that, according to NVIDIA, underscored the need for open, customisable tools that give organisations more control over long-running agents. The company says the pattern was consistent: the agent circumvented application-layer security controls to complete its assigned task.
NVIDIA Founder and CEO Jensen Huang framed the launch as an engineering challenge.
“AI’s extraordinary potential for society will only be realized if we solve AI safety,” said Huang.
“As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety. Safety and security require full-stack engineering. NVIDIA Open Agent Safety Platform brings together industry, researchers and public-sector organizations to share best practices, align on evaluation methods and foster international cooperation. Together, we can raise the bar for global AI safety,” Huang added.
The platform has two core components: NVIDIA OpenShell, an open-source runtime, and NVIDIA Sentry, a hardware-based reference design. NVIDIA says organisations can deploy individual elements according to their own requirements.
OpenShell, now broadly available, creates a secure runtime boundary that traces all agent actions and enforces policy. NVIDIA says it works across both open and closed models, and adds minimal overhead when running on its Vera CPU, which the company describes as the first purpose-built CPU for agentic AI.
Because OpenShell is open source, developers can also extend it to third-party compute platforms, including those from Arm and Intel. NVIDIA argues that enterprises need an enforceable boundary outside the model and agent harness as agents take on work across more systems.
Sentry, meanwhile, sits outside the agent’s own environment. It runs as an out-of-band watchdog on NVIDIA BlueField-4 DPUs, monitoring agent behaviour continuously.
According to NVIDIA, Sentry enforces security policies in silicon and can quarantine and stop an agent that moves outside its software boundary within milliseconds. The company adds that it operates from an isolated trust domain that is invisible to both agents and attackers.
Sentry is built on NVIDIA DOCA software. NVIDIA says this allows it to inspect agent requests and responses, provide attested telemetry, verify agent identity and enforce granular, zero-trust access policies for data, tools, application programming interfaces and services.
Several major technology firms have already tied their products to the platform. Anthropic, for instance, says its Claude Managed Agents run the agent loop on a separate server from the sandboxes where work executes, and that integrations with OpenShell and BlueField let enterprises tighten control over access to those sandboxes.
“Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do, especially in sensitive environments,” said Paul Smith, Chief Commercial Officer of Anthropic.
“Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software,” Smith continued.
SpaceXAI is also using the platform for Cursor coding agents and Grok models. Its president voiced a similar view on where controls should sit.
“As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, President at SpaceXAI.
“Customers should be able to set those limits for Cursor and Grok and trust they will hold,” Nicolls added.
Scale AI, in turn, is working with NVIDIA to fold the platform’s technologies into the agentic infrastructure layer of its Scale GenAI Portfolio.
“Scale AI is using the NVIDIA Open Agent Safety Platform reference design to build reliable agentic AI systems for our enterprise and government customers running mission-critical applications, with isolation, policy enforcement and auditability built in from the start,” said Francis deSouza, CEO of Scale AI.
“We support agentic security with clear boundaries that define what agents can do, and controls that keep them operating within those permissions,” deSouza further explained.
Enterprise software vendors are moving in the same direction. Salesforce and NVIDIA have integrated OpenShell with Slack, allowing teams to view agent activity and audit events, and to approve or reject agent requests for additional permissions.
SAP, for its part, is embedding OpenShell with its Joule Studio runtime, part of the SAP Business AI Platform. The company is also contributing engineering work to OpenShell and working with NVIDIA on interoperability standards through the Open Secure AI Alliance.
More than 100 organisations are working with the platform’s technologies, according to NVIDIA. They include Accenture, Cisco, CrowdStrike, Deloitte, EY, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Perplexity and ServiceNow.
Beyond software, robotics companies such as Figure, Gecko Robotics and Skild AI are building with OpenShell to embed safety controls into autonomous systems that act in the physical world.
Financial services firms are also involved. Citi and JPMorganChase are collaborating with NVIDIA on shared open source agent safety technologies.
Energy and infrastructure providers are on the list as well. NVIDIA names Hitachi Energy, EPRI, NextEra Energy, Quanta Services, SPP, Schneider Electric, Siemens Energy and Worley among critical U.S. infrastructure providers working with the technologies.
On the operating system side, Canonical, SUSE and Red Hat are integrating the platform into widely used software. Red Hat runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA, a co-engineered enterprise AI solution for building, deploying and managing AI across hybrid cloud environments.
Finally, infrastructure partners including Baseten, CoreWeave, Dell Technologies, GMI Cloud, HPE, HP Inc., Lenovo, Nebius, Oracle Cloud Infrastructure, Supermicro and Together AI are offering solutions that support the platform, NVIDIA says.

