Intel adds NVIDIA’s OpenShell policy layer to its AI agent toolkit

Photo: Matheus Bertelli / Pexels

Intel adds NVIDIA’s OpenShell policy layer to its AI agent toolkit

Intel's AI for Enterprise Agent Toolkit now supports NVIDIA OpenShell, bringing sandboxing, YAML policies and kernel-level controls to autonomous agents on Xeon

Intel has integrated NVIDIA OpenShell into its AI for Enterprise Agent Toolkit. The addition gives companies running autonomous AI agents a dedicated policy layer that controls what those agents can do.

What OpenShell actually adds

Technically, the integration brings three main capabilities: sandboxed execution, policy specifications written in YAML, and access controls enforced at the kernel level. All of it runs on Intel Xeon processors.

Sandboxed execution means each agent operates inside its own contained environment. If something goes sideways, the damage is meant to stay inside that box rather than spreading across the wider system.

YAML is a plain-text configuration format that engineers already use widely. Writing policies in it means security teams can read, review and version-control agent rules like any other config file, without learning a proprietary language.

The kernel is the core of an operating system, the layer that decides which programs get access to memory, files and hardware. Enforcing rules there makes them far harder for an agent to route around than rules applied higher up the software stack.

OpenShell supports default-deny rules, applied on a per-sandbox basis. Anything not specifically permitted is blocked, and each sandbox gets its own rule set.

Advertisement

The policies can also govern process access, controlling which programs an agent is allowed to launch or interact with.

Credential management is part of the package too. Sensitive data such as passwords and keys is kept outside the agent’s reach, so the agent can use approved services without ever holding the secrets itself.

The integration supplies a gateway that handles sandboxes, policies and credentials in one place, along with granular access controls. It also supports live policy updates and maintains audit trails.

Opt-in by design

Intel has made the feature off-by-default. Teams turn it on with a single configuration flag: deploy_openshell=on.

The integration is also additive. It layers on top of the toolkit without replacing existing components, so current deployments keep working as they did before.

OpenShell itself is released under the Apache-2.0 license. That is a permissive open-source license, meaning companies can inspect, modify and deploy the code without paying licensing fees or open-sourcing their own changes.

The NVIDIA connection

OpenShell is NVIDIA’s project, not Intel’s. NVIDIA launched it on September 28, 2026, alongside its broader Open Agent Safety Platform.

Intel’s integration was announced in tandem with those NVIDIA developments. NVIDIA supplies the open-source policy engine, while Intel packages it into an enterprise toolkit tuned for its Xeon server chips.

Why agent security is becoming the main event

Early AI chatbots mostly produced text. A person read the output and decided what to do with it, which kept a human between the model and any real-world consequences.

Autonomous agents remove much of that buffer. They are built to interact directly with system components, which is exactly what makes them useful and exactly what makes security teams lose sleep.

OpenShell’s approach targets that risk from several angles at once. Sandboxes contain actions, default-deny rules limit permissions, credential isolation protects secrets and audit trails record what happened.

What this means for enterprises and the chip race

The feature is off by default, so real-world impact depends on how many teams actually flip the switch and how much operational overhead strict default-deny policies create in practice.

Security tooling also only works as well as the rules people write. A kernel-level enforcement engine paired with a sloppy YAML file can still leave doors open.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Intel adds NVIDIA’s OpenShell policy layer to its AI agent toolkit
Intel adds NVIDIA’s OpenShell policy layer to its AI agent toolkit

Intel's AI for Enterprise Agent Toolkit now supports NVIDIA OpenShell, bringing sandboxing, YAML policies and kernel-level controls to autonomous agents on Xeon

Photo: Matheus Bertelli / Pexels

Intel has integrated NVIDIA OpenShell into its AI for Enterprise Agent Toolkit. The addition gives companies running autonomous AI agents a dedicated policy layer that controls what those agents can do.

What OpenShell actually adds

Technically, the integration brings three main capabilities: sandboxed execution, policy specifications written in YAML, and access controls enforced at the kernel level. All of it runs on Intel Xeon processors.

Sandboxed execution means each agent operates inside its own contained environment. If something goes sideways, the damage is meant to stay inside that box rather than spreading across the wider system.

YAML is a plain-text configuration format that engineers already use widely. Writing policies in it means security teams can read, review and version-control agent rules like any other config file, without learning a proprietary language.

The kernel is the core of an operating system, the layer that decides which programs get access to memory, files and hardware. Enforcing rules there makes them far harder for an agent to route around than rules applied higher up the software stack.

OpenShell supports default-deny rules, applied on a per-sandbox basis. Anything not specifically permitted is blocked, and each sandbox gets its own rule set.

Advertisement

The policies can also govern process access, controlling which programs an agent is allowed to launch or interact with.

Credential management is part of the package too. Sensitive data such as passwords and keys is kept outside the agent’s reach, so the agent can use approved services without ever holding the secrets itself.

The integration supplies a gateway that handles sandboxes, policies and credentials in one place, along with granular access controls. It also supports live policy updates and maintains audit trails.

Opt-in by design

Intel has made the feature off-by-default. Teams turn it on with a single configuration flag: deploy_openshell=on.

The integration is also additive. It layers on top of the toolkit without replacing existing components, so current deployments keep working as they did before.

OpenShell itself is released under the Apache-2.0 license. That is a permissive open-source license, meaning companies can inspect, modify and deploy the code without paying licensing fees or open-sourcing their own changes.

The NVIDIA connection

OpenShell is NVIDIA’s project, not Intel’s. NVIDIA launched it on September 28, 2026, alongside its broader Open Agent Safety Platform.

Intel’s integration was announced in tandem with those NVIDIA developments. NVIDIA supplies the open-source policy engine, while Intel packages it into an enterprise toolkit tuned for its Xeon server chips.

Why agent security is becoming the main event

Early AI chatbots mostly produced text. A person read the output and decided what to do with it, which kept a human between the model and any real-world consequences.

Autonomous agents remove much of that buffer. They are built to interact directly with system components, which is exactly what makes them useful and exactly what makes security teams lose sleep.

OpenShell’s approach targets that risk from several angles at once. Sandboxes contain actions, default-deny rules limit permissions, credential isolation protects secrets and audit trails record what happened.

What this means for enterprises and the chip race

The feature is off by default, so real-world impact depends on how many teams actually flip the switch and how much operational overhead strict default-deny policies create in practice.

Security tooling also only works as well as the rules people write. A kernel-level enforcement engine paired with a sloppy YAML file can still leave doors open.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.