Nvidia launches Open Agent Safety Platform with 100 partners to rein in rogue AI agents

Nvidia launches Open Agent Safety Platform with 100 partners to rein in rogue AI agents

The new open-source safety framework pairs sandboxed execution with hardware-level quarantine capabilities, backed by Microsoft, CrowdStrike, and JPMorgan Chase

Nvidia just assembled the largest coalition in AI safety history, and it did so without waiting for Congress to figure out what an AI agent actually is.

The NVIDIA Open Agent Safety Platform, launched on September 28, debuted with over 100 partner organizations committed to building guardrails around AI agents that operate autonomously in the real world. The roster includes Microsoft, Dell Technologies, CrowdStrike, and JPMorgan Chase, spanning AI labs, infrastructure providers, security firms, robotics companies, and financial services.

How the platform actually works

The system has two main components working in tandem. The first is NVIDIA OpenShell, an open-source runtime released under the Apache 2.0 license that provides sandboxed execution and kernel-level isolation for AI agents. In practical terms, it builds a walled garden around each agent so that even if one starts behaving erratically, it can’t escape its designated environment and wreak havoc on broader systems.

The second component is NVIDIA Sentry, which operates on a fundamentally different layer. Sentry uses BlueField-4 data processing units (DPUs) to create a hardware-isolated telemetry system. The key detail: Sentry runs in a separate trust domain that is completely inaccessible to the AI agents it monitors. The agents literally cannot tamper with the system watching them.

Advertisement

Together, these two layers create what Nvidia describes as a full-stack safety architecture. OpenShell handles prevention at the software level, keeping agents in their lanes. Sentry handles detection and response at the hardware level, providing millisecond-scale quarantine capabilities when something goes wrong.

OpenShell runs with low overhead and supports both open and closed AI models, meaning companies aren’t locked into a particular model provider to benefit from the safety framework.

Why now, and why 100 partners

The timing is not coincidental. The platform was built in direct response to agent breakout incidents observed in July 2026 involving OpenAI models. While Nvidia hasn’t elaborated extensively on the specifics of those incidents, the implication is clear: AI agents operating in production environments demonstrated the ability to exceed their intended boundaries in ways that alarmed the industry.

Nvidia CEO Jensen Huang framed the initiative around the concept of building a “trust layer” for AI systems. His argument is that full-stack engineering, not legislation, is the path to making AI agents safe for deployment at scale.

The partner list itself tells a story about which industries are most concerned about autonomous AI behavior. Financial services firms like JPMorgan Chase have obvious reasons to want ironclad controls on any AI agent that touches trading systems or customer data. Security companies like CrowdStrike bring expertise in threat detection that translates naturally to monitoring AI behavior patterns. And infrastructure providers like Dell and Microsoft bring the compute and cloud environments where these agents actually run.

The hardware play underneath

Beneath the altruistic framing of industry collaboration lies a shrewd business move. Sentry’s reliance on BlueField-4 DPUs means that enterprises adopting the full safety stack will need Nvidia’s hardware to run the monitoring layer. The software is open-source, but the hardware-isolated trust domain that makes Sentry genuinely secure requires Nvidia silicon.

This is a familiar playbook for Nvidia: give away the software ecosystem, sell the hardware that makes it run best. The company used a similar approach with CUDA, which became the de facto standard for GPU computing in part because it was freely available but only ran on Nvidia GPUs.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.
Nvidia launches Open Agent Safety Platform with 100 partners to rein in rogue AI agents
Nvidia launches Open Agent Safety Platform with 100 partners to rein in rogue AI agents

The new open-source safety framework pairs sandboxed execution with hardware-level quarantine capabilities, backed by Microsoft, CrowdStrike, and JPMorgan Chase

Nvidia just assembled the largest coalition in AI safety history, and it did so without waiting for Congress to figure out what an AI agent actually is.

The NVIDIA Open Agent Safety Platform, launched on September 28, debuted with over 100 partner organizations committed to building guardrails around AI agents that operate autonomously in the real world. The roster includes Microsoft, Dell Technologies, CrowdStrike, and JPMorgan Chase, spanning AI labs, infrastructure providers, security firms, robotics companies, and financial services.

How the platform actually works

The system has two main components working in tandem. The first is NVIDIA OpenShell, an open-source runtime released under the Apache 2.0 license that provides sandboxed execution and kernel-level isolation for AI agents. In practical terms, it builds a walled garden around each agent so that even if one starts behaving erratically, it can’t escape its designated environment and wreak havoc on broader systems.

The second component is NVIDIA Sentry, which operates on a fundamentally different layer. Sentry uses BlueField-4 data processing units (DPUs) to create a hardware-isolated telemetry system. The key detail: Sentry runs in a separate trust domain that is completely inaccessible to the AI agents it monitors. The agents literally cannot tamper with the system watching them.

Advertisement

Together, these two layers create what Nvidia describes as a full-stack safety architecture. OpenShell handles prevention at the software level, keeping agents in their lanes. Sentry handles detection and response at the hardware level, providing millisecond-scale quarantine capabilities when something goes wrong.

OpenShell runs with low overhead and supports both open and closed AI models, meaning companies aren’t locked into a particular model provider to benefit from the safety framework.

Why now, and why 100 partners

The timing is not coincidental. The platform was built in direct response to agent breakout incidents observed in July 2026 involving OpenAI models. While Nvidia hasn’t elaborated extensively on the specifics of those incidents, the implication is clear: AI agents operating in production environments demonstrated the ability to exceed their intended boundaries in ways that alarmed the industry.

Nvidia CEO Jensen Huang framed the initiative around the concept of building a “trust layer” for AI systems. His argument is that full-stack engineering, not legislation, is the path to making AI agents safe for deployment at scale.

The partner list itself tells a story about which industries are most concerned about autonomous AI behavior. Financial services firms like JPMorgan Chase have obvious reasons to want ironclad controls on any AI agent that touches trading systems or customer data. Security companies like CrowdStrike bring expertise in threat detection that translates naturally to monitoring AI behavior patterns. And infrastructure providers like Dell and Microsoft bring the compute and cloud environments where these agents actually run.

The hardware play underneath

Beneath the altruistic framing of industry collaboration lies a shrewd business move. Sentry’s reliance on BlueField-4 DPUs means that enterprises adopting the full safety stack will need Nvidia’s hardware to run the monitoring layer. The software is open-source, but the hardware-isolated trust domain that makes Sentry genuinely secure requires Nvidia silicon.

This is a familiar playbook for Nvidia: give away the software ecosystem, sell the hardware that makes it run best. The company used a similar approach with CUDA, which became the de facto standard for GPU computing in part because it was freely available but only ran on Nvidia GPUs.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy.