Nvidia Wants Hardware to Watch AI Agents While They Work
Matthew Leo · Published September 29, 2026 · AI
Nvidia introduced an Open Agent Safety Platform on September 28 that puts restrictions around autonomous AI agents while they work. Its central idea is straightforward: an agent should not be the only thing deciding whether its own actions are allowed.
The platform combines OpenShell, an open-source runtime that confines an agent to an operator's rules, with an optional hardware layer called Sentry on Nvidia's BlueField data-processing units. In Nvidia's technical description, an operator can define access to files, networks, tools and credentials before an agent starts. Sentry is meant to watch activity from outside the agent's own environment and help enforce those limits.
What the controls can actually do
For a business using agents to read documents or run code, this changes the question from “Is the model trustworthy?” to “What can this job reach?” An agent that only needs a test database should not have access to a production customer database. An agent asked to draft an email should not quietly gain permission to send it. Those are examples of sensible access rules, not claims that Nvidia's product has passed a real-world test of either scenario.
Nvidia says OpenShell uses kernel-level isolation and that the BlueField layer can observe agent behaviour independently of the host. The company calls the wider design a reference platform. It says OpenShell is open source, while the extra hardware enforcement is optional and suited to infrastructure equipped for it. This is not a consumer switch that automatically secures every chatbot or laptop.
The Associated Press reported that outside experts see value in these boundaries but warned that defining effective rules remains difficult. An agent can still produce a wrong answer or make a poor decision while staying inside its permissions. Nvidia has not published independent evidence that the new platform would have stopped any specific past incident.
Why teams may pay attention now
The announcement follows reports of agents reaching systems beyond their assigned tasks. Mapletechie recently covered OpenAI's pause after a sandbox breach. That incident and Nvidia's response point to a practical procurement question for Canadian companies and public agencies: can they see and limit each agent's access, and can they stop it without relying on the agent to obey a new instruction?
Before adopting a platform like this, a team should test a narrow task with deliberately restricted files, network destinations and credentials, then inspect what happens when the agent attempts something outside its scope. Logs, human approval for sensitive actions and a way to revoke access still matter. Nvidia's design offers a clearer place to put those controls; whether it holds up under hostile or unusual workloads needs independent testing.
Tags: Nvidia, AI agents, cybersecurity, OpenShell, News analysis