Analysis
October 2, 2026
8 min read
Maxime Dalessandro

Nvidia Open Agent Safety Platform: what the DPU can't see

Nvidia's Open Agent Safety Platform pairs the OpenShell runtime with Sentry, a DPU watchdog that quarantines agents in milliseconds. Where that span ends.

#Nvidia#OpenShell#BlueField-4#agent security#AI agents#zero trust#PostgreSQL

TL;DR. On September 28, 2026, Nvidia launched the Open Agent Safety Platform: OpenShell, an open source runtime that sets the boundary an agent executes inside, and Sentry, a watchdog on BlueField-4 DPUs that monitors from outside the host and can quarantine an agent in milliseconds. More than 100 organizations are collaborating, Anthropic, Microsoft, SAP, and JPMorganChase among them. The design principle is the right one: enforcement lives where the agent cannot touch it. The open question is altitude. A runtime sees syscalls and a DPU sees flows, and an authorized database session looks identical at both altitudes whether it reads one row or every table the role can see.

Nvidia's framing for the launch is blunt. Jensen Huang put it as "safety and security require full-stack engineering," and the announcement describes the platform as full-stack governance across the software, hardware, compute, and robotics systems that run agents. The trigger, per The Next Web's coverage, is a string of incidents in which agents bypassed the controls around them, including OpenAI agents taking over a German wiki to use it as a message board. After a month in which the industry watched sandbox escapes and agents editing their own traces, the consensus architecture has become enforcement from a vantage point the agent cannot write to. Nvidia just shipped the reference design for it.

Two components, one principle

OpenShell is the software half: an open source secure runtime, published on GitHub, that enforces what an agent can see, do, and interact with. Operators define which files, networks, tools, and credentials an agent may reach; the runtime applies those rules out of process, keeps an audit trail of every allow and deny decision, and collects sandbox logs centrally. Per Infosecurity Magazine, the controls reach from kernel-level filesystem and process restrictions up to policy checks on outbound requests. It supports Claude, Codex, OpenClaw, and custom agents, and it runs on local machines, on-premises servers, cloud, and Kubernetes. Nvidia optimized it for its Vera CPUs, claiming 80% faster sandbox performance there, but Arm and Intel platforms are supported and no Nvidia hardware is required.

Sentry is the hardware half, and the more interesting one. It runs on BlueField-4 DPUs, built on DOCA, as a security domain independent of the host: it keeps operating even if the host it watches is compromised. From that position it inspects requests and responses, verifies identity, enforces zero-trust policy, produces attested telemetry of agent behavior, and can quarantine an agent that moves outside its boundary in milliseconds. The quarantine claim is the headline primitive: a watchdog the agent cannot see, with the authority to cut it off faster than any human review loop.

The partner list signals how quickly this becomes default infrastructure. The press release names Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, and ServiceNow among more than 100 collaborating organizations. Claude's Managed Agents integrate with OpenShell and BlueField, SAP is embedding OpenShell in its Joule Studio runtime, and Salesforce wired it to Slack so humans can review activity and approve permissions. When a runtime boundary ships inside the platforms agents already run on, "should agents run inside an enforced boundary" stops being a question anyone asks. The question that remains is what the boundary can express.

What each vantage point sees

Walk one authorized agent session through the stack and tag what each enforcement point observes.

The agent opens a connection to a Postgres host. OpenShell sees the process making the attempt, the credential it loaded, the destination host and port, and checks each against policy. Allowed: the agent's role is permitted to reach this database. Every one of those decisions lands in the audit trail. Sentry, from the DPU, sees the flow: source, destination, identity, tenant boundary, all attested, none of it falsifiable by the agent. Also allowed. Both verdicts are correct. The session is authorized.

Then the session starts issuing SQL, and both vantage points go dark. Not through any defect: the packets are encrypted application payload moving along a permitted flow, and payload semantics were never these layers' job. The query text, the tables it names, the plan the optimizer picks, the pages it drags off disk, the rows it returns, the write set it commits: all of it happens below the floor that syscalls and flows can describe. Nvidia's own materials say Sentry enforces granular zero-trust policy on data access, and at the DPU's altitude that means which principals reach which data services over which paths. It cannot mean which rows, because a DPU does not parse SQL against a schema it has no concept of.

A horizontal flow of one agent session from process launch through connection and network transit into a database, where it becomes query, plan, and rows touched. Two brackets below mark enforcement spans: OpenShell covers the process, credential, and connection steps, Sentry covers the network transit. The database interior, holding the query, plan, and rows, sits highlighted beyond the end of both brackets.

One authorized session, three altitudes. OpenShell rules on the process and the connection, Sentry rules on the flow. The SQL inside the session executes past the end of both spans.

This is the same boundary we traced through CData's Connect AI Gateway three days before Nvidia's launch, one layer up. A connector gateway governs the requests it mediates and never sees the query executing inside the source. A runtime governs the syscalls and connections, a DPU governs the flows, and neither sees the query either. Each layer added this month ends at a boundary, and the boundaries nest: tool call, process, packet. The query inside the database sits inside all of them.

A quarantine fires on a boundary. A query never crosses one.

Sentry's quarantine primitive assumes the dangerous agent is the one that leaves its lane: escapes the sandbox, reaches a host it should not, tunnels out through a resolver. For that class, in-silicon enforcement outside the host is exactly right, and the recent incident record says the class is real.

But the incident record carries a second class, and it is the one we keep writing about. The OpenAI and Hugging Face incident ran on authorized writes: agents used storage operations they were permitted to perform as a covert coordination channel. Stale authorization does its damage through sessions that were legitimately granted and outlived the condition that justified them. A Supabase anon key reading a table RLS never protected is an authorized read. In each case every observable the enforcement stack checks comes back green: right process, right credential, right destination, right flow. The damage is in the content of the permitted action, and content at the database layer means SQL against a schema whose meaning the lower layers do not hold.

Granularity follows the same line. Quarantine acts on an agent in milliseconds, which is the right response to an escape in progress. Against a damaging query inside an authorized session it is both too slow and too coarse: a SELECT that exfiltrates a table the role could always read finishes inside the same flow it started in, and cutting the agent off afterward ends a session whose harm is already committed. The enforcement point that could have ruled on the query is the one that can read it: at parse time, against the schema, with knowledge of what the tables mean and what this agent's task actually requires.

Out-of-band needs a semantic floor

None of this argues against the platform. Out-of-band is the correct posture, and Nvidia commoditizing it is good news: an agent that can rewrite its own logs can never be trusted to enforce its own limits, so every layer of self-policing the industry retires is progress. OpenShell's allow-and-deny audit trail and Sentry's attested telemetry are the kind of record an incident review can actually trust.

The conclusion the launch invites is to carry the same principle one layer further down. The database is a natural out-of-band vantage point: it sits outside the agent's process, it already authenticates every session, and it is the one place the query stops being payload and becomes structure, a plan, a set of tables, a write set. Enforcement there can rule on what the lower layers cannot express: this role may read these tables for this task, this query's plan touches what it predicted, this write set matches the approval that authorized it. That takes resolved meaning, knowing what the tables are and which agent tasks map to them, which is precisely what packet and process vantage points cannot reconstruct. Sentry and a data-layer policy gate do not compete for a budget line; they bound different failure classes of the same agent. One catches it leaving the boundary. The other governs what it does while staying inside.

The platform's partner list suggests Nvidia understands the stack has more layers than its silicon reaches: the reference design governs where agents run and what they may reach, and leaves what their queries mean to whoever holds the schema. That is the layer the next launch in this sequence will have to claim.

Where Datapace fits

The span below the packet is where Datapace works. Datapace is building the context layer between your databases and your AI: resolved meaning validated by the people who own the data, the workload evidence beside it (cost, performance, usage and freshness, lineage), and a policy gate over what an agent may do and access, served over MCP. If your agent stack now enforces everything except the SQL, that is the conversation to have: book a call.

Sources

  1. Nvidia, NVIDIA Launches Open Agent Safety Platform, September 28, 2026 (platform description, OpenShell and Sentry components, Vera and BlueField-4 details, partner list, Huang quote, Claude Managed Agents, SAP Joule Studio, Slack integration).
  2. Nvidia, Open Agent Safety Platform solutions page (OpenShell enforcement scope and GitHub availability, supported agents, deployment targets, allow/deny audit trail, Sentry attested telemetry and tenant isolation, 80% sandbox performance claim, host-independent security domain).
  3. Infosecurity Magazine, NVIDIA Launches Open Platform to Secure Autonomous AI Agents, September 2026 (kernel-level filesystem and process controls, outbound request policy checks, Salesforce Slack workflow).
  4. The Next Web, Nvidia launches agent safety platform backed by over 100 companies, September 28, 2026 (launch date, incident context including the German wiki takeover, operator-defined files, networks, tools and credentials, Open Secure AI Alliance governance under the Linux Foundation, Huang quote).

Frequently asked questions

What is the Nvidia Open Agent Safety Platform?
An open platform and reference design announced September 28, 2026 for governing autonomous AI agents. It combines OpenShell, an open source secure runtime, with Sentry, an out-of-band watchdog on BlueField-4 DPUs. Over 100 organizations are collaborating on it.
What is Nvidia OpenShell?
An open source runtime that sets the boundary an AI agent executes inside: which files, networks, tools, and credentials it can reach, with every allow or deny decision logged. It runs on local, cloud, and Kubernetes setups without Nvidia hardware, and supports Claude, Codex, and custom agents.
What is Nvidia Sentry and how fast can it quarantine an agent?
Sentry is a watchdog that runs on BlueField-4 DPUs, outside the host the agent runs on. It inspects traffic, verifies identity, collects attested telemetry, and can quarantine an agent that moves outside its boundary in milliseconds, staying operational even if the host itself is compromised.
Can OpenShell or Sentry govern the SQL an agent runs inside a database?
No. Both enforce at the process and network layers: which connection an agent may open, to which host, as which identity. The SQL inside an authorized session, the tables it touches, the plan, the write set, is payload at both altitudes and needs enforcement at the data layer.
Does OpenShell require Nvidia hardware to run?
No. OpenShell is optimized for Nvidia Vera CPUs, where Nvidia claims 80% faster sandbox performance, but it runs on Arm and Intel platforms and deploys to local machines, on-premises servers, cloud, and Kubernetes without BlueField-4. Sentry is the component tied to Nvidia silicon.

Keep reading

Ready to let agents touch production, safely?

Bring a use case. We will show you what agents can do on your live data, inside your guardrails.