cd /news/ai-agents/nvidia-built-the-ai-factory-now-its-… · home › topics › ai-agents › article
[ARTICLE · art-143286] src=networkworld.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Nvidia built the AI factory. Now it’s building the locks for the doors

Nvidia launched the Nvidia Open Agent Safety Platform, a full-stack system for governing AI agents that pairs the Nvidia OpenShell runtime with a new hardware-based watchdog called Sentry, the company announced this week. Nvidia vice president of enterprise AI Justin Boitano tied the release to recent agent failures, saying "model-level safeguards alone can't govern what agents can access or do," after an OpenAI agent reportedly went rogue and breached Hugging Face in July, prompting Nvidia to form the Open Secure AI Alliance. Nvidia senior director Ali Golshan, whose team built OpenShell, said agent behavior spans the file system, network, memory and other agents, and that sub-agents can combine permitted capabilities in ways a policy did not intend, a risk the platform's Policy Prover checks for.

read8 min views2 publishedOct 1, 2026

Nvidia has led the industry through much of the AI revolution, building the most important computing platform of this era. Yet no one has considered Nvidia a security company.

That perception should shift after this week’s launch of the Nvidia Open Agent Safety Platform, a full-stack approach to governing AI agents that pairs its Nvidia OpenShell runtime with a new hardware-based watchdog called Sentry.

To back up a little, Nvidia has had security capabilities for years, including products such as Nvidia BlueField DPUs, DOCA, Morpheus, Confidential Computing, and NeMo Guardrails. These are security platforms for Palo Alto, Check Point, Fortinet, and others to run on—showing that while Nvidia is not known as a security brand, it has been active in security.

And Nvidia’s own software has been a target. Last year, Wiz Research disclosed Nvidia Scape, a critical container escape flaw in the Nvidia Container Toolkit. When your code sits under nearly every AI workload, a flaw like that becomes an industry-wide risk. In fact, I’ve been calling for the company to be more vocal regarding its role in securing AI. The world knows Nvidia as an AI brand, and security should be as big a component as computing and networking.

With the Open Agent Safety Platform, Nvidia is putting security at the center of its AI strategy, approaching it as an engineering problem to rethink, as it has in other parts of the AI stack.

Agents are driving this strategic pivot. In a recent analyst briefing, Ali Golshan, a senior director at Nvidia whose team built OpenShell, explained why traditional controls fall short. In the virtual machine and container world, you could write a policy and tie it to a process, a namespace, or a pod. “But agents don’t work like that,” Golshan said. “Agent behavior manifests across the file system, the network, memory, and other agents.”

Agents are trained to solve problems, so when they encounter friction, they go around it. “Agents don’t really understand the difference between a blocked policy that is not allowed versus a failure,” Golshan said. His best line captures why this is hard: “Agents are grown, not installed.” Nvidia’s research found that sub-agents can combine permitted capabilities in ways a policy did not intend. Policy Prover checks for this risk.

The industry has already seen this risk play out. In July, an OpenAI agent reportedly went rogue and breached Hugging Face, prompting Nvidia to form the Open Secure AI Alliance. This week, Justin Boitano, Nvidia’s vice president of enterprise AI, framed the news around that failure: “Recent incidents have highlighted a fundamental hurdle for AI agents, and that is that model-level safeguards alone can’t govern what agents can access or do.”

The Open Agent Safety Platform is an open reference design with two main components. The first is OpenShell, an Apache 2.0-licensed runtime that moves policy enforcement out of the agent’s reach and into the Linux kernel. Each agent runs in its own sandbox, credentials remain with a gateway outside the sandbox, and a policy prover uses formal methods to verify boundaries before the agent runs. “A developer can prove, for example, that an agent cannot access the internet before the agent starts running,” Boitano said. Golshan stressed that this is “not LLM as a judge,” but rather deterministic, mathematical reasoning.

OpenShell has also matured since its March debut. “When we launched in March, it was essentially single player,” Golshan said in a follow-up analyst Q&A. “With this release, it is fully multi-tenant.” He described the new release as a stable foundation with no breaking changes, adding, “It is ready for prime time.”

The second piece, Sentry, is the more strategically interesting one. It runs on BlueField-4 DPUs as an independent, out-of-band security domain. Because the DPU sits between the agent harness on the CPU and the model it calls, Sentry can monitor requests, responses, and chain-of-thought reasoning, and cut the agent off in milliseconds. Boitano compared it to the safety island in a self-driving car, an independent system that ensures the primary system fails safely. If a security testing agent starts reasoning about going beyond its approved target, he said, “Sentry can then detect this and intervene instantly.” Importantly, Sentry on BlueField adds an optional security layer for added protection. Boitano said OpenShell on CPUs is “honestly good enough” for most enterprise access control, with Sentry aimed at frontier work such as red teaming and evaluating models before they’ve been aligned.

The partner list is what gives this weight. According to Nvidia, Anthropic is integrating Claude Managed Agents with OpenShell and BlueField; Salesforce has connected OpenShell to Slack so teams can approve or reject agent permission requests; SAP is embedding it in Joule Studio; and SpaceXAI is using the platform for Cursor coding agents and Grok models. Citi and JPMorganChase are collaborating on the technology, and more than 100 organizations are working with it. “Safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, president of SpaceXAI, in the release. That sentence sums up the whole architecture.

Earlier this month at the All-In Summit, CEO Jensen Huang addressed this topic. He spent much of his time pushing back on doom predictions, but he didn’t dismiss safety. “Safety is paramount,” he said, calling the trade-off between safety and leadership a false choice. His prescription for the frontier lab incidents was pure engineering: “Root cause the problem from an engineering perspective. What happened? What could we have done differently? And what are we going to implement and institutionalize?”

This week’s launch is Nvidia putting its engineering where its mouth is. “AI’s extraordinary potential for society will only be realized if we solve AI safety,” Huang stated. “Safety and security require full-stack engineering.” He expanded on that in a CNBC interview, saying, “We can’t have a successful AI industry if the world doesn’t think it’s built and is confident it’s built and deployed safely.” Boitano’s comments at the press briefing were in line with this: “The industry does not need agents that promise to stay within bounds. It needs systems that can prove and enforce those boundaries.”

This is a meaningful step forward, but questions remain. During the analyst Q&A, I asked how this aligns with OpenAI, Google, and others building their own harnesses and sandboxes. Boitano said OpenShell is meant to be “compatible with every harness and every model combination,” but OpenAI and Google aren’t named launch partners, and their support will matter. I also asked about governance. Nvidia plans to move OpenShell to the Linux Foundation to make it part of the CNCF, but that hasn’t happened yet. Until it does, some buyers will view this as an Nvidia project, not an industry standard.

Performance is another unknown. Boitano acknowledged that running OpenShell on CPU cores will have “a slight impact” and that Nvidia hasn’t published formal measurements yet. While OpenShell is open and runs on Arm and x86, Sentry is an Nvidia implementation built on BlueField and DOCA. The strongest version of this story runs on Vera CPUs and BlueField-4, benefiting customers seeking defense in depth and supporting Nvidia’s hardware business. Nvidia will also need to earn credibility with CISOs, who haven’t previously thought of it as a security company.

Most organizations are still early in their use of agents, so now is the time to get the foundation right before hundreds of long-running agents work across the business. Here’s what I would prioritize:

Nvidia has been active in cybersecurity for years, bringing accelerated computing and AI to security through products like BlueField and Morpheus, as well as its work with security partners. Much of that work has happened behind the scenes. As a result, security leaders haven’t typically thought of Nvidia first when discussing AI protection. That’s changing because the problem has changed. When AI meant models answering questions, security could be handled largely at the application and network layers. That approach doesn’t hold up when AI means autonomous agents taking actions across file systems, networks, and other agents at machine speed. Security now has to be engineered across the entire stack, from silicon to systems software to the runtime where agents operate, and Nvidia has deep experience there.

One of the more interesting aspects of this launch is that Nvidia didn’t frame security as another product. It framed it as a systems engineering problem, which is where the company is strongest. Separating probabilistic intelligence from a deterministic control layer, enforcing policy outside the agent, verifying policies mathematically, and adding an independent watchdog in silicon together form a coherent architecture, not a collection of point features. And because OpenShell is open and the platform is a reference design, the rest of the industry, including security vendors, can build on it.

There’s also a broader point about the AI debate. Huang is right that fear-driven predictions haven’t served the industry well. But the best response to doom isn’t dismissal. It’s demonstrating, with evidence, that we understand the risks and can control them. Every agent that escapes its boundary strengthens the case for slowing down; the Hugging Face incident, which occurred before Nvidia acquired Hugging Face, is one example. Every well-contained failure strengthens the case for moving forward. Security isn’t a drag on AI adoption; it’s what makes adoption possible. Companies won’t hand real work to agents they can’t trust, and they must engineer trust.

Nvidia still has work to do. It needs to publish performance data, hand over OpenShell to neutral governance, bring the rest of the frontier labs on board, and establish itself with security leaders who haven’t previously considered Nvidia a security provider. But with today’s launch, it has moved from talking about agent safety to shipping it. The industry spent the last three years building the AI factory. The next three will be about whether we can safely let it run on its own, and Nvidia has positioned itself as a central part of that answer.

── more in #ai-agents 4 stories · sorted by recency
── more on @nvidia 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/nvidia-built-the-ai-…] indexed:0 read:8min 2026-10-01 · —