Nvidia CEO Huang unveils new software that works as a browser for AI agents Nvidia CEO Jensen Huang launched the Open Agent Safety Platform on September 28, a two-part system combining the open-source Apache 2.0 runtime OpenShell with a hardware-level monitoring layer called Sentry to sandbox autonomous AI agents. Nvidia said OpenShell introduces minimal overhead on its Vera CPUs, and more than 100 enterprise software firms including Adobe, Salesforce, SAP, Microsoft, Red Hat and Anthropic had begun integrating Nvidia's agentic platform tools by September. Huang said "AI's extraordinary potential for society will only be realized if we solve AI safety. Nvidia CEO Huang unveils new software that works as a browser for AI agents The Open Agent Safety Platform introduces sandboxed environments for autonomous AI, drawing on browser-tab architecture to keep agents in check. Jensen Huang wants AI agents to run the way your Chrome tabs do: isolated, policy-bound, and easy to kill when they misbehave. On September 28, Nvidia https://cryptobriefing.com/markets/nvidia/ ’s CEO launched the Open Agent Safety Platform, a two-part system combining an open-source runtime called OpenShell with a hardware-level monitoring layer named Sentry. Together, they create what Huang is framing as a “browser for agents,” a secure environment where autonomous AI can operate without going rogue. As enterprises rush to deploy AI agents that can code, research, monitor cybersecurity threats, and run complex operations for hours or days at a stretch, someone needs to build the guardrails. Nvidia is betting that someone should be Nvidia. How the browser metaphor actually works OpenShell runs AI agents inside sandboxed execution environments, each one isolated like a browser tab. If one agent crashes or starts behaving outside its policy boundaries, the others keep running. The system enforces strict policy adherence, maintains audit trails, and can push policy updates to running agents without shutting them down. Sentry sits underneath as the hardware-level enforcer, monitoring agent behavior and stepping in when software-layer controls aren’t enough. Nvidia claims OpenShell introduces minimal overhead on its Vera CPUs, meaning enterprises won’t pay a steep performance tax for the added safety layers. The runtime ships under an Apache 2.0 license, making it freely available for developers and organizations to inspect, modify, and deploy. “AI’s extraordinary potential for society will only be realized if we solve AI safety,” Huang said during the announcement. The enterprise ecosystem taking shape The Open Agent Safety Platform didn’t appear in a vacuum. Nvidia spent much of 2026 assembling the pieces. Earlier in the year, around March and April, the company released its Agent Toolkit, a package that included the Nemotron 3 Ultra model with 550 billion parameters, purpose-built for the kind of long-running agent workflows that enterprise customers care about. AI, tech, and the markets they move—in one daily briefing. Daily. Free. Join 34,000+ readers across crypto, finance, and policy. That toolkit also bundled skills libraries, pre-built capabilities that agents can draw on rather than learning from scratch. By September, over 100 enterprise software firms had started integrating Nvidia’s agentic platform tools into their own products. The roster reads like a who’s-who of enterprise tech: Adobe https://cryptobriefing.com/markets/adobe/ , Salesforce https://cryptobriefing.com/markets/salesforce/ , SAP, Microsoft https://cryptobriefing.com/markets/microsoft/ , and Red Hat are all contributing to or building on the stack. Anthropic https://cryptobriefing.com/markets/anthropic/ , the safety-focused AI lab behind Claude, is also listed among the partners. Why sandboxing agents is harder than sandboxing web pages These agents are designed to be “long-running” and “self-evolving,” according to Nvidia’s description. They can operate for hours or days, make decisions, call external APIs, modify their own behavior based on new information, and interact with critical business systems. That’s precisely why Nvidia paired the software-layer sandboxing of OpenShell with Sentry’s hardware-level enforcement. Software guardrails can be circumvented by sufficiently capable agents. Hardware-level monitoring adds a second line of defense that doesn’t depend on the agent’s cooperation. The platform targets four primary domains: coding, research, cybersecurity, and operations. Each comes with its own risk profile. An agent writing code might introduce vulnerabilities. An agent running cybersecurity operations has, by definition, access to sensitive systems. The audit trail functionality becomes critical here, giving enterprises a forensic record of every decision an agent made and why. Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our Editorial Policy https://cryptobriefing.com/editorial-policy/ .