cd /news/ai-agents/nvidia-launches-openshell-an-open-so… · home › topics › ai-agents › article
[ARTICLE · art-140874] src=cryptobriefing.com ↗ pub= topic=ai-agents verified=true sentiment=↑ positive

Nvidia launches OpenShell, an open-source runtime for securing autonomous AI agents

Nvidia announced OpenShell, an open-source runtime for securing autonomous AI agents, at GTC San Jose 2026 under the Apache 2.0 license. OpenShell enforces YAML-defined policies using kernel-level isolation via Landlock LSM and seccomp BPF, supports live policy updates, and logs agent actions in audit trails; its GitHub repository reached 8.6k stars and 1,390 commits as of September 2026. Nvidia secured partnerships with Cisco, SAP, and Cadence for enterprise integration, with hardware support from Dell, HPE, and Lenovo.

by read2 min views1 publishedSep 28, 2026
Nvidia launches OpenShell, an open-source runtime for securing autonomous AI agents
Image: Cryptobriefing (auto-discovered)

The software gives enterprises policy-based controls over AI agents that can execute code, call APIs, and handle sensitive data.

Nvidia has entered the AI security conversation with OpenShell, an open-source runtime designed to keep autonomous AI agents on a leash. Announced at GTC San Jose 2026, the software provides sandboxed execution environments and policy-based controls at the infrastructure level. OpenShell operates under the Apache 2.0 license. As of September 2026, the project’s GitHub repository has accumulated 8.6k stars and 1,390 commits.

What OpenShell actually does #

OpenShell enforces strict rules about what AI agents can and cannot do, defined through flexible YAML policy files. It uses kernel-level isolation via Landlock LSM and seccomp BPF — Linux security mechanisms that restrict what a process can access at the operating system level. Landlock controls filesystem access, while seccomp BPF filters system calls. The runtime also supports live policy updates, allowing administrators to change the rules for an agent without shutting it down. Every action gets logged in comprehensive audit trails. OpenShell integrates with Nvidia’s existing Agent Toolkit and is frequently deployed alongside NemoClaw, Nvidia’s agent orchestration framework.

Enterprise partnerships signal serious ambitions #

Nvidia has secured partnerships with Cisco, SAP, and Cadence to integrate OpenShell into enterprise workflows. On the hardware side, the runtime supports deployment across platforms from Dell, HPE, and Lenovo.

Why this matters now #

Long-running AI agents present a fundamentally different security challenge than traditional software. An AI agent makes decisions, executes code dynamically, calls external APIs, and processes sensitive data — all with a degree of autonomy that makes traditional security models inadequate. OpenShell’s approach enforces policy at the runtime level, letting organizations define precise boundaries and monitor everything the agent does within them.

Disclosure: This article was edited by Diego Almada Lopez. For more information on how we create and review content, see our

Editorial Policy.

── more in #ai-agents 4 stories · sorted by recency
── more on @nvidia 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/nvidia-launches-open…] indexed:0 read:2min 2026-09-28 · —