InsightOn.ai

Nvidia / 28 September 2026

Nvidia Puts AI Agent Controls on BlueField Silicon

Nvidia has launched the Open Agent Safety Platform, combining its broadly available OpenShell software with a Sentry reference design that monitors AI agents from a separate processor. OpenShell sets policy boundaries around an agent's access to data and tools. Sentry, running on BlueField-4 data processing units, can detect attempts to cross those boundaries and, Nvidia says, quarantine the agent within milliseconds. “Safety and security require full-stack engineering,” Huang said. The announcement gives that claim a software runtime and a hardware enforcement design.

OpenShell traces agent actions and applies rules while agents run on CPUs. Nvidia says it runs with minimal overhead on Vera, the CPU it has designed for agent workloads. The runtime is open source and can be extended to Arm and Intel platforms, so organizations can start with existing compute and common policy controls. Sentry adds an isolated trust domain on BlueField-4. Nvidia's DOCA software supplies identity checks, telemetry and access policies for application programming interfaces, services and data. The division gives developers a portable entry point while defining a particular role for Nvidia silicon in more demanding installations.

The integration list is more informative than the headline partner count. Anthropic says Claude Managed Agents can add OpenShell and BlueField controls around its agent sandboxes. Salesforce has tied OpenShell to Slack, where teams can inspect agent activity and approve requests for greater access. SAP is embedding the runtime in Joule Studio, and SpaceXAI says it is using the platform with Cursor coding agents and Grok models. These are different routes to enterprise use: model infrastructure, workplace approvals, business applications and coding workflows.

Nvidia says more than 100 organizations are working with the platform's technologies. Red Hat is running OpenShell and DOCA on its AI Factory with Nvidia; Figure, Gecko Robotics and Skild AI are building with OpenShell for machines that act in the physical world. Citi and JPMorganChase are among financial groups collaborating on shared open source agent safety technologies. That span gives the runtime multiple distribution channels, though the named relationships range from integrations to collaborative work. It also puts policy and audit requirements into computing choices made well before a customer selects a particular GPU cluster.

The commercial path differs by layer. OpenShell can spread across mixed CPU estates and establish a familiar policy model. Sentry could make BlueField-4 relevant wherever independent enforcement is required, while Vera's reported efficiency gives Nvidia another way to compete for agent hosts. In each case the platform inserts Nvidia into an architectural decision about how agents are governed, a decision that could shape hardware and software procurement across enterprise fleets.

Analysis

The Slack and SAP integrations give OpenShell access to everyday approval and business workflows, while Anthropic's sandbox integration reaches the agent execution layer. Nvidia's strategic prize is to make BlueField-4 the independent enforcement point when those distributed controls are assembled into production systems.