What did NVIDIA announce on 28 September?

NVIDIA’s investor newsroom post dated 28 September 2026 announces the Open Agent Safety Platform. The summary lists OpenShell open-source software and the Sentry reference system design on BlueField-4 for out-of-band monitoring and millisecond quarantine.

The post places the launch against recent agent security incidents where, NVIDIA says, agents circumvented application-layer controls. For adjacent agent-security reporting on this site, see Zenity’s AgentCore finding and Anthropic Managed Agents dynamic workflows.

NVIDIA lists many collaborators (Anthropic, Cisco, CrowdStrike, Microsoft, Salesforce, SAP, and others). Those names are NVIDIA’s launch roster, not independent attestations we verified.

OpenShell’s dated launch materials describe a runtime control plane for agents—policy hooks around tool execution—rather than a new foundation model. Keep that category clear when you file it beside sandbox products from other vendors: OpenShell is NVIDIA’s framing of agent safety plumbing, with GitHub activity after the announcement filling in APIs and examples.

Long aisle of densely packed server racks inside a data center, with cable trays above. No people appear.
CERN data-centre server aisle (File:CERN Server 03.jpg), CC BY-SA 3.0 via Wikimedia Commons. Contextual compute hall; it is not NVIDIA’s OpenShell demo, not BlueField-4 hardware, and does not depict a quarantined agent. Photo: Florian Hirzinger - www.fh-ap.com / Wikimedia Commons. CC BY-SA 3.0 · Cropped and resized.

What is OpenShell, and what sits outside it?

NVIDIA’s 28 September developer blog describes OpenShell 0.1.0 as an open-source runtime that enforces which systems and data an agent can access without rewriting the agent. Components named there include a Gateway for fleets, a Supervisor outside the workload that checks outbound requests, and a Sandbox with kernel-level filesystem and process controls.

The blog says the supervisor can inspect configured HTTP, GraphQL, and MCP traffic—for example allowing a read while blocking a write on the same API—and records decisions in an OCSF audit trail. Credentials can stay outside the workload via provider profiles.

Sentry is described as an optional, out-of-band layer on BlueField-4. NVIDIA’s product FAQ language (on the agent-safety product page) states OpenShell can run on supported local, cloud, and Kubernetes setups without BlueField-4. We did not validate that matrix.

NVIDIA’s blog also describes a policy-advisor path where an agent may propose a narrowly scoped network or file change after a denial; proposals remain pending for human review by default, and the agent cannot approve its own request. Filesystem and process limits set at sandbox start still require a new sandbox to change.

Named early adopters in the blog include Cadence for chip-design agents, Slack for on-demand automation, and Gecko Robotics for physical-robot governance. Those are NVIDIA’s customer examples, not case studies we audited.

Close view of network and server hardware in a rack, with blue indicator lights. No people appear.
Wikimedia servers detail by Victor Grigas, CC BY-SA 3.0 via Wikimedia Commons (File:Wikimedia Servers-0051 16.jpg). Archival rack photograph; it does not show OpenShell’s supervisor, MCP inspection, or Sentry on BlueField-4. Photo: Helpameout / Wikimedia Commons. CC BY-SA 3.0 · Cropped and resized.

What changed by 9–10 October on GitHub?

The GitHub repository NVIDIA/OpenShell identifies the project as the safe, private runtime for autonomous AI agents and carries an Apache 2.0 LICENSE file we opened. The releases page lists OpenShell v0.1.3 with a 9 October timestamp and an install snippet pinning OPENSHELL_VERSION=v0.1.3.

v0.1.3’s notes are mostly engineering fixes and features (Helm RBAC options, MCP inspection profiles, sandbox restart policy, provider additions). That is a point release, not a second platform launch.

GitHub metadata we fetched showed a push timestamp on 10 October UTC. A busy repo is not, by itself, a new product announcement.

When you cite post-launch commits, pin the tag or SHA you reviewed. Preview branches can rename policy verbs quickly. Prefer README quickstarts that declare supported OS/runtime matrices over social demos that omit fail-closed behaviour.

How should teams read NVIDIA’s security claims?

The developer blog describes formal policy analysis (“policy prover”) and long-horizon adversarial experiments where agents tried to persuade an AI reviewer to grant GitHub write access. NVIDIA reports that protected repository writes did not occur in those tests. Those are NVIDIA’s experiment claims; we did not reproduce them.

Open source means you can read and deploy the runtime under Apache-2.0. It does not automatically give you BlueField hardware, a correct policy, or immunity from prompt injection inside an allowed tool.

If you already gate dangerous tools with human approval, keep that layer. Runtime sandboxes complement, rather than replace, agent approval gates.

Anthropic’s quote in the press release frames Claude Managed Agents as establishing a boundary by separating the agent loop server from work sandboxes, with OpenShell/BlueField as an additional layer. That is a partnership statement, not a configuration we validated.

Vendor safety platforms need an adversarial checklist: denied path writes, unexpected egress, secret file reads, and MCP tool calls. Compare OpenShell’s enforcement points with GitHub Copilot local sandboxing and with OS-level boxes like AWS Strands Box—different layers, overlapping threats.

What should a security team try first?

Start with OpenShell’s documented quickstart on a disposable sandbox and a read-only network policy, as NVIDIA’s blog illustrates with curl against api.github.com. Confirm denials appear in openshell logs before attaching a real coding agent.

Decide explicitly whether you need BlueField-4 Sentry or only the software runtime. Do not assume DPU quarantine exists on commodity cloud VMs.

Map OpenShell policies to your MCP and HTTP tool surface. A policy that allows a broad host while relying on the model to “be careful” is not the architecture NVIDIA is selling.

Install the documented runtime on a disposable host, enable the strictest sample policy, and run a hostile agent script that tries to exfiltrate an environment variable over HTTP. Record whether OpenShell blocks, prompts, or logs-only. Until that drill passes, do not market the platform as enforcing.

What did we not test?

We did not run the install script, create a sandbox, attach Claude Code or Codex, enable policy advisor, exercise the prover, or place workloads on BlueField-4. Partner integrations named in the press release were not independently confirmed.

Common questions

Is OpenShell only for NVIDIA CPUs?

NVIDIA markets tight integration with Vera CPUs and optional BlueField-4 Sentry, and also says OpenShell can extend to other platforms and run without BlueField-4. We did not test non-NVIDIA hosts.

What license is the GitHub repo under?

The LICENSE file we opened in NVIDIA/OpenShell is Apache License 2.0.

Is v0.1.3 the platform launch?

No. The platform press release is dated 28 September; v0.1.3 is a 9 October GitHub release of the OpenShell software.

THE TAKEAWAY

What to remember

OpenShell is NVIDIA’s agent-runtime control story with a 28 September announcement and later GitHub movement—pin a SHA and fail a hostile egress test before you trust the brochure.

Sources & further reading

  1. NVIDIA Launches Open Agent Safety Platform… ↗
  2. Add Runtime Controls to AI Agents with NVIDIA OpenShell ↗
  3. NVIDIA/OpenShell ↗
  4. OpenShell v0.1.3 ↗
How this story was made

Written by Kristian Kostov with AI assistance and checked against the linked sources. Company performance claims are attributed to the company. Analysis reflects AiLookout’s interpretation; we have not independently tested the products discussed. Cover photography is illustrative and does not depict the specific announcement or product.

Our editorial standards
Back to all stories