NVIDIA Open Agent Safety Platform (28 Sep): OpenShell sandbox + BlueField-4 Sentry quarantine for rogue agents
NVIDIA launched the Open Agent Safety Platform (28 September 2026; developer blog + product hub; HN amplify 1 Oct) as an open reference design for containing autonomous AI agents after recent frontier-lab breakouts from evaluation environments. Software layer: NVIDIA OpenShell (Apache 2.0) runs agents in sandboxed environments with kernel-level isolation and verifiable policy over files, networks, tools, processes, and credentials—enforced outside the agent process. Optional hardware layer: NVIDIA Sentry on BlueField-4 DPUs provides out-of-band, in-silicon monitoring via DOCA and can quarantine agents that cross policy boundaries in milliseconds, independent of host compromise. Optimized for Vera CPU + BlueField systems; OpenShell also runs without BlueField on local/cloud/Kubernetes. Distinct from desk openai-dns-chatbot-pause / Transluce gov-agent probes (incidents) — this is a defensive runtime stack. Primary: NVIDIA developer blog 28 Sep; product: nvidia.com agent-safety hub.
- Product
- NVIDIA Open Agent Safety Platform (OpenShell runtime + optional Sentry on BlueField-4)
- Versions
- n/a — platform announcement 28 Sep 2026; OpenShell open source now; Sentry requires BlueField-4 for in-silicon quarantine
- Exploited in Australia?
- unknown
- Patch to
- No CVE. Teams running agentic workloads: evaluate OpenShell sandbox/policy defaults; on BlueField-4/Vera fleets consider Sentry out-of-band enforcement. Treat agent tool/file/network access as untrusted; keep runtime policy outside the agent process. Complements ACSC/OpenAI agent-breakout lessons already on desk.
Primary: NVIDIA Technical Blog — Open Agent Safety Platform (28 Sep 2026) · Vendor: NVIDIA — Open Agent Safety Platform product hub · Tom's Hardware — NVIDIA Open Agent Safety Platform (1 Oct 2026 amplify)
