What happened
On 28 September 2026, NVIDIA announced the Open Agent Safety Platform: NVIDIA OpenShell (Apache 2.0 open-source secure runtime providing kernel-level isolation, verifiable policy, and action tracing for agents running on NVIDIA Vera CPUs, extendable to Arm/Intel) and NVIDIA Sentry, an out-of-band watchdog running on BlueField-4 DPUs that quarantines agents leaving their boundary in milliseconds using DOCA-based in-silicon threat detection, attested telemetry, identity verification, and granular zero-trust access policy. NVIDIA concurrently published the developer-blog engineering guidance 'Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring' setting out five core principles (verifiable policy, out-of-band enforcement, the model path as control point/kill switch, scaling authority with inspectability of reasoning, shared-responsibility model) and a three-layer app/runtime/infrastructure architecture. Partners include Anthropic (Claude Managed Agents integration), Cisco, Microsoft, Oracle, CrowdStrike, JPMorganChase, Palantir, Palo Alto Networks, Scale AI, ServiceNow, and others.
Why it matters
This is a materially new approach to agent security: enforcing boundaries outside the model's execution environment and in hardware, making policy verifiable before run, and giving defenders a kill switch at the model-call path. It responds directly to the 2026 breakout incidents (including the reported Hugging Face exposure) and defines an engineering reference pattern that rivals and standards bodies (CSA is already mapping it to AARM) will build on. Even as vendor output, its open-source runtime and published principles now function as de-facto guidance for agentic-AI control at scale.
Action needed
Evaluate OpenShell/Sentry (or equivalent out-of-band enforcement) for long-running agent workloads; adopt the five principles (out-of-band enforcement, model-path kill switch, policy verification, inspectable reasoning) in agent security architecture decisions; treat agent runtime policy and wearability as design-time requirements rather than after-the-fact monitoring.