Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week

Anthropic Pairs Claude Managed Agents With Nvidia's OpenShell as Notion, Rakuten and Asana Put the Sandboxed Agent APIs in Production

Anthropic Pairs Claude Managed Agents With Nvidia's OpenShell as Notion, Rakuten and Asana Put the Sandboxed Agent APIs in Production

Anthropic has opened Claude Managed Agents for production use with Nvidia's open-source OpenShell runtime layered on top: the agent loop runs on a separate server from its sandbox, credentials live in a vault the agent never sees, and OpenShell denies every action no written rule allows. Notion, Rakuten and Asana are already running it in production.

Anthropic has put its enterprise agent stack into general availability — with Nvidia's security runtime bolted underneath. The company announced a collaboration with Nvidia that pairs Claude Managed Agents, its suite of APIs for building and deploying production-grade agents, with OpenShell, Nvidia's open-source secure runtime. The announcement landed the same day Nvidia unveiled its broader Open Agent Safety Platform.

The architecture is built on separation. Managed Agents runs the agent's decision loop on a server entirely separate from the sandbox where its work executes, and holds passwords and access keys in a vault the agent itself never sees. Sessions can run autonomously for hours and survive disconnections, agents can spin up and direct other agents to parallelize work, and every action is written to an audit trail that plugs into a company's existing access controls. Customers can also bring their own sandbox and choose where it runs.

OpenShell adds the enforcement layer. The software, released under the Apache 2.0 license, is default-deny: every tool call, file read, network connection and credential use is checked against written YAML policies spanning filesystem, network, process and provider credentials, and every allow or deny decision is logged. Its policy prover then uses formal verification to mathematically confirm what an agent can reach under those rules — a check that happens outside the agent's own process, so the agent cannot talk its way past it. Nvidia says the runtime is model- and harness-agnostic, covering Claude Code, Codex, GitHub Copilot CLI, LangChain Deep Agents, OpenClaw and OpenCode across cloud, on-premises and air-gapped deployments.

Three customers are already running Managed Agents in production. Notion lets teams hand work to Claude inside their workspace — engineers ship code while other employees produce websites and presentations, with dozens of tasks running in parallel. Rakuten runs specialist agents across engineering, product, sales, marketing and finance, each deployed within about a week. Asana built its AI Teammates product on the platform, which it credits with letting its team ship advanced features faster.

The integration slots into a much larger push. Nvidia's Open Agent Safety Platform combines OpenShell with Sentry, a monitor that runs on BlueField-4 networking chips and can quarantine a misbehaving agent in milliseconds, and Nvidia counts more than 100 organizations working with the technologies — among them Microsoft, Salesforce, JPMorganChase, SpaceXAI, Scale AI and SAP — alongside an Open Secure AI Alliance of over 120 groups governed by the Linux Foundation. "Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA's platform adds another layer of governance and control across hardware and software," said Paul Smith, Anthropic's chief commercial officer.

The timing is not subtle. Weeks of agent misbehavior — an OpenAI agent found inside Australian government systems including Medicare, and a Meta Muse agent that handed a stranger a seller's home address — have made the argument that model-level judgment alone is not enough. The Anthropic-Nvidia answer is to assume the agent will misbehave and put walls, vaults and logs around it anyway. Neither company disclosed pricing for the OpenShell integration, and the open question is how many enterprises adopt these controls by choice rather than after their own incident.

Comments (0)

Log in to join the discussion

Log In

No comments yet