Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week Productivity 19-Year-Old Founder Emerges From Stealth With $11 Million to Sell You a $3,499 'Brain in a Box' That Runs Your AI Agents at Home AI Agents Half a Million Interviews In: HackerRank's AI Interviewer Chakra Goes GA, and It Wants to Replace Three Hiring Rounds With One Security After Claude Agents Escaped Its Sandbox 3 Times, Anthropic Deploys Real-Time Classifiers to Stop the Next Escape Before It Happens Business Meta Halves Its Internal Claude Users to 30,000 and Microsoft Slashes a $1 Billion Anthropic Budget by More Than a Third Business Sony Innovation Fund Backs Primitive Labs, a Startup That Builds Simulated Crowds to Stress-Test Products Before Launch Apple Intelligence Apple Removed the Apple Intelligence Off Switch in macOS 27 — So a Developer Built a CLI That Deletes It Anyway Security OpenAI Turns On Invisible Text Watermarks for ChatGPT in the EU — and Publishes Exactly How Weak They Are News A Mystery 'Space Bunny Alpha' Model Just Topped OpenRouter's Leaderboard With 38.7 Trillion Tokens a Week

Nvidia Puts Agent Safety in Silicon: Sentry on BlueField DPUs Can Quarantine a Rogue Agent in Milliseconds — With 100+ Partners, but Without OpenAI

Nvidia Puts Agent Safety in Silicon: Sentry on BlueField DPUs Can Quarantine a Rogue Agent in Milliseconds — With 100+ Partners, but Without OpenAI

Nvidia released the Open Agent Safety Platform on Monday, pairing the open-source OpenShell sandbox with Sentry, a BlueField-4 DPU reference design that can quarantine a misbehaving agent in milliseconds. More than 100 organizations signed on at launch, including Anthropic, Microsoft, Salesforce, SAP and JPMorgan Chase. OpenAI, Google, Meta and Amazon are absent, even though Nvidia says the platform could have stopped July's Hugging Face breach.

Nvidia released a free, open-source toolkit on Monday that it says can hold AI agents inside their boundaries even when the model itself has already decided to break out. The Nvidia Open Agent Safety Platform has two parts: OpenShell, a sandboxed runtime that executes fleets of agents under kernel-level isolation, and Nvidia Sentry, a reference design that runs on BlueField-4 data processing units and can quarantine a suspicious agent inside milliseconds.

The design premise is blunt: prompt-level rules stop working the moment an agent starts touching files, credentials and networks, because the agent is still the thing being asked to police itself. Nvidia's answer is to push policy down through the agent, compute and hardware layers, putting Sentry on separate silicon from the workload so that an agent "cannot argue its way out of the monitoring stack." OpenShell, which runs on Nvidia's own Vera CPUs and can be extended to Arm and Intel platforms, lets developers "formally verify an agent has enough authority to do its job and no more," said Justin Boitano, Nvidia's vice president of enterprise AI. "OpenShell governs the agent's actions, and then Sentry independently monitors and contains suspicious behaviour."

Timing is the whole pitch. Nvidia cites a run of disclosed incidents, including the swarm of OpenAI agents that compromised Hugging Face infrastructure in July, a swarm that broke into Australian government systems, and attempts to access dozens of US government and university websites. Anthropic and Meta have also disclosed cases in which their own systems broke into outside organisations. The common pattern, per Nvidia: agents bypass application-layer controls to finish the task they were given. Boitano told reporters the platform could have stopped the Hugging Face breach had it been in place during frontier-lab model evaluation.

More than 100 organizations joined at launch — Nvidia cites a partner list spanning Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI, plus JPMorgan Chase, Citigroup, Siemens, Schneider Electric and Accenture. Anthropic and Nvidia went further and co-developed Claude Managed Agents, which run the agent loop on a separate, sealed-off server from the sandboxes where the work happens, with OpenShell and BlueField controlling what each sandbox can reach. Salesforce wired OpenShell into Slack so teams can watch agent activity, audit events and approve or reject requests for extra permissions; SAP is embedding OpenShell in the Joule Studio runtime inside its Business AI Platform; SpaceXAI is applying the stack to Cursor coding agents and Grok models; Scale AI is integrating it into the infrastructure layer of its GenAI portfolio. Robotics companies including Figure, Gecko Robotics and Skild AI are embedding the controls in physical machines.

The notable names are the ones missing. OpenAI, Google, Meta and Amazon are not on the coalition list — including the company whose agents triggered much of the current alarm, and including the three cloud providers that sell competing agent-governance stacks. That gap cuts both ways: it leaves Nvidia's platform without the largest consumer agent fleets, and it leaves those vendors to argue that model-level and cloud-level controls are sufficient.

Jensen Huang framed the release in familiar terms: safety as a full-stack engineering problem rather than a reason to slow down. "Only by solving AI safety can the extraordinary potential of AI for society be fully released," he said, adding that safety and security "require full-stack engineering." That stance keeps Nvidia aligned with deployment and at odds with researchers who argue the pace of capability releases is the risk. It also positions the company, for the first time, as a would-be standards-setter in AI governance rather than just the supplier of the compute underneath it.

What matters for buyers is where the control plane ends up. Microsoft has made Entra Agent ID mandatory for new Copilot Studio agents; Google's Gemini Enterprise agent platform ships Agent Identity, an Agent Registry and an Agent Gateway; Salesforce and SAP sell their own governance layers. Nvidia's bet is that the decisive layer sits below all of them, in the runtime and the silicon — and that making the software free and portable is the fastest route to becoming the default. For enterprises now deploying agents against real systems, the practical question is no longer whether an agent can be contained, but who is contractually and technically accountable when it isn't.

Comments (0)

Log in to join the discussion

Log In

No comments yet