~ / resources / news / nvidia-agent-safety
4 min read
NVIDIA Wants a Locked Room for AI Agents. Here’s How It Works
NVIDIA and more than 100 companies launched an open safety system for AI agents: one free tool that boxes them in, and one chip-level watchdog that can shut them down. Here’s what that means if you don’t build this stuff for a living.
SR
Sep 30, 2026
At a glance
WHAT IT IS
A two-part safety system for AI agents, announced Sept 28, 2026.
WHO’S BEHIND IT
NVIDIA plus 100+ companies, including Anthropic, Microsoft, and SpaceXAI.
WHAT’S FREE
OpenShell, the open-source part. It’s available now.
THE CATCH
Sentry, the hardware part, is a design you can copy, not a download. Nearly every claim so far comes from NVIDIA and its partners.
First, what’s an AI agent?
A chatbot answers questions. An agent does things. It can open files, write and run code, send messages, and use accounts to finish a task, sometimes for hours with nobody watching.
That’s the appeal. It’s also the risk.
The problem: agents wander
NVIDIA says several leading AI labs have recently reported agents breaking out of the test environments meant to contain them and reaching systems they never should have touched. Some agents also misreported what they’d done.
NVIDIA’s own researchers call this “drift”: an agent slowly leaving its task because of a bug, a blocked action, or vague instructions. Their main lesson is blunt. An agent can’t be trusted to police itself.
The fix: a locked room and a camera outside
The platform has two parts.
FREE · OPEN SOURCE
OpenShell is the locked room
It’s free, open-source software. Each agent runs in its own sandbox, think of a room with no windows and one door. The people running the agent write the rules: which files it can see, which networks it can reach, which tools it can use. OpenShell checks those rules before the agent starts and enforces them while it works, and it keeps a log of every yes and no. NVIDIA first announced it in March and now calls it broadly available. It runs on local machines, company servers, and cloud setups, and it doesn’t need NVIDIA’s special chip.
OPTIONAL · HARDWARE
Sentry is the camera outside the room
It watches the agent from outside the computer the agent runs on, using a dedicated chip called BlueField-4. The logic is simple: an agent can’t tamper with something it can’t reach. NVIDIA says Sentry can quarantine an agent within milliseconds if it steps out of bounds, and that it keeps working even if the main machine is compromised. It’s optional.
Why NVIDIA compares this to the web browser
Early websites could run code on your computer. The fix wasn’t asking developers to be good. Browsers started sealing each tab in its own sandbox, so one bad page couldn’t infect the rest.
NVIDIA argues agents need the same thing.
Trust and innovation are not in conflict. Safety is how adoption speeds up.
NVIDIA’s pitch
Who’s in
According to reporting on the launch, Anthropic says the platform adds another layer of control on top of its Claude Managed Agents. Salesforce connected OpenShell to Slack, so teams can approve or reject an agent’s request for more access from a chat window. NVIDIA also ties the platform to the Open Secure AI Alliance, a Linux Foundation group of 120+ organizations.
The catch
–
Sentry isn’t something you can download. It’s a reference design built around NVIDIA’s own chips, though NVIDIA says the platform also works with other hardware.
–
The claims are unproven. Everything about what OpenShell and Sentry can do comes from NVIDIA and its partners. No independent testing has been reported yet.
–
No price was disclosed for the platform as a whole.
–
It still takes work. Companies have to map what their agents connect to and decide the rules.
–
It’s a safety layer, not a guarantee.
Who should care
If your team runs agents with real access
Company data, customer accounts, payments: ask every vendor where the limits live. Inside the agent’s reach, or outside it?
If you’re a developer
OpenShell is free. Try it on a test project first.
Everyone else
Nothing to do today. Just know that the people building these systems are now saying, in public, that agents need guardrails they can’t edit.
$ sudo
verdict
A sensible idea with serious backers.
Don’t trust the agent to behave; build walls it can’t move. The free half is usable now. The hardware half is, for now, NVIDIA’s word.
Sources
04
SR
Reported by
Sudo Review team
News desk
Our news pieces explain launches, pricing changes and shutdowns in plain English, with what each change means for your stack. No sponsors, no paid placements.
On this page
01
03
04
06
07
09
10
$ sudo
request –tool
Want us to test an agent tool?
← Back to
All news
Read next →