Answer in brief
OpenShell sets an agent's runtime boundaries and Sentry is intended to watch from separate hardware. The architecture is concrete; its real-world protection still needs deployment evidence.
Two layers around a working agent
NVIDIA announced the Open Agent Safety Platform on 28 September as a combination of OpenShell software and a Sentry reference design. OpenShell is intended to put an enforceable boundary around an agent while it runs, including its access to files, credentials and external services. NVIDIA's technical explanation describes Sentry as a separate watcher on BlueField-4 hardware. Axios reported the launch against rising concern about agents that take actions outside their assigned scope. The specific design matters because a verbal instruction to an agent is weaker than a technical limit on what its process can reach.
The claimed enforcement path
According to NVIDIA, OpenShell applies rules outside the agent's own process so a generated instruction cannot simply rewrite its permissions. The company says Sentry monitors from an out-of-band domain and can quarantine an agent crossing its boundaries in milliseconds. That timing is a vendor claim about the reference design, not a universal measured response for every installation. The technical blog describes policy verification and visibility across agent, runtime and infrastructure layers. Teams will need to establish whether their chosen agent, model endpoint and tool connections are actually routed through those controls.
Availability is not the same as assurance
NVIDIA says OpenShell software is available and can be extended beyond its own CPUs, while Sentry relies on the BlueField-4 hardware path. The company names many partners, but collaboration, support or early adoption does not certify each partner's deployment. A useful security review should include a denied network destination, an attempted credential read, a tool that returns hostile instructions and a monitor outage. It should record not only whether a request is blocked, but who receives the alert, whether the agent can resume, and what evidence remains for investigation.
What purchasers can ask for
Before adopting the stack, request a clear policy map: permitted destinations, secret handling, exception procedure, audit-log retention and the administrator who can change rules. Run tests on the actual infrastructure rather than assuming the reference design carries over unchanged. Independent evaluation of latency, false positives and bypass resistance would help distinguish promising engineering from proven protection. The 30 September evidence cutoff supports the launch, components and NVIDIA's stated performance; it does not establish that every agent using the platform is contained under real attack.
Questions and answers
What is OpenShell?
NVIDIA describes it as an open-source runtime that isolates agents and applies policies to the systems, files, credentials and network services they can use.
What does Sentry add?
The Sentry reference design places monitoring and enforcement on a separate BlueField-4 data-processing unit. NVIDIA says it can stop out-of-bound activity quickly.
Does this prove agents are safe?
No. The announcement describes an architecture and vendor claims. Assurance requires tests of a particular deployment, policy configuration and response to failures.
