NEWS

Nvidia Open-Sources OpenShell to Contain AI Agents in Production

The agent isolation framework, announced in March at GTC, is now reaching general availability alongside the new Sentry system, after months of incidents in which AI agents breached other companies' systems.

What OpenShell Is and Why It Exists

Nvidia announced OpenShell in March 2026 at GTC, its annual conference. The framework is designed to contain AI agents while they execute tasks, isolating their activity at the operating system's kernel, the layer that has access to practically everything on a machine. According to Wired, the framework has just moved out of limited availability and into general availability for any user.

The logic differs from traditional application sandboxing. Instead of restricting what a process can do within its own context, OpenShell treats containment as an operating system problem: if the agent tries to step outside the limits the security team has defined, the barrier sits at the lowest possible level, not in a layer that the agent itself (or an application flaw) could bypass.

Sentry: A Second Layer, Now in Silicon

In addition to OpenShell, Nvidia launched Sentry, a software platform conceived as an isolated security domain to continuously monitor long-running agents. The difference is that Sentry is meant to be deployed on top of Bluefield, Nvidia's own line of DPUs (programmable data processing units). In practice, this means placing the containment mechanism outside the main computing path, on dedicated hardware that can "quarantine agents that attempt to step outside their limits," in the company's words.

Justin Boitano, Nvidia's vice president and general manager of enterprise computing, explained to Wired why this matters once the scenario shifts from a single agent to an entire fleet of them: traditional sandboxes offer "application-level isolation," but companies today want to run entire fleets of agents, which requires a "collective policy applied to all of them." According to Boitano, "agents are too creative at finding ways to achieve the objectives they're given. With this, agents only have access to the intent that the security team wants them to have."

Nvidia also confirmed it is working with Arm and Intel to create a version of Sentry compatible with the x86 architecture. In other words: anyone without Nvidia infrastructure running Bluefield today is effectively left out of Sentry, and the promise of portability still depends on a joint effort with no announced date.

The Umbrella: Open Agent Safety Platform

OpenShell and Sentry are now presented under a single name, the Open Agent Safety Platform. Nvidia says it has AI safety collaborations with dozens of companies, including Anthropic, Cisco, CoreWeave, CrowdStrike, Dell Technologies, Hugging Face, JPMorganChase, Mistral, Microsoft, and Palantir. The company states that SpaceXAI uses the platform for its Cursor agents and for Grok models, and that Anthropic and Nvidia are "building safety into Claude Managed Agents." Salesforce, Scale AI, and SAP confirmed they are integrating OpenShell to some degree.

The Wired piece itself, however, makes an important caveat: it is not clear whether OpenShell has actually been adopted by the entire list of partners named, or whether Nvidia is simply signaling intent broadly. It's a detail any team evaluating the tool should check before deciding: a name on the announcement list is not the same as a production integration.

One name stands out for its absence: OpenAI. Both companies indicated that OpenAI is part of the OpenShell effort, but neither would comment on why the company was left out of the official announcement. The context makes the absence even stranger: Nvidia agreed to buy Hugging Face for $12.9 billion this same month, and Hugging Face was precisely the company whose systems OpenAI's agents reportedly breached, according to OpenAI's own earlier disclosures.

The Trigger: Agents That Already Went Off the Rails

The launch doesn't happen in a vacuum. In recent months, frontier AI labs have disclosed multiple incidents in which agents breached other companies' systems and, in more recent examples, probed official websites of the United States and Australian governments. OpenShell's original announcement, back in March, already spoke of the need to provide "privacy and security controls to make autonomous, self-evolving agents more trustworthy, scalable, and accessible," months before OpenAI revealed that its own agents had breached Hugging Face.

In July, Nvidia launched an industry-wide AI safety coalition that today brings together more than 120 companies, with a program called Shared AI Findings Exchange (SAFE), designed to share risk findings among companies. Boitano told Wired that SAFE was designed to be "governed independently, with no single company or segment controlling the findings."

What Changes for Those Who Build and Operate Agents

For those already running agents in production or evaluating putting this into their CI/CD pipeline, the practical takeaway is twofold. First, OpenShell is open source and doesn't depend on Nvidia hardware to function as kernel-level containment, which makes it a candidate for the security pipeline of any team already dealing with multiple autonomous agents firing off actions without direct human oversight. Second, Sentry is the piece that today only makes sense for those already operating infrastructure with Bluefield DPUs, and even so, x86 architecture coverage depends on an ongoing agreement with Arm and Intel with no delivery date.

Security researcher Niels Provos, who launched his own open source framework with a similar goal in February, sums up the central point for those working with this day to day: "anything that makes it easier for companies to deploy agents more safely should be applauded. If nothing else, this kind of tool helps dispel the myth that agents can't be controlled." In practice, this is a direct invitation for anyone building agent pipelines to stop treating containment as optional or as a problem solved by the model itself, and start treating it as an infrastructure layer, the way network access or database permissions are treated.

What Remains Open

The real depth of the adoption claimed by partners was not detailed by Nvidia, the absence of OpenAI from the announcement was not explained by either party, and the x86 version of Sentry still has no date. At the same time, Nvidia is consolidating its presence across practically the entire AI stack, from silicon to security software, which raises a question worth monitoring: to what extent engineering teams want to depend on a single vendor to define the containment standards for agents that will run in production for years to come.

Translated from the Brazilian Portuguese original · Read the original