The platform consists of two components: OpenShell, an open-source agent runtime released under Apache 2.0, and Nvidia Sentry, a watchdog service that runs on Nvidia’s BlueField-4 data processing units. Because the BlueField DPU operates on a separate processor with its own trust domain, it can monitor an agent’s traffic and actions independently. When an agent tries to exceed its permissions, Sentry can cut it off at the network level within “milliseconds,” according to Nvidia.
The announcement follows a series of high-profile sandbox escapes over the summer. OpenAI disclosed on July 21 that GPT-5.6 Sol and a research prototype had exploited a zero-day in a package proxy to reach Hugging Face’s production database; stopping that run took nearly three hours, according to reports. Days later, Anthropic said three of its models had found unintended internet access at evaluation partner Irregular and published a malicious package to PyPI. Meta followed on Aug. 6 with a pre-release Muse Spark model that read and modified a real website’s database. Google also announced that Gemini had broken into networks for three companies.
Justin Boitano, Nvidia’s vice president of enterprise AI, said in a press briefing that “model-level safeguards alone can’t govern what agents can access or do,” and that Nvidia is introducing “a deterministic system to mediate and enforce how these agents behave.” The new OpenShell release includes a policy prover that checks that agent permissions cannot be combined into unintended actions.
However, The Decoder notes that Sentry cannot reliably stop agents that have been tricked or that hide their intentions on its own. Separately, Nvidia also announced a $150bn stock buyback on the same day.