# Adoption Stories

By [DYLIT Chronicles](https://dylit.info/user/dylitmediabuzz)

[AI for All - Beyond the Hype](https://dylit.info/pr/ai-for-all-beyond-the-hype/6a9efac02e92664f4d50cf9d) > [Adoption Stories](https://dylit.info/ch/adoption-stories/6a9efac02e92664f4d50cfca)

NVIDIA Adds a Hardware Watchdog to Keep AI Agents in Bounds What NVIDIA announced NVIDIA announced its Open Agent Safety Platform on September 28, 2026, combining the open-source OpenShell agent runtime with an optional hardware enforcement layer called NVIDIA Sentry. The target is autonomous AI agents, not AI models in general. The launch lands at a tense moment. NVIDIA says the system would have prevented the recent high-profile breach of Hugging Face by OpenAI's AI models. That's the company's own claim, and nobody has tested it independently. NVIDIA says more than 100 organizations are working with the platform's technologies. Layer one: OpenShell, the software boundary OpenShell (Apache 2.0) is an open source secure runtime for executing autonomous AI agents in sandboxed environments with kernel-level isolation. It runs each agent in a sandbox, converts the operator's instructions into a verifiable policy, checks those limits before the agent starts, and keeps enforcing them while it works. Every allow and deny decision gets logged for audit, and before a policy change is approved, OpenShell uses formal verification to flag risky new access, such as reaching a new host with credentials, so those changes wait for human review. It supports agents such as Claude Code, Codex, OpenCode, GitHub Copilot CLI, and OpenClaw. OpenShell isn't brand new. NVIDIA first announced it in March. Layer two: Sentry, the hardware watchdog Sentry is an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs to continuously monitor agent behavior. If an AI agent attempts to move outside its software boundary, Sentry quarantines and stops it in milliseconds. The separation is the point. Placing Sentry on a separate processor, rather than on the CPU or GPU where the agent operates, gives it an isolated view of the agent's activity. In a Vera Rubin POD, each compute tray's BlueField-4 sits on the node's only path to the model. Put together, the chain looks like this. OpenShell sets and enforces the rules from inside the host, and Sentry watches from outside it. Sentry's monitoring and enforcement stay operational even if the host or workload is compromised. It relies on NVIDIA DOCA to correlate agent interactions, policy decisions, and tool access. Integration and who it's for The complete design is optimized for NVIDIA Vera CPU and BlueField DPU-based systems, and also compatible with other hardware. OpenShell works on its own. It can run on supported local, on-premises, cloud, and Kubernetes infrastructure without BlueField-4. The early partners are mostly enterprise. Anthropic's Claude Managed Agents use OpenShell and BlueField integrations to enforce sandbox access control. Canonical, SUSE and Red Hat are integrating the platform into their operating systems, and infrastructure partners include CoreWeave, Nebius, Oracle Cloud Infrastructure and Together AI. SAP is embedding OpenShell inside its Joule Studio runtime. Limitations and open questions The two halves are at very different stages. OpenShell is broadly available through NVIDIA's developer site and GitHub, while Sentry is published as a reference design for partners to turn into products. Analysts at Moor Insights & Strategy note that OpenShell ships as version 0.1.0 and that Sentry has no availability date yet. Pricing isn't confirmed. The performance claims haven't been checked either. No independent benchmark has verified the millisecond quarantine, and detection latency and false-positive rates hadn't appeared in independent evaluations as of launch. Then there's cost. Customers who want both layers of protection will be buying NVIDIA silicon.  
