Nvidia’s Open Agent Safety Platform moves the agent limit off the model and into silicon — but the portable half and the enforcing half are not the same component.
Every quotation below is from NVIDIA’s own press release of 28 September 2026, including the statements attributed to Anthropic, SpaceXAI and Scale AI. The observation that the open component and the enforcing component are not the same component is a reading of what that release states: it describes OpenShell as open source and extensible to Arm and Intel, and it makes no openness or portability claim for Sentry either way. Two counts in the release are kept separate here: over 100 organisations working with the platform’s technologies, and over 120 organisations initiating the Open Secure AI Alliance. The release contains no latency figure, no benchmark, no error rate and no price. Nothing here is investment advice.
What Happened
On September 28, 2026, Nvidia announced what it calls the Open Agent Safety Platform, a framework designed to enforce boundaries on AI agents not through the model itself but through dedicated silicon. The release’s own language is precise: “Sentry provides in-silicon security enforcement, meaning that if an AI agent attempts to move outside its software boundary, Sentry quarantines and stops it in milliseconds.” Sentry runs on BlueField-4 DPUs and, per the release, “continuously monitors agent activity and enforces security policies independently in silicon.” The word independently is doing structural work: this is a separate processor watching the agent, not a model preference that can be argued away.
The named stack has four components. OpenShell is the secure runtime — the release describes it as open source software that can be extended to work with third-party compute platforms, including those from Arm and Intel, and it is broadly available now through Nvidia’s developer resources page and GitHub. Sentry is the out-of-band watchdog that performs the actual enforcement. DOCA handles inspection and enforcement logic. The Vera CPU and BlueField-4 DPU are the underlying hardware. The release names no licence for OpenShell.
Alongside the platform, Nvidia announced the Open Secure AI Alliance, governed by the Linux Foundation, which counts over 120 leading organizations among its initiators. That is a distinct population from the over 100 organizations described as working with the platform’s technologies — the release lists Anthropic, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow, and SpaceXAI among that second group. Two counts, two different things: merging them into one number misreads the release.
The key insight: The release’s own asymmetry is the story. OpenShell — the portable, open-source runtime — extends to Arm and Intel by Nvidia’s explicit description. Sentry — the component that actually stops an agent — runs on BlueField-4 DPUs, and the release makes no openness claim and no portability claim for it at all. The portable component and the enforcing component are not the same thing.

The Structural Read
The notable thing here is not that a chip company wants safety in the chip. It is that the model makers quoted in Nvidia’s own release agree the model is the wrong place for the limit. Mike Nicolls, president at SpaceXAI, states it directly: “As customers rely more on agents to get real work done, safety should be enforced outside the model by additional controls the agent can’t get past. Customers should be able to set those limits for Cursor and Grok and trust they will hold.”
Anthropic’s contribution to this release is architectural rather than model-level. Its product Claude Managed Agents — which integrates with Nvidia’s platform and is Anthropic’s own product, not a component of Nvidia’s platform — “establish a security boundary by running the agent loop in a separate server from the sandboxes where their work executes.” Two different companies, two different approaches, same structural argument: the limit has to live somewhere the agent cannot reach.
This publication has covered the same logic arriving from the application layer — a wallet capped to a budget, credentials as a first-class object, an approval gate on publish, send, and spend. Sentry is that argument arriving from underneath. If the control has to hold against the agent itself, a preference the agent can be talked out of is not a control. That observation is anchored only to pieces already published here; no market-size claim follows from it.
Three Implications
The Asymmetry Is a Design Choice Worth Watching
OpenShell’s portability to Arm and Intel lowers the barrier for adoption across the broad developer ecosystem. Sentry’s silence on portability — per a reading of the release’s own wording — means the enforcing component stays tied, at least for now, to BlueField-4 DPUs. Buyers who need the full enforcement capability get to make that pairing explicit in their procurement decisions.
Missing Numbers Are the Risk Buyers Cannot Currently Size
The release promises in-milliseconds quarantine and then provides no latency figure, no benchmark, no false-positive rate, and no price. A control that quarantines a running agent has a real cost when it fires incorrectly. Nothing in the release lets a reader size either the benefit or that cost. Francis deSouza, CEO of Scale AI, describes building systems with “isolation, policy enforcement and auditability built in from the start” — but the numbers to validate that promise remain unpublished. The release itself carries its own caution: “Many of the products and features described herein remain in various stages and will be offered on a when-and-if-available basis.”
The Alliance Count and the Platform Count Are Doing Different Work
Over 100 organizations working with platform technologies and over 120 organizations initiating the Open Secure AI Alliance are separate populations counted for separate purposes. The alliance, governed by the Linux Foundation, is a standards and research body — its count signals legitimacy for an open governance effort. The platform count signals commercial traction. Treating them as one number of 120-plus platform adopters overstates what the release actually claims.
The Bottom Line
Nvidia has built a platform where the open, portable component and the enforcing component are not the same thing — and the release does not bridge that gap. OpenShell travels to Arm and Intel by Nvidia’s own description; Sentry’s portability is simply not addressed. There are no performance numbers, no price, and no availability date for Sentry, only the platform’s own disclaimer that features ship on a when-and-if-available basis. The structural argument underneath — that agent limits must live somewhere the agent cannot reach — is the part the industry is clearly converging on. The hardware-level details of who owns that enforcement layer, and at what cost when it fires incorrectly, are the questions this release leaves open.
Source: Nvidia Newsroom — Open Agent Safety Platform, September 28, 2026
91,000+ executives read Business Engineer for the AI strategy frameworks cited by ChatGPT, Claude, and Perplexity.
Every quotation above is taken from NVIDIA’s own press release of 28 September 2026, including the statements attributed to Mike Nicolls of SpaceXAI, to Anthropic and to Francis deSouza of Scale AI. This publication has read that release directly and has not independently tested any component described in it. The observation that the open component and the enforcing component are not the same component is a reading of what the release states and does not state. The release describes OpenShell as open source software extensible to third-party compute platforms including those from Arm and Intel, and it describes Sentry as running on BlueField-4 DPUs. It makes no openness claim and no portability claim for Sentry in either direction. Nothing above should be read as NVIDIA having called Sentry closed, or as a claim that Sentry could not run on other hardware. Two separate counts appear in the release and are kept separate above: over 100 organisations are described as working with the platform’s technologies, and over 120 leading organisations are described as having initiated the Open Secure AI Alliance, which is governed by the Linux Foundation. Those are different populations counting different things and neither is a count of paying customers. Claude Managed Agents is Anthropic’s own product, described in the release as integrating with NVIDIA’s platform rather than forming part of it. The release names no licence for OpenShell, gives no price for any component, and contains no latency figure, benchmark, accuracy or false-positive rate. OpenShell is described as broadly available; the release states no availability date for Sentry and cautions that many of the products and features it describes remain in various stages and will be offered on a when-and-if-available basis. Nothing above predicts anything about NVIDIA, about its position in silicon, or about whether this approach becomes a standard, and nothing here is investment advice.








