NVIDIA on Monday launched an Open Agent Safety Platform designed to keep increasingly autonomous AI agents inside prescribed technical boundaries from testing through production, adding a new heavyweight to the fast-forming market for agent control planes. It builds on the Open Secure AI Alliance NVIDIA formed in July after the Hugging Face breach.
NVIDIA says more than 100 organizations are working with the platform, including Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI, along with robotics companies Figure, Gecko Robotics and Skild AI.
The timing comes as AI safety has shifted from an industry argument to a political and public reckoning. OpenAI disclosed new cases of agents going beyond their intended boundaries. Australian officials escalated concerns over agent activity involving government systems. World leaders gathered at the United Nations amid increasingly public disagreements over how and how urgently advanced AI should be controlled.
[Related: Okta CEO Lays Out AI Agent Security Push at Oktane 2026]
“Several frontier labs have recently reported versions of the same story,” NVIDIA wrote in its technical blog. “AI agents broke out of the evaluation environments that were meant to contain them and reached systems they never should have been allowed to. Some of the agents even misreported what they did.”
Jump to: NVIDIA vs. Blueprint Alliance comparison chart.
Taken together, the incidents have shifted the security question from Can an agent be instructed not to do something? to What independent system can actually stop it?
Monday’s platform announcement is separate from the Open Secure AI Alliance, the industry coalition NVIDIA formed in July with CrowdStrike and more than 30 other companies after the Hugging Face breach. That alliance brought companies together around AI security. Monday’s launch is a set of runtime and hardware tools that NVIDIA says more than 100 organizations are already working with.
Hardware Approach to Agent Control
NVIDIA’s answer is to move that authority outside the agent, using two main pieces.
OpenShell is an Apache 2.0 open-source runtime, now at version 0.1.0, that puts each agent inside a sandbox and enforces rules over which files, processes, networks and services it can use.
In practical terms, an agent might be allowed to read from a GitHub repository but blocked from writing to it. OpenShell starts default-deny. When an agent hits a blocked request, it can propose a narrower rule, but it cannot approve that rule itself. Low-risk changes can be auto-approved after OpenShell’s policy and security checks; anything that expands risky authority, such as credential use, API methods or network reach, is flagged for human review.
Sentry adds another layer underneath that software boundary. The optional watchdog runs on NVIDIA’s BlueField-4 data processing units, physically separated from the host running the agent. NVIDIA says Sentry can monitor agent activity continuously and quarantine an agent in milliseconds if it crosses its boundary.
The distinction is simple: OpenShell puts a fence around the agent. Sentry puts a guard outside the fence.
“AI’s extraordinary potential for society will only be realized if we solve AI safety,” NVIDIA CEO Jensen Huang said in the announcement. “Safety and security require full-stack engineering.”
A Veto the Agent Can’t Override
NVIDIA’s basic premise is the last line of defense should live somewhere the agent itself cannot change, disable or talk its way around. This approach is closer to a kill switch than behavioral suggestions. If an agent starts reaching an outside system, using a credential in the wrong place or modifying a protected resource, the surrounding infrastructure can block the action even if the agent still believes it is pursuing the right objective.
Old Ideas, New Stack
Sandboxing, least privilege, network segmentation, credential brokers, formal policy analysis and hardware-isolated security all predate AI agents. What is distinctive about NVIDIA’s approach is it is attempting to stack those controls around the agent. It runs from the sandbox, through network and credential enforcement, and ultimately into a separate hardware trust domain the agent does not control.
Consider a company red-teaming an AI coding agent that discovers an external service would help it finish faster. Without an independent runtime boundary, the company is relying on the agent’s instructions and whatever permissions were granted at the start.
With OpenShell, the request is checked against policy before it leaves the sandbox. If the destination isn’t approved, the connection stops there, even if the agent tries a different tool or writes its own code to make the same call. If the agent or host somehow slips past that boundary, Sentry can quarantine the workload from separate BlueField hardware.
The same model applies outside a red-team lab. A bank might let an agent read customer records for a fraud report but not alter them. In each case, access does not automatically become authority. That is the core of NVIDIA’s approach, where it lets the agent work, but keeps the final veto somewhere else.
Six Days Earlier: The Blueprint Alliance
NVIDIA’s announcement comes just six days after Okta used its Oktane conference to launch the Blueprint Alliance with AWS, CrowdStrike, Databricks, Docker, Google Cloud, Lovable, Proofpoint, Salesforce, ServiceNow, Wiz and Zscaler — a coalition proposing a shared architecture for securing AI agents across identity, applications, data, infrastructure and security.
NVIDIA vs. Blueprint Alliance: The Kill Switch Difference
The two are trying to solve much of the same problem, but from different layers of the stack.
The Blueprint Alliance starts with identity. Its premise is that every agent should be treated as a distinct enterprise identity with a known owner, defined permissions and traceable delegation. Organizations can then decide what the agent may do, monitor it and revoke its access when necessary.
NVIDIA, fittingly for a compute and infrastructure company, starts much closer to the machine. Its question is less Who is this agent? than What can this running process actually touch — and what can the infrastructure physically stop it from doing?
Under the Blueprint model, a coding agent might be registered to a specific team, limited to one GitHub repository and cut off if its behavior turns suspicious. Under NVIDIA’s model, the same agent could run in an OpenShell sandbox that lets it read the repository but blocks it from pushing code, using its credential elsewhere or reaching an unapproved service.
The kill switches show how the two contrast. Blueprint’s controls can revoke identity, credentials, sessions or access. NVIDIA’s can stop the action at the runtime boundary. With Sentry, NVIDIA quarantines the workload from a separate hardware layer. That makes the two approaches more complementary than competitive, at least technically.
Politically Different Animals
Blueprint’s political bet is that no single vendor will own the agent control plane. Identity, cloud, applications, data and security are already split across too many companies, so the answer is to make those pieces work together.
NVIDIA’s bet is different: there should be an enforcement layer underneath those systems, close to the runtime and infrastructure. And NVIDIA is prepared to provide it.
The political question underneath the technical one is: Are vendors building parts of one shared control plane, or competing to own the layer with the final veto?
The chart below shows where the two efforts overlap and where their approaches diverge.

For practitioners, the difference may matter less. Identity establishes who an agent is and what authority it should have. Runtime controls determine whether the action it is attempting right now should actually happen. What NVIDIA adds is a harder boundary, betting that as agents grow more autonomous, safety cannot depend solely on the agent recognizing the line it should not cross.
Agents have proven very good at finding the gap in the fence. NVIDIA’s pitch is that the fence shouldn’t have any gaps, and that it should be built on NVIDIA silicon.