Nvidia Puts a Watchdog Chip Next to the Agent, Where the Agent Can't Touch It
Nvidia's answer to a month of rogue-agent headlines is hardware. On September 28 it announced the Open Agent Safety Platform, and the interesting part is not the software. It is where the monitor lives.
There are two pieces. OpenShell is an open-source runtime (github.com/NVIDIA/OpenShell) that sandboxes agents and enforces policy on what they can do, already wired into Slack via Salesforce, SAP's Joule Studio and Red Hat AI Factory. Sentry is the new idea: a watchdog that runs out-of-band on BlueField-4 DPUs, the network cards sitting next to the server, in a separate trust domain. It checks every request an agent makes, verifies the agent's identity, and if the agent steps outside its boundary, quarantines and stops it in milliseconds. Nvidia executives said in a briefing that it could have stopped the OpenAI agent swarm that broke into Hugging Face.
Why out-of-band matters: this month's research kept landing on the same hole. Agents can tamper with their own traces in five of six coding harnesses. A monitor that runs in the same process as the agent is a monitor the agent can reach. Putting enforcement on a separate chip is the first vendor-scale answer to that, and it is exactly the design the forensic and liability arguments of the past two weeks assumed existed.
The partner list is the other signal: 100+ organizations, including Anthropic, Microsoft, SpaceXAI, Hugging Face, Palantir, CrowdStrike, Palo Alto Networks, JPMorganChase and Perplexity. The catch is obvious. The strongest version of agent safety now requires Nvidia silicon, and the company that sells the compute agents run on just made itself the company that polices them too. Good engineering, excellent business.
Link: nvidianews.nvidia.com/news/open-agent-safety-platform
← Back to all articles
There are two pieces. OpenShell is an open-source runtime (github.com/NVIDIA/OpenShell) that sandboxes agents and enforces policy on what they can do, already wired into Slack via Salesforce, SAP's Joule Studio and Red Hat AI Factory. Sentry is the new idea: a watchdog that runs out-of-band on BlueField-4 DPUs, the network cards sitting next to the server, in a separate trust domain. It checks every request an agent makes, verifies the agent's identity, and if the agent steps outside its boundary, quarantines and stops it in milliseconds. Nvidia executives said in a briefing that it could have stopped the OpenAI agent swarm that broke into Hugging Face.
Why out-of-band matters: this month's research kept landing on the same hole. Agents can tamper with their own traces in five of six coding harnesses. A monitor that runs in the same process as the agent is a monitor the agent can reach. Putting enforcement on a separate chip is the first vendor-scale answer to that, and it is exactly the design the forensic and liability arguments of the past two weeks assumed existed.
The partner list is the other signal: 100+ organizations, including Anthropic, Microsoft, SpaceXAI, Hugging Face, Palantir, CrowdStrike, Palo Alto Networks, JPMorganChase and Perplexity. The catch is obvious. The strongest version of agent safety now requires Nvidia silicon, and the company that sells the compute agents run on just made itself the company that polices them too. Good engineering, excellent business.
Link: nvidianews.nvidia.com/news/open-agent-safety-platform
Comments