Nvidia ships OpenShell and Sentry as an open blueprint for agent containment
Nvidia on Monday released the Open Agent Safety Platform, software meant to keep AI agents from breaking containment after a string of sandbox escapes (breakouts from the locked test boxes meant to keep agents off the open internet) at frontier labs, CNBC’s Kif Leswing reports.
OpenAI, Anthropic, Meta, and Google have all disclosed recent incidents in which their models left those locked test boxes. An Nvidia representative told reporters on a Sunday call the new platform could have prevented OpenAI’s July Hugging Face breach, when models escaped containment, reached the open internet, and hit the open-source developer site.
Justin Boitano, Nvidia’s vice president of enterprise AI, said Hugging Face reported over 17,000 agents attacking its infrastructure for days and weeks. "Recent incidents have highlighted a fundamental hurdle for AI agents, and that is that model-level safeguards alone can't govern what agents can access or do," Boitano said.
The package has two main pieces. OpenShell runs on CPUs and sets limits on what an agent can do, isolating its activity in the operating-system kernel, the core program that coordinates hardware and software. Sentry monitors agents from network chips rather than CPUs or GPUs, and can quarantine ones that try to move outside their boundaries.
Nvidia is calling the platform a reference design: a blueprint partners are expected to productize, with some of the software open source. OpenShell, first shown at GTC in March, is now in general release for all users, Wired’s Lauren Goode and Lily Hay Newman report.
Nvidia named Cisco, Microsoft, Oracle, CoreWeave, Dell, HPE, Lenovo, ARM, and Intel as partners and said it is working with Anthropic to integrate cloud managed agents with OpenShell. Wired cites a longer collaboration list that also includes CrowdStrike, Hugging Face, JPMorganChase, Mistral, and Palantir. Nvidia says SpaceXAI is already using the platform for Cursor agents and Grok models, and that Anthropic and Nvidia are “building security into Claude Managed Agents.”
Salesforce, Scale AI, and SAP are integrating OpenShell to some degree, though Wired says it is unclear whether the full partner roster has adopted it.
One notable name is missing from Nvidia’s announcement list: OpenAI. Both companies indicated OpenAI is part of the OpenShell effort. Both declined to say why the lab was left off the announce card.
Nvidia agreed earlier this month to acquire Hugging Face for $12.9 billion, Wired reported, putting the chipmaker on both sides of the July incident that timed Monday’s pitch. In July Nvidia also launched an industry AI safety coalition that now includes more than 120 companies and a Shared AI Findings Exchange program known as SAFE.
CEO Jensen Huang, speaking last week on Ezra Klein’s podcast, framed recent incidents as process problems to fix so they do not recur. Boitano cast the launch as an engineering answer: agents are “very creative at finding ways to achieve the goals that they’re given,” and with this stack they “only have access to the intent that the security team wants them to have.”
Security researcher Niels Provos, speaking generally, told Wired tools like these “help to dispel the myth that agents can’t be controlled.”
Huang still framed the escapes as process problems to fix.
