Skip to content
Data-center aisle with security monitoring screens

TL;DR: On 28 September 2026 Nvidia announced OpenShell, open-source agent runtime security on Vera CPUs and extendable to Arm and Intel, plus Sentry, a BlueField-4 DPU watchdog reference design that can quarantine agents in milliseconds. Partners listed include Anthropic, Microsoft, Salesforce, SAP, JPMorganChase, Hugging Face, and SpaceXAI. OpenAI, Google, Meta, and Amazon are not on that partner list. OpenShell is on GitHub. Sentry is a reference design, not a priced product with a public ship date. This is not a law and not a guarantee against every rogue agent.

Status note: Checked 6 October 2026 against Nvidia's investor-relations press release of 28 September 2026. Partner lists, product packaging, and ship dates for any Sentry-based hardware can still change. Claims below about capabilities track the company release unless noted otherwise.

How we got here

AI agents are software that can take actions on a user's behalf: open files, call APIs, move money, or change cloud settings. As those agents leave chat windows and touch real systems, companies worry less about a wrong answer and more about a wrong action that is hard to reverse.

Most safety talk still sits inside the model: train it to refuse, add policy layers, log prompts. Nvidia's pitch is different. Put a software boundary outside the model, watch what the agent does at runtime, and cut it off in hardware if needed. That is the frame of the 28 September launch.

What OpenShell is supposed to do

OpenShell is the open-source half of the platform. Nvidia describes it as a secure runtime for agents, available on GitHub, running on Vera CPUs and designed so others can extend it to Arm and Intel. The idea is a controlled environment where an agent can be tested and then run with clearer limits on what tools and data it can reach.

In plain terms: the model may still invent a plan, but the runtime decides whether that plan is allowed to touch the network, the filesystem, or a production database. Nvidia is selling the boundary as something engineers can inspect and fork, not a closed black box.

Open source does not mean finished enterprise deployment. Teams still have to integrate OpenShell with their own identity systems, logging, and approval workflows. The release positions OpenShell as available now for builders who want that starting point.

Sentry and the out-of-band watchdog

Sentry is the hardware-leaning half. Nvidia ties it to BlueField-4 data processing units, or DPUs: cards that sit beside the main CPUs and can watch traffic and agent behavior without living inside the same process as the model. The company says a Sentry-style design can quarantine a misbehaving agent in milliseconds.

Important packaging detail: Sentry is described as a reference design, not a standalone product with a public price or ship date in the release. Reference designs show partners how to build; they are not the same as a SKU you can order from a price list tomorrow. Anyone claiming Nvidia "shipped Sentry" as a finished retail product is ahead of what the IR note says.

The out-of-band angle matters for serious readers. If the watchdog lives only inside the same software stack as the agent, a compromised agent might attack the guard. A DPU that can cut network paths or isolate compute from outside that stack is Nvidia's answer to that worry. Whether customers adopt it at scale is a separate question the press release does not settle.

Who is listed, and who is not

Nvidia named a long partner group around the platform. The release includes Anthropic, Microsoft, Salesforce, SAP, JPMorganChase, Hugging Face, SpaceXAI, and others. Those names signal early ecosystem interest: model labs, cloud and enterprise software vendors, a major bank, and the open-model community hub.

OpenAI, Google, Meta, and Amazon do not appear among the partners listed in that Nvidia release. That is an absence from the published list, not a documented refusal or a claim that those companies oppose the idea. Rival stacks and private deals can sit outside a press-release roster. Readers should treat the list as Nvidia's announced collaborators on this day, nothing more.

Where things stand

What is on the record: Nvidia launched an Open Agent Safety Platform pairing open-source OpenShell with a BlueField-4 Sentry reference design, aimed at securing agents from testing through deployment, with OpenShell on GitHub and a named partner set that does not include OpenAI, Google, Meta, or Amazon in the release text.

What is not on the record: a new law, a regulator mandate, a public Sentry product price or general-availability date, or proof that the stack stops every rogue agent in the wild. Hardware quarantine in milliseconds is a vendor claim for a reference architecture. Adoption, independent testing, and real-world failure rates are still ahead of this announcement.

Sources: NVIDIA investor relations press release, 28 September 2026.