NVIDIA Launches Open Agent Safety Platform as Jensen Huang Pushes for Faster AI Safety Engineering

NVIDIA is expanding beyond AI compute with a new security platform designed to keep increasingly autonomous agents inside defined operational boundaries. The NVIDIA Open Agent Safety Platform combines open source runtime software with hardware based monitoring capable of restricting access to files, credentials, APIs, tools, and external services while independently stopping agents that attempt to move outside their assigned permissions. CEO Jensen Huang argues that progress in AI capabilities should be matched by faster work on AI safety, but NVIDIA has not positioned the platform as an argument for abandoning regulation or slowing safety research.

"AI’s extraordinary potential for society will only be realized if we solve AI safety."
— Quote by: Jensen Huang.

The platform has 2 main components. OpenShell creates a secure runtime boundary around autonomous agents and records the actions and permission decisions they make while operating. NVIDIA says it can protect credentials by keeping them outside the agent environment and can control which files, applications, tools, and network resources an agent is allowed to reach. OpenShell is optimized for NVIDIA Vera CPUs but is open source and can be extended to third party compute platforms including Arm and Intel. The second component, Sentry, runs independently on NVIDIA BlueField 4 DPUs and acts as an external watchdog capable of monitoring agent activity and quarantining an agent within milliseconds if it crosses defined security boundaries.

That hardware separation is an important part of NVIDIA’s design. Sentry operates from an isolated trust domain rather than relying entirely on the same software environment controlled by the agent, using NVIDIA DOCA to inspect requests and responses, verify identity, protect data access, and enforce zero trust policies. NVIDIA’s official documentation does not state that Sentry needs access to a model’s private chain of thought or internal reasoning traces. The system is described around observable agent activity and infrastructure controls, making claims that closed models would need to expose their hidden reasoning for Sentry to function unsupported by NVIDIA’s announcement.

The commercial implications are still significant. Sentry specifically uses BlueField 4 DPUs, while OpenShell has been optimized for NVIDIA Vera, giving NVIDIA another infrastructure layer around the rapidly expanding agentic AI market. At the same time, the software side is intentionally broader, with Anthropic, Microsoft, Red Hat, Salesforce, Cisco, CrowdStrike, Dell, HPE, Hugging Face, JPMorganChase, Palantir, Perplexity, SAP, ServiceNow, Scale AI, SpaceXAI, and others participating in the ecosystem. NVIDIA says SpaceXAI is already using the platform with Cursor coding agents and Grok models, while Salesforce has integrated OpenShell controls into Slack.

The announcement fits NVIDIA’s wider push toward open AI infrastructure. NVIDIA is expanding local AI around open models including Nemotron, while Huang has also argued that open models strengthen safety, cybersecurity, innovation, and AI sovereignty. Open Agent Safety extends that strategy by trying to standardize how autonomous models are contained and audited regardless of whether the model itself is open or closed.

Huang reinforced his generally open stance a day later during a CNBC interview about AI model distillation, where he rejected the characterization of learning from competing AI systems as inherently equivalent to theft. Asked about distillation, Huang called it "competition" and argued that companies are allowed to test competing products. His position differs from statements by US Treasury Secretary Scott Bessent, who has previously described some forms of overseas model distillation as theft and raised the possibility of sanctions. The disagreement concerns policy and intellectual property treatment rather than the operation of NVIDIA’s new safety platform.

"That’s called competition."
— Quote by: Jensen Huang.

NVIDIA’s announcement is more interesting than simply adding another security product to its AI stack. As agents receive broader access to browsers, enterprise systems, code, infrastructure, and eventually robotics, safety increasingly becomes an infrastructure problem as well as a model problem. NVIDIA is betting that some of those controls should live outside the agent itself, where the model cannot simply override them.

There is also an obvious business benefit. If enterprises decide autonomous agents require dedicated security infrastructure, BlueField DPUs, Vera CPUs, DOCA, and NVIDIA’s wider AI platform gain another reason to exist inside AI deployments. That does not mean the safety platform was created simply to sell more hardware, nor does NVIDIA claim it eliminates the need for alignment research or policy. What it does show is how NVIDIA is turning AI safety into another full stack engineering layer around the compute market it already dominates.

Should autonomous AI safety rely more heavily on external hardware and runtime controls, or should the model itself remain the primary place where safeguards are enforced?

Share
Angel Morales

Founder and lead writer at Duck-IT Tech News, and dedicated to delivering the latest news, reviews, and insights in the world of technology, gaming, and AI. With experience in the tech and business sectors, combining a deep passion for technology with a talent for clear and engaging writing

Previous
Previous

AMD Buys World Labs for $8.2 Billion as Fei Fei Li Becomes Chief Scientist

Next
Next

PHYSINT $400 Million Budget Claim Disputed as Xbox Deal Is Said to Cost Far Less