Nvidia launches platform that will limit AI agent actions
Nvidia introduced the Open Agent Safety Platform — an open software platform and reference architecture for controlling autonomous AI agents from the testing stage to use in production systems.
As Nvidia reported, the platform is designed to create an independent safety layer for AI agents that does not rely solely on rules embedded in the model itself or the agent application.
One of the main components is Nvidia OpenShell — open-source software that runs an agent in an isolated environment. An administrator can predefine which files, network resources, tools, processes, and credentials the agent will have access to.
OpenShell checks these restrictions before launch and enforces them while the agent is running. Thus, even if the AI tries to perform an action outside the permitted scenario, its capabilities are limited at the execution environment level, not just by instructions for the model itself.
The second component is Nvidia Sentry. This is an independent monitoring system that can run on BlueField-4 data processing units separate from the environment where the AI agent itself is running. It monitors its activity and can apply security policies or isolate the agent if it goes beyond established limits.
Nvidia explains that offloading such control to separate hardware has a key advantage: the agent itself does not have access to the system that is watching it. In a configuration with BlueField-4, control can be carried out independently of the main processor and software environment.
The platform has been optimized for Nvidia Vera and BlueField server systems, but OpenShell is open-source software and can also run on hardware from other manufacturers, including Arm and Intel platforms.
Nvidia explains the need for separate protection by the fact that modern AI agents are increasingly getting access not only to text chat, but also to files, corporate databases, software tools, network resources, and the ability to execute code on their own. According to the company, experiments have already recorded cases where agents moved beyond test environments or performed actions not intended by operators.
Other major technology companies are also joining the development of the new approach. IBM, in particular, is integrating its digital identity and access management tools with OpenShell, and Cisco plans to combine the Nvidia platform with its tools for protecting networks, cloud infrastructure, and AI applications.
However, the Open Agent Safety Platform is not a guarantee that an AI agent will never perform a dangerous action. It is about an additional technical layer of isolation, monitoring, and policy enforcement that should reduce the risk that an autonomous agent gains access to resources or performs an operation for which it did not have permission.