ibl.ai Agentic AI Blog

Insights on building and deploying agentic AI systems. Our blog covers AI agent architectures, LLM infrastructure, MCP servers, enterprise deployment strategies, and real-world implementation guides. Whether you are a developer building AI agents, a CTO evaluating agentic platforms, or a technical leader driving AI adoption, you will find practical guidance here.

Topics We Cover

Featured Research and Reports

We analyze key research from leading institutions and labs including Google DeepMind, Anthropic, OpenAI, Meta AI, McKinsey, and the World Economic Forum. Our content includes detailed analysis of reports on AI agents, foundation models, and enterprise AI strategy.

For Technical Leaders

CTOs, engineering leads, and AI architects turn to our blog for guidance on agent orchestration, model evaluation, infrastructure planning, and building production-ready AI systems. We provide frameworks for responsible AI deployment that balance capability with safety and reliability.

Back to Blog

Agent Containment Moved Into Silicon. What You Still Own.

ibl.ai EngineeringSeptember 28, 2026
Premium

NVIDIA's Open Agent Safety Platform pairs OpenShell, an Apache 2.0 runtime boundary you can run today, with Sentry β€” an out-of-band watchdog NVIDIA describes as a reference system design, not a shipping product. The strongest control in the announcement is the one you cannot buy yet, and that is the part worth planning around.

The Short Answer

NVIDIA announced its Open Agent Safety Platform on 28 September 2026: OpenShell, an Apache 2.0 runtime boundary available now, and Sentry, a DPU watchdog NVIDIA calls a reference system design. The shipping half is the software, and on ibl.ai you own all the code and the data.

Almost every agent containment control in production today runs in the same software stack as the agent it contains. That is a structural weakness everyone in this field has been carrying, and it is the one NVIDIA just went after.

What did NVIDIA actually announce?

Two components and a supporting software layer, announced on 28 September 2026.

OpenShell is an open-source runtime that establishes a secure boundary for agents on CPUs β€” "a secure runtime boundary for controlling how autonomous AI agents execute tasks across open and closed models." It traces what an agent does and enforces policy while it runs. It targets NVIDIA's Vera CPU, described as the first purpose-built CPU for agentic AI, and is extensible to third-party processors from Arm and Intel.

Sentry is an out-of-band watchdog running on BlueField-4 DPUs. It monitors agent behaviour continuously and, if an agent tries to move outside its software boundary, quarantines and stops it in milliseconds. NVIDIA's DOCA software provides the programmable layer for inspecting agent requests, verifying identity and enforcing access policy.

The two are at very different stages, and the release is precise about it. NVIDIA says the platform "consists of NVIDIA OpenShell open source software and the NVIDIA Sentry reference system design".

Its availability sentence covers "OpenShell and skills". BlueField-4 itself is expected in early availability with NVIDIA's Vera Rubin platforms in 2026 β€” but Sentry, the control that would run on it, has no date at all.

OpenShell is real and downloadable today, under Apache 2.0. Sentry is a design others can build to.

Why does "out-of-band" matter more than "milliseconds"?

Because a control that shares a fate with the thing it controls is not really a control.

Every containment mechanism most platforms ship β€” sandboxes, egress allowlists, guardrail models, syscall filters, ours included β€” runs inside the same operating system, and often the same trust domain, as the agent.

If the agent finds a way out of its box, it is standing next to the thing that was supposed to stop it.

A watchdog on a separate processor does not share that fate. It is the same argument that put management controllers on separate silicon and firewalls on separate boxes, applied to a workload that writes its own next action.

The millisecond figure is the headline; the separation is the substance.

Is this real adoption or a launch-day list?

More than 100 organizations are named as working with the platform, and the list is unusually broad.

Anthropic, Microsoft, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI are among them.

A model lab, two hyperscalers, a bank, a defence contractor and a rocket company is not a market segment β€” it is a signal that agent containment has become infrastructure rather than a feature.

What is the trade nobody is putting on the slide?

Portability. The open half and the strong half are not the same half.

Layer What it gives you What it ties you to
OpenShell
Available now
Runtime boundary, action tracing, policy enforcementNothing hard β€” Apache 2.0, extensible to Arm and Intel
Sentry
Reference system design β€” no ship date
Out-of-band enforcement, millisecond quarantineBlueField-4 DPUs
Your platformSandbox, egress policy, secrets, audit trailWhatever you chose β€” this is the part you can still own

The strongest control in the announcement is the one that is not a product yet. That is not a criticism β€” a reference design is how this kind of enforcement usually starts β€” but it changes what you can do with it this year.

You cannot standardise on a reference system design, and you cannot price one: there is no SKU and no GA date.

Worth noting too that NVIDIA says OpenShell is extensible to Arm and Intel, and says nothing of the kind about Sentry β€” so when in-silicon enforcement does ship, the portability question arrives with it.

Does this make software containment obsolete?

No, and treating it that way would be a mistake.

Hardware enforcement is a backstop for the case where the software boundary fails. It does not decide what the boundary should be.

Something still has to say that this agent may reach these hosts and no others, that this credential is usable but not readable, that this action requires an approval β€” and then record what happened in a form an auditor can read.

That policy layer is the one you write, and it is the one that has to be true in an environment where there is no BlueField-4: a laptop, a small district's server room, a facility whose accreditation forbids the hardware refresh.

Where does ibl.ai sit in this?

In the layer above it, and deliberately.

Our agent sandboxes give each chat its own Linux VM that starts with no network at all, opened only to an allowlist of exact host:port pairs, with API secrets the agent can call with but never read.

Every privacy detection is written to a read-only audit endpoint that records entity types and never raw values.

None of that competes with an out-of-band watchdog. It is the policy the watchdog would be enforcing, and it runs today, on hardware you already have.

On ibl.ai you own all the code and the data. The platform runs under a perpetual licence on your own infrastructure, model-agnostic across any LLM, with no per-seat pricing β€” and you can deploy anywhere: your cloud, your VPC, on-premise, GovCloud, or fully air-gapped.

ibl.ai is family-owned and operated from New York, NY β€” a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

Containment you can inspect beats containment you are promised. An open-source runtime and a watchdog on separate silicon are both moves in that direction β€” and so is owning the policy they enforce.

Sources: components, hardware, availability and the partner list from NVIDIA's announcement; OpenShell's Apache 2.0 licence and kernel-level isolation from NVIDIA's developer blog and the OpenShell repository; BlueField-4 timing from NVIDIA's BlueField-4 announcement.

Related: Letting a K-12 AI Agent Run Code Without Letting Data Out β€” the software policy layer in detail, where the buyer is a school district.

Why does owning the AI stack matter?

ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing β€” so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.

  • You own all the code and the data

    Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform β€” the stack itself is yours.

  • Model-agnostic

    Run any LLM β€” Claude, GPT, Gemini, Llama, Command, or your own fine-tune β€” and switch providers without rewriting the platform.

  • No per-seat pricing

    Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.

  • Deploy anywhere

    Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY β€” a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

See the ibl.ai AI Operating System in Action

Discover how leading universities and organizations are transforming education with the ibl.ai AI Operating System. Explore real-world implementations from Harvard, MIT, Stanford, and users from 400+ institutions worldwide.

View Case Studies
Work with our team

Pilots, deployment, and full ownership

Most enterprise engagements are one-time, not subscriptions. You integrate ibl.ai with your own data, deploy it on your own infrastructure, and the engineering hours scale with the work β€” so the price tracks the scope, not your headcount.

Start here

Pilot

from $15K

fixed scope Β· fixed timeline

A time-boxed proof of value on your real data β€” not a slide deck.

Best for: Teams that want to see ibl.ai working before committing.

  • Deployed on your infrastructure or our cloud
  • 1–2 production agents wired to a slice of your data
  • One integration (LMS / SIS / SSO / data source)
  • Weekly working sessions with our engineers
  • Pilot fee credits toward a full engagement
Scope a pilot
Most common

Integration & Deployment

$25K – $80K

one-time Β· not a subscription

Full deployment integrated with your data and systems. Engineering hours scale with scope.

Best for: Organizations rolling ibl.ai out across a department, campus, or business unit.

  • Platform deployed in your VPC, on-prem, or air-gapped
  • Integrated with your data + identity (SSO / SAML)
  • Multiple custom agents built to your workflows
  • Engineering hours proportional to scope
  • You own the data Β· run any LLM you choose
Plan a deployment
Full ownership

Codebase Transfer + Custom AI Engineering

Custom quote

perpetual license Β· you own the stack

We transfer the full source code. You own and self-host the entire platform β€” outright.

Best for: Organizations and enterprises that benefit from perpetual ownership and sovereignty.

  • Complete source-code transfer + perpetual license
  • Dedicated AI engineering team on your roadmap
  • Custom agents, models, and integrations to spec
  • Air-gapped capable Β· zero vendor lock-in
  • Family-owned, New York–based long-term partner
Talk about ownership
You own the code and data Run any LLM β€” Claude, GPT, Gemini, Llama Family-owned & operated from New York, NY