The Short Answer
NVIDIA announced its Open Agent Safety Platform on 28 September 2026: OpenShell, an Apache 2.0 runtime boundary available now, and Sentry, a DPU watchdog NVIDIA calls a reference system design. The shipping half is the software, and on ibl.ai you own all the code and the data.
Almost every agent containment control in production today runs in the same software stack as the agent it contains. That is a structural weakness everyone in this field has been carrying, and it is the one NVIDIA just went after.
What did NVIDIA actually announce?
Two components and a supporting software layer, announced on 28 September 2026.
OpenShell is an open-source runtime that establishes a secure boundary for agents on CPUs β "a secure runtime boundary for controlling how autonomous AI agents execute tasks across open and closed models." It traces what an agent does and enforces policy while it runs. It targets NVIDIA's Vera CPU, described as the first purpose-built CPU for agentic AI, and is extensible to third-party processors from Arm and Intel.
Sentry is an out-of-band watchdog running on BlueField-4 DPUs. It monitors agent behaviour continuously and, if an agent tries to move outside its software boundary, quarantines and stops it in milliseconds. NVIDIA's DOCA software provides the programmable layer for inspecting agent requests, verifying identity and enforcing access policy.
The two are at very different stages, and the release is precise about it. NVIDIA says the platform "consists of NVIDIA OpenShell open source software and the NVIDIA Sentry reference system design".
Its availability sentence covers "OpenShell and skills". BlueField-4 itself is expected in early availability with NVIDIA's Vera Rubin platforms in 2026 β but Sentry, the control that would run on it, has no date at all.
OpenShell is real and downloadable today, under Apache 2.0. Sentry is a design others can build to.
Why does "out-of-band" matter more than "milliseconds"?
Because a control that shares a fate with the thing it controls is not really a control.
Every containment mechanism most platforms ship β sandboxes, egress allowlists, guardrail models, syscall filters, ours included β runs inside the same operating system, and often the same trust domain, as the agent.
If the agent finds a way out of its box, it is standing next to the thing that was supposed to stop it.
A watchdog on a separate processor does not share that fate. It is the same argument that put management controllers on separate silicon and firewalls on separate boxes, applied to a workload that writes its own next action.
The millisecond figure is the headline; the separation is the substance.
Is this real adoption or a launch-day list?
More than 100 organizations are named as working with the platform, and the list is unusually broad.
Anthropic, Microsoft, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI are among them.
A model lab, two hyperscalers, a bank, a defence contractor and a rocket company is not a market segment β it is a signal that agent containment has become infrastructure rather than a feature.
What is the trade nobody is putting on the slide?
Portability. The open half and the strong half are not the same half.
| Layer | What it gives you | What it ties you to |
|---|---|---|
| OpenShell Available now | Runtime boundary, action tracing, policy enforcement | Nothing hard β Apache 2.0, extensible to Arm and Intel |
| Sentry Reference system design β no ship date | Out-of-band enforcement, millisecond quarantine | BlueField-4 DPUs |
| Your platform | Sandbox, egress policy, secrets, audit trail | Whatever you chose β this is the part you can still own |
The strongest control in the announcement is the one that is not a product yet. That is not a criticism β a reference design is how this kind of enforcement usually starts β but it changes what you can do with it this year.
You cannot standardise on a reference system design, and you cannot price one: there is no SKU and no GA date.
Worth noting too that NVIDIA says OpenShell is extensible to Arm and Intel, and says nothing of the kind about Sentry β so when in-silicon enforcement does ship, the portability question arrives with it.
Does this make software containment obsolete?
No, and treating it that way would be a mistake.
Hardware enforcement is a backstop for the case where the software boundary fails. It does not decide what the boundary should be.
Something still has to say that this agent may reach these hosts and no others, that this credential is usable but not readable, that this action requires an approval β and then record what happened in a form an auditor can read.
That policy layer is the one you write, and it is the one that has to be true in an environment where there is no BlueField-4: a laptop, a small district's server room, a facility whose accreditation forbids the hardware refresh.
Where does ibl.ai sit in this?
In the layer above it, and deliberately.
Our agent sandboxes give each chat its own Linux VM that starts with no network at all, opened only to an allowlist of exact host:port pairs, with API secrets the agent can call with but never read.
Every privacy detection is written to a read-only audit endpoint that records entity types and never raw values.
None of that competes with an out-of-band watchdog. It is the policy the watchdog would be enforcing, and it runs today, on hardware you already have.
On ibl.ai you own all the code and the data. The platform runs under a perpetual licence on your own infrastructure, model-agnostic across any LLM, with no per-seat pricing β and you can deploy anywhere: your cloud, your VPC, on-premise, GovCloud, or fully air-gapped.
ibl.ai is family-owned and operated from New York, NY β a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
Containment you can inspect beats containment you are promised. An open-source runtime and a watchdog on separate silicon are both moves in that direction β and so is owning the policy they enforce.
Sources: components, hardware, availability and the partner list from NVIDIA's announcement; OpenShell's Apache 2.0 licence and kernel-level isolation from NVIDIA's developer blog and the OpenShell repository; BlueField-4 timing from NVIDIA's BlueField-4 announcement.
Related: Letting a K-12 AI Agent Run Code Without Letting Data Out β the software policy layer in detail, where the buyer is a school district.