---
title: "Agent Containment Moved Into Silicon. What You Still Own."
slug: "nvidia-open-agent-safety-platform-containment-in-silicon"
author: "ibl.ai Engineering"
date: "2026-09-28 16:00:00"
category: "Premium"
topics: "agent safety, AI security, NVIDIA, agent sandboxing, self-hosted AI, enterprise AI governance"
summary: "NVIDIA's Open Agent Safety Platform pairs OpenShell, an Apache 2.0 runtime boundary you can run today, with Sentry — an out-of-band watchdog NVIDIA describes as a reference system design, not a shipping product. The strongest control in the announcement is the one you cannot buy yet, and that is the part worth planning around."
banner: ""
thumbnail: ""
linkedin: |
  NVIDIA announced its Open Agent Safety Platform today, and the interesting part is where the enforcement point sits.

  Two pieces, and they are at very different stages. OpenShell is an Apache 2.0 runtime that traces every action an agent takes and enforces policy as it runs — on NVIDIA's Vera CPU, and extensible to Arm and Intel. It is available today on GitHub.

  Sentry is the out-of-band watchdog: it runs on BlueField-4 DPUs, watches the agent without the host's cooperation, and quarantines it in milliseconds if it crosses its boundary. The release is explicit that it is a "reference system design" — the availability sentence covers OpenShell and skills, and gives Sentry no ship date at all.

  Out-of-band is still the idea worth taking. Every containment control most of us ship today — sandboxes, egress allowlists, guardrails, ours included — runs inside the same software stack as the thing it is containing. A watchdog on a separate processor does not share that fate.

  More than 100 organizations are named around it, including Anthropic, Microsoft, JPMorganChase, Palantir, Red Hat, Hugging Face and SpaceXAI. That is not a pilot.

  The honest read for anyone building agent platforms: the strongest control in this announcement is not the least portable one, it is the one that is not a product yet. Plan on OpenShell; treat in-silicon quarantine as a direction of travel.

  Which is why the layer above it still matters. On ibl.ai you own all the code and the data — the sandbox, the egress policy, the audit trail and the platform itself run on your infrastructure, on any cloud, in your VPC, on-premise, or fully air-gapped.

  Containment you can inspect beats containment you are promised. Both of these are moves in that direction.

  #iblai #AIsecurity #AgenticAI #EnterpriseAI #NVIDIA
---

## The Short Answer

**NVIDIA announced its Open Agent Safety Platform on 28 September 2026: OpenShell, an Apache 2.0 runtime boundary available now, and Sentry, a DPU watchdog NVIDIA calls a reference system design. The shipping half is the software, and on ibl.ai you own all the code and the data.**

Almost every agent containment control in production today runs in the same software stack as the agent it contains. That is a structural weakness everyone in this field has been carrying, and it is the one NVIDIA just went after.

## What did NVIDIA actually announce?

Two components and a supporting software layer, announced on **28 September 2026**.

**OpenShell** is an open-source runtime that establishes a secure boundary for agents on CPUs — "a secure runtime boundary for controlling how autonomous AI agents execute tasks across open and closed models." It traces what an agent does and enforces policy while it runs. It targets NVIDIA's **Vera CPU**, described as the first purpose-built CPU for agentic AI, and is extensible to third-party processors from **Arm and Intel**.

**Sentry** is an out-of-band watchdog running on **BlueField-4 DPUs**. It monitors agent behaviour continuously and, if an agent tries to move outside its software boundary, quarantines and stops it **in milliseconds**. NVIDIA's **DOCA** software provides the programmable layer for inspecting agent requests, verifying identity and enforcing access policy.

The two are at very different stages, and the release is precise about it. NVIDIA says the platform "consists of NVIDIA OpenShell open source software and **the NVIDIA Sentry reference system design**".

Its availability sentence covers "OpenShell and skills". BlueField-4 itself is [expected in early availability](https://blogs.nvidia.com/blog/bluefield-4-ai-factory/) with NVIDIA's Vera Rubin platforms in 2026 — but Sentry, the control that would run on it, has no date at all.

OpenShell is real and downloadable today, under **Apache 2.0**. Sentry is a design others can build to.

## Why does "out-of-band" matter more than "milliseconds"?

Because a control that shares a fate with the thing it controls is not really a control.

Every containment mechanism most platforms ship — sandboxes, egress allowlists, guardrail models, syscall filters, ours included — runs inside the same operating system, and often the same trust domain, as the agent.

If the agent finds a way out of its box, it is standing next to the thing that was supposed to stop it.

A watchdog on a separate processor does not share that fate. It is the same argument that put management controllers on separate silicon and firewalls on separate boxes, applied to a workload that writes its own next action.

The millisecond figure is the headline; the separation is the substance.

## Is this real adoption or a launch-day list?

More than **100 organizations** are named as working with the platform, and the list is unusually broad.

Anthropic, Microsoft, Cisco, CrowdStrike, Dell Technologies, Figure, HPE, Hugging Face, JPMorganChase, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI are among them.

A model lab, two hyperscalers, a bank, a defence contractor and a rocket company is not a market segment — it is a signal that agent containment has become infrastructure rather than a feature.

## What is the trade nobody is putting on the slide?

Portability. The open half and the strong half are not the same half.

<table style="width:100%; border-collapse:collapse; margin:1.5rem 0; font-size:0.95rem;">
  <thead>
    <tr style="background:#f5f5f0; border-bottom:2px solid #2175C5;">
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">Layer</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What it gives you</th>
      <th style="text-align:left; padding:0.75rem; color:#5f6368;">What it ties you to</th>
    </tr>
  </thead>
  <tbody>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>OpenShell</strong><br /><span style="font-size:0.85rem; color:#5f6368;">Available now</span></td><td style="padding:0.75rem;">Runtime boundary, action tracing, policy enforcement</td><td style="padding:0.75rem;">Nothing hard — Apache 2.0, extensible to Arm and Intel</td></tr>
    <tr style="border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Sentry</strong><br /><span style="font-size:0.85rem; color:#5f6368;">Reference system design — no ship date</span></td><td style="padding:0.75rem;">Out-of-band enforcement, millisecond quarantine</td><td style="padding:0.75rem;">BlueField-4 DPUs</td></tr>
    <tr style="background:#f0f9ff; border-bottom:1px solid #e5e7eb;"><td style="padding:0.75rem;"><strong>Your platform</strong></td><td style="padding:0.75rem;">Sandbox, egress policy, secrets, audit trail</td><td style="padding:0.75rem;"><strong>Whatever you chose — this is the part you can still own</strong></td></tr>
  </tbody>
</table>

The strongest control in the announcement is the one that is not a product yet. That is not a criticism — a reference design is how this kind of enforcement usually starts — but it changes what you can do with it this year.

You cannot standardise on a reference system design, and you cannot price one: there is no SKU and no GA date.

Worth noting too that NVIDIA says *OpenShell* is extensible to Arm and Intel, and says nothing of the kind about Sentry — so when in-silicon enforcement does ship, the portability question arrives with it.

## Does this make software containment obsolete?

No, and treating it that way would be a mistake.

Hardware enforcement is a backstop for the case where the software boundary fails. It does not decide what the boundary should be.

Something still has to say that this agent may reach these hosts and no others, that this credential is usable but not readable, that this action requires an approval — and then record what happened in a form an auditor can read.

That policy layer is the one you write, and it is the one that has to be true in an environment where there is no BlueField-4: a laptop, a small district's server room, a facility whose accreditation forbids the hardware refresh.

## Where does ibl.ai sit in this?

In the layer above it, and deliberately.

Our agent sandboxes give each chat its own Linux VM that starts with **no network at all**, opened only to an allowlist of exact host:port pairs, with API secrets the agent can call with but never read.

Every privacy detection is written to a read-only audit endpoint that records entity types and never raw values.

None of that competes with an out-of-band watchdog. It is the policy the watchdog would be enforcing, and it runs today, on hardware you already have.

On ibl.ai you own all the code and the data. The platform runs under a perpetual licence on your own infrastructure, model-agnostic across any LLM, with no per-seat pricing — and you can deploy anywhere: your cloud, your VPC, on-premise, GovCloud, or fully air-gapped.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.

Containment you can inspect beats containment you are promised. An open-source runtime and a watchdog on separate silicon are both moves in that direction — and so is owning the policy they enforce.

*Sources: components, hardware, availability and the partner list from [NVIDIA's announcement](https://nvidianews.nvidia.com/news/open-agent-safety-platform); OpenShell's Apache 2.0 licence and kernel-level isolation from [NVIDIA's developer blog](https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/) and [the OpenShell repository](https://github.com/NVIDIA/OpenShell); BlueField-4 timing from [NVIDIA's BlueField-4 announcement](https://blogs.nvidia.com/blog/bluefield-4-ai-factory/).*

*Related: [Letting a K-12 AI Agent Run Code Without Letting Data Out](/blog/agent-sandboxes-k12-districts-code-execution) — the software policy layer in detail, where the buyer is a school district.*

## Why does owning the AI stack matter?

**ibl.ai is the agentic AI platform where you own all the code and the data. You self-host the entire stack inside your own perimeter, run it model-agnostic across any LLM and switch anytime, and pay by usage with no per-seat pricing — so you can deploy anywhere: your cloud, on-premise, GovCloud, or fully air-gapped.**

- **You own all the code and the data.** Full source code under a perpetual license, running on your infrastructure. Not API access to someone else's platform — the stack itself is yours.
- **Model-agnostic.** Run any LLM — Claude, GPT, Gemini, Llama, Command, or your own fine-tune — and switch providers without rewriting the platform.
- **No per-seat pricing.** Usage-based billing against a budget cap you set. Cost tracks what your organization actually uses, not how many people you employ.
- **Deploy anywhere.** Your cloud, your VPC, on-premise, GovCloud, or a fully air-gapped network with no outbound connectivity.

1.6M+ users across 400+ organizations run the platform this way, including NVIDIA, MIT, and Syracuse University.

ibl.ai is family-owned and operated from New York, NY — a U.S.-headquartered, domestically-owned long-term partner, not a vendor that sells licenses and moves on.
