Nvidia Makes OpenShell AI Agent Security Sandbox Generally Available
Nvidia is rallying technology companies around open-source security tools as AI agents increasingly interact with—and potentially threaten—online infrastructure.
As reports continue to emerge about AI agents wreaking havoc on online infrastructure, chipmaker Nvidia is urging technology companies to adopt new open-source tools designed to improve AI security.
Over the past few months, Frontier AI Lab has uncovered multiple incidents in which AI agents hacked other companies and, more recently, investigated U.S. and Australian government websites. Already playing a leading role in bringing the AI industry together around open-source security, Nvidia is introducing a new software security platform to make its agent-based AI sandbox more widely available.
Nvidia OpenShell AI security sandbox is now generally available
OpenShell, one of Nvidia’s recently announced security sandboxes for AI agents, is now generally available to all users. Nvidia first announced OpenShell at its annual GTC conference in March.
OpenShell is a framework for housing AI agents and isolating their activities within the operating system kernel. The kernel is the core program that can access virtually every part of a computer system to manage its hardware and software.
Anthropic, Microsoft and other companies work with Nvidia on AI safety
Nvidia says it is collaborating on AI safety and security with dozens of technology companies, including Anthropic, Cisco, CoreWeave, CrowdStrike, Dell Technologies, Hugging Face, JPMorganChase, Mistral, Microsoft and Palantir.
According to Nvidia, SpaceXAI uses the Open Agent Safety Platform for Cursor agents and Grok models. Nvidia also says Anthropic and the chipmaker are “building security into Claude Managed Agents.” Salesforce, Scale AI and SAP are confirmed to have some level of OpenShell integration.
However, it remains unclear whether every company on Nvidia’s partner list has adopted OpenShell or whether Nvidia is making the platform broadly available to its partners.
Why OpenAI is missing from Nvidia’s OpenShell announcement
One notable name, OpenAI, is missing from Nvidia’s list. Both companies have indicated that OpenAI is involved in Nvidia’s OpenShell efforts, but neither company directly commented on why the AI lab was left out of the announcement.
Nvidia developed OpenShell before recent AI agent hacks
Security engineers and AI safety experts had been examining the need to isolate and monitor AI agents well before recent revelations about rogue agent hacks.
Nvidia’s March announcement of OpenShell came months before OpenAI revealed that its AI agents had hacked Hugging Face, an open-source AI company. Nvidia said the framework would add “privacy and security controls to make self-evolving autonomous AI agents, or claws, more reliable, scalable and accessible.” Nvidia agreed to acquire Hugging Face for $12.9 billion earlier this month.
Nvidia’s announcement described OpenShell as a way to add privacy and security controls to autonomous AI agents.
Nvidia Sentry adds another layer of AI agent protection
Nvidia has also developed a software platform called Sentry, an isolated security domain for chips that continuously monitors long-running AI agents.
Although Sentry is technically a software tool, it is designed to run on Nvidia’s BlueField series of programmable data processing units, or DPUs. Alongside the restrictions imposed by OpenShell, Sentry is intended to provide a separate and independent mechanism that can “isolate agents that attempt to move outside the perimeter.”
“Sentry is another way for Nvidia customers and open-source users to actually implement security policies through OpenShell,” said Justin Boitano, Nvidia’s vice president and general manager of enterprise computing.
Traditional sandboxes were built for “application-level isolation,” Boitano said. However, organizations now want to run fleets of AI agents, requiring “collective policies across all agents.”
“Agents are very creative in finding ways to accomplish a given goal,” Boitano said. “This ensures that agents only have access to the intents that security teams want.”
Sentry will support Arm and Intel architectures
Boitano added that Nvidia is working with Arm and Intel to develop a version of Sentry that runs on x86 chip architecture.
“Once you run it on these instruction set architectures, you can run it on any architecture,” he said.
Source: www.wired.com


