Nvidia says its 100 partner Open Agent Safety Platform can cut off autonomous AI systems at the silicon layer in milliseconds, reframing AI safety as a buildable infrastructure problem.
Nvidia released an open, 100-partner engineering answer on September 28, 2026 that can quarantine a rogue AI agent in milliseconds at the silicon-and-software path to the model. The Open Agent Safety Platform pairs the OpenShell open-source software stack with a Sentry reference system design, the clearest statement yet from CEO Jensen Huang that AI safety is a buildable infrastructure problem rather than a reason to halt the build.
In Nvidia's reference design, the BlueField-4 data-processing unit sits on the only path to the model inside a Vera Rubin POD, physically separated from the host CPU. The agent cannot reach the model without passing through that chip, which moves the unit of safety from inside the model to a separate supervisor on its doorstep. OpenShell's architecture documentation calls this a split between a trusted supervisor and an untrusted sandbox workload, with network access and credentials mediated at the supervisor rather than inside the agent.
Sentry is the optional monitoring layer. According to Nvidia's developer blog, Sentry uses the company's DOCA framework to correlate agent interactions, policy decisions and tool or data access, then continuously verifies the agent's identity and delegated authority. An agent that attempts to leave its software boundary can be quarantined in milliseconds, the vendor says. The mechanism borrows the trust pattern used in confidential computing, where the chip is the enforcement boundary and the host is treated as untrusted.
The openness is the second half of the move. Nvidia says more than 100 partners are building on the platform, and the OpenShell software is broadly available through developer resources and GitHub. By releasing the design and inviting outside review, Nvidia is arguing the safety question should be answered the way chip, browser, and cloud-security questions are answered: with reference implementations, public scrutiny, and partner competition. The contrast with the AI safety debate's dominant tone of calls for moratoriums and tighter regulation is deliberate.
The limits are documented in Nvidia's own materials. OpenShell's security best-practices page warns that every endpoint the platform allows is a potential exfiltration path, and changing filesystem or process controls requires recreating the sandbox. The architecture and best-practices pages also describe network mediation differently: one as a supervisor-separated architecture, the other as a gateway CONNECT-proxy inside a virtual network. The two framings have not been reconciled into a single network topology. Nvidia's claim of millisecond quarantine is unbenchmarked, and the software's broad availability does not extend to the hardware. Customers need a Vera Rubin system with BlueField-4 already running before Sentry can do anything.
There is also a category of risk the platform does not address. OpenShell and Sentry can mediate an agent's path to a model inside a customer's infrastructure. They do not extend to threat actors who wield AI as a tool from outside, the gap that critics of self-regulation point to when they call for licensing, compute thresholds, or third-party red-teaming. Nvidia's bet is that engineering the inside of the system is the part the industry can ship first.
The platform is on GitHub now. The first independent benchmark of Sentry's quarantine latency and the first disclosed breakout attempt will test whether infrastructure containment, opened to a hundred partner implementations, can move the public conversation faster than the calls for a pause.