# NVIDIA Open Agent Safety Platform
![[resources/images/wiki-nvidia-open-agent-safety-platform.png]]
**Entity class:** Open AI-agent security platform and reference system design
**Developer and ecosystem convener:** [[wiki/NVIDIA|NVIDIA]]
**Announced:** September 28, 2026
**Core components:** [[wiki/NVIDIA OpenShell|NVIDIA OpenShell]] and [[wiki/NVIDIA Sentry|NVIDIA Sentry]]
## Definition
**NVIDIA Open Agent Safety Platform** is an open software platform and reference system design for governing AI agents from testing through deployment. NVIDIA presents the platform as a trust layer built outside the agent's own reasoning process: software controls determine what an agent may see, change and contact, while an optional hardware-isolated monitor observes activity and can enforce or quarantine from a domain the agent and host software cannot directly reach. The platform therefore joins runtime governance, continuous telemetry, identity and access enforcement, threat detection and containment across the application, runtime and infrastructure layers rather than treating model guardrails as the complete safety boundary.
NVIDIA CEO Jensen Huang described the launch as the beginning of an open ecosystem for safe agent systems and argued that safety is the means by which trust is earned rather than a brake on innovation. NVIDIA's technical materials express the same premise operationally: prompts and model safeguards influence what an agent attempts, while runtime and infrastructure controls enforce what it is allowed to do. The platform is not one indivisible appliance; organizations can deploy [[wiki/NVIDIA OpenShell|OpenShell]] without BlueField hardware and add [[wiki/NVIDIA Sentry|Sentry]] when they require a separate in-silicon enforcement domain.
## OpenShell and Sentry reference design
![[resources/images/wiki-nvidia-open-agent-safety-platform-reference-design.png]]
The reference design combines two enforcement planes. [[wiki/NVIDIA OpenShell|NVIDIA OpenShell]] is the open-source secure runtime boundary: it places each agent in an isolated sandbox, mediates filesystem, process, network, credential, tool and model access, verifies policy and records allow-or-deny decisions. [[wiki/NVIDIA Sentry|NVIDIA Sentry]] is the out-of-band watchdog: it uses [[wiki/NVIDIA DOCA|NVIDIA DOCA]] on [[wiki/BlueField-4|NVIDIA BlueField-4]] DPUs to observe agent requests and responses, bind actions to identity and delegated authority, maintain attested telemetry and apply policy from hardware isolated from the agent and host.
### NVIDIA OpenShell
- **Agent sandboxes:** kernel-level isolation, restricted files and processes, and no unmediated network access.
- **Supervisor:** out-of-sandbox evaluation of network requests, credential release and live policy enforcement.
- **Gateway:** identity, sandbox lifecycle, policy, settings and credential control across a fleet.
- **Policy prover:** formal verification that proposed permissions remain inside operator-defined boundaries.
- **Deployment model:** open or closed models and multiple harnesses across local, cloud, hybrid, on-premises, edge and air-gapped environments.
### NVIDIA Sentry
- **Independent observation:** continuous monitoring from a BlueField-4 trust domain outside agent and host software.
- **Hardware-based enforcement:** policy evaluation and containment on the path between agent workloads and models, tools, data and services.
- **Identity governance:** verification of agent identity and delegated authority for each interaction.
- **Trusted telemetry:** contextual records joining agent interactions, policy decisions and resource access.
- **Containment:** NVIDIA states that Sentry can quarantine and stop an agent that crosses its boundary in milliseconds.
## Security model and evidence boundary
The platform implements defense in depth rather than claiming that runtime control solves every question in [[wiki/AI Safety|AI safety]]. OpenShell governs execution outside the agent process, but it remains part of the host software environment; Sentry adds a separate infrastructure trust domain, but its strongest isolation and enforcement claims depend on supported BlueField-4 and DOCA deployment. Neither layer establishes that a model is truthful, aligned, conscious or incapable of dangerous planning. Their narrower and testable function is to constrain consequences, preserve observation and make policy enforcement harder for an agent to bypass.
NVIDIA describes OpenShell as broadly available under the Apache 2.0 license and the platform software and skills as available through NVIDIA developer resources and GitHub. Product availability, integration depth and the meaning of participation are not uniform across every organization in the ecosystem graphic. Inclusion below confirms representation in NVIDIA's official September 28, 2026 ecosystem image; it does not by itself prove a contract, production deployment, technical contribution or identical adoption status.
## Public-transition interpretation and OpenAI boundary
[[articles/Safety Discourse Is Transition Discourse|Safety Discourse Is Transition Discourse]] interprets the platform as both a security architecture and a public-transition architecture: a receiving and stabilization layer for autonomous systems moving into ordinary institutions. That interpretation is the article's thesis rather than an intention NVIDIA states. The documentary basis is narrower and should remain visible: NVIDIA describes confidence, trust, education, shared practice and international cooperation as conditions of a successful AI ecosystem, while [[wiki/OpenAI|OpenAI]] describes gradual deployment as a way for people and institutions to experience, understand and adapt to increasingly capable systems.
OpenAI does not appear in the 107-logo placard or NVIDIA's launch-release partner text. The absence does not establish why OpenAI is outside the roster. It is also not a technical separation: [[wiki/NVIDIA OpenShell|OpenShell]] officially supports Codex, and NVIDIA and OpenAI separately describe a strategic systems partnership dating to OpenAI's early history. The article records its role-separation reading as a future-adjudicable hypothesis, while this entry preserves the confirmed roster fact and the unresolved reason for the omission.
## Official ecosystem roster — every logo in the NVIDIA graphic
The official graphic contains **107 represented organizations and projects**. NVIDIA describes the field as more than 100 industry partners spanning applications, models, infrastructure, chips and energy, while the visual roster also includes alliances, research bodies, public-sector and industry organizations. Canonical identities are expanded below where the logo uses an abbreviation or parent brand.
- [[wiki/1Password|1Password]]
- [[wiki/Absolute Security|Absolute Security]]
- [[wiki/Accenture|Accenture]]
- [[wiki/AgenticSOC Alliance|AgenticSOC Alliance]]
- [[wiki/Akamai|Akamai]]
- [[wiki/Anthropic|Anthropic]]
- [[wiki/Arm|Arm]]
- [[wiki/Armadin|Armadin]]
- [[wiki/Baseten|Baseten]]
- [[wiki/Bedrock Data|Bedrock Data]]
- [[wiki/Bitdeer|Bitdeer]]
- [[wiki/Bohr Quantum|Bohr Quantum]]
- [[wiki/Cadence Design Systems|Cadence]]
- [[wiki/Canonical|Canonical]]
- [[wiki/Check Point Software Technologies|Check Point]]
- [[wiki/Cisco|Cisco]]
- [[wiki/Citi|Citi]]
- [[wiki/Cloud Security Alliance|Cloud Security Alliance]]
- [[wiki/Cloudflare|Cloudflare]]
- [[wiki/Cognition AI|Cognition]]
- [[wiki/CoreWeave|CoreWeave]]
- [[wiki/Crosspoint Capital|Crosspoint Capital]]
- [[wiki/CrowdStrike|CrowdStrike]]
- [[wiki/Crusoe|Crusoe]]
- [[wiki/Dassault Systèmes|Dassault Systèmes]]
- [[wiki/DeepInfra|DeepInfra]]
- [[wiki/Dell Technologies|Dell Technologies]]
- [[wiki/Deloitte|Deloitte]]
- [[wiki/DigiCert|DigiCert]]
- [[wiki/DigitalOcean|DigitalOcean]]
- [[wiki/Dream|Dream]]
- [[wiki/Eclypsium|Eclypsium]]
- [[wiki/Electric Power Research Institute|EPRI]]
- [[wiki/EQTY Lab|EQTY Lab]]
- [[wiki/Everseen|Everseen]]
- [[wiki/ExtraHop|ExtraHop]]
- [[wiki/EY|EY]]
- [[wiki/F5|F5]]
- [[wiki/Figure AI|Figure]]
- [[wiki/Firmus|Firmus]]
- [[wiki/Forescout|Forescout]]
- [[wiki/Fortanix|Fortanix]]
- [[wiki/Fortinet|Fortinet]]
- [[wiki/Gecko Robotics|Gecko Robotics]]
- [[wiki/GMI Cloud|GMI Cloud]]
- [[wiki/Hitachi Energy|Hitachi Energy]]
- [[wiki/HPE|HPE]]
- [[wiki/HP Inc.|HP Inc.]]
- [[wiki/Hugging Face|Hugging Face]]
- [[wiki/IBM|IBM]]
- [[wiki/IREN|IREN]]
- [[wiki/Irregular|Irregular]]
- [[wiki/JFrog|JFrog]]
- [[wiki/JPMorganChase|JPMorganChase]]
- [[wiki/Lambda|Lambda]]
- [[wiki/LangChain|LangChain]]
- [[wiki/Lenovo|Lenovo]]
- [[wiki/Lightning AI|Lightning AI]]
- [[wiki/Microsoft|Microsoft]]
- [[wiki/Mistral AI|Mistral AI]]
- [[wiki/monday.com|monday.com]]
- [[wiki/National Technology Security Coalition|National Technology Security Coalition]]
- [[wiki/Nebius|Nebius]]
- [[wiki/Netskope|Netskope]]
- [[wiki/NextEra Energy|NextEra Energy]]
- [[wiki/Nous Research|Nous Research]]
- [[wiki/Okta|Okta]]
- [[wiki/Opaque Systems|OPAQUE]]
- [[wiki/OpenWorker|OpenWorker]]
- [[wiki/Oracle Cloud Infrastructure|Oracle Cloud Infrastructure]]
- [[wiki/Orca Security|Orca Security]]
- [[wiki/Palantir Technologies|Palantir]]
- [[wiki/Palo Alto Networks|Palo Alto Networks]]
- [[wiki/Perplexity|Perplexity]]
- [[wiki/Quanta Services|Quanta Services]]
- [[wiki/Red Hat|Red Hat]]
- [[wiki/ReversingLabs|ReversingLabs]]
- [[wiki/RSAC|RSAC]]
- [[wiki/SailPoint|SailPoint]]
- [[wiki/Salesforce|Salesforce]]
- [[wiki/SAP|SAP]]
- [[wiki/Scale AI|Scale AI]]
- [[wiki/Schneider Electric|Schneider Electric]]
- [[wiki/SentinelOne|SentinelOne]]
- [[wiki/ServiceNow|ServiceNow]]
- [[wiki/Siemens|Siemens]]
- [[wiki/Siemens Energy|Siemens Energy]]
- [[wiki/SINET|SINET]]
- [[wiki/Skild AI|Skild AI]]
- [[wiki/Southwest Power Pool|SPP — Southwest Power Pool]]
- [[wiki/SpaceXAI|SpaceXAI]]
- [[wiki/Supermicro|Supermicro]]
- [[wiki/SUSE|SUSE]]
- [[wiki/Synopsys|Synopsys]]
- [[wiki/Technology Association of Georgia|TAG — Technology Association of Georgia]]
- [[wiki/TENEX.AI|TENEX.AI]]
- [[wiki/Together AI|Together AI]]
- [[wiki/Torq|Torq]]
- [[wiki/TrendAI|TrendAI]]
- [[wiki/United States Department of War|U.S. Department of War]]
- [[wiki/Upwind|Upwind]]
- [[wiki/Veeam|Veeam]]
- [[wiki/Veracode|Veracode]]
- [[wiki/Vultr|Vultr]]
- [[wiki/Wiz|Wiz]]
- [[wiki/Worley|Worley]]
- [[wiki/Zscaler|Zscaler]]
## Roster reconciliation — the 55 logos omitted from the press release
The logo placard and the press release are not interchangeable partner lists. A name-by-name comparison finds **52 of the 107 placard identities somewhere in NVIDIA's release text and 55 placard identities that never appear there at all**. The downloadable newsroom PDF repeats the same release rather than supplying a second complete directory. For those 55 entities, the placard on NVIDIA's official platform page is the controlling NVIDIA evidence of launch-ecosystem inclusion.
The 55 placard-confirmed, press-release-omitted participants are:
- [[wiki/1Password|1Password]]
- [[wiki/Absolute Security|Absolute Security]]
- [[wiki/AgenticSOC Alliance|AgenticSOC Alliance]]
- [[wiki/Akamai|Akamai]]
- [[wiki/Bedrock Data|Bedrock Data]]
- [[wiki/Bitdeer|Bitdeer]]
- [[wiki/Bohr Quantum|Bohr Quantum]]
- [[wiki/Check Point Software Technologies|Check Point Software Technologies]]
- [[wiki/Cloud Security Alliance|Cloud Security Alliance]]
- [[wiki/Cloudflare|Cloudflare]]
- [[wiki/Crosspoint Capital|Crosspoint Capital]]
- [[wiki/Crusoe|Crusoe]]
- [[wiki/DeepInfra|DeepInfra]]
- [[wiki/DigiCert|DigiCert]]
- [[wiki/DigitalOcean|DigitalOcean]]
- [[wiki/Dream|Dream]]
- [[wiki/Eclypsium|Eclypsium]]
- [[wiki/EQTY Lab|EQTY Lab]]
- [[wiki/Everseen|Everseen]]
- [[wiki/ExtraHop|ExtraHop]]
- [[wiki/F5|F5]]
- [[wiki/Firmus|Firmus]]
- [[wiki/Forescout|Forescout]]
- [[wiki/Fortanix|Fortanix]]
- [[wiki/Fortinet|Fortinet]]
- [[wiki/IREN|IREN]]
- [[wiki/JFrog|JFrog]]
- [[wiki/Lambda|Lambda]]
- [[wiki/LangChain|LangChain]]
- [[wiki/Lightning AI|Lightning AI]]
- [[wiki/Mistral AI|Mistral AI]]
- [[wiki/monday.com|monday.com]]
- [[wiki/National Technology Security Coalition|National Technology Security Coalition]]
- [[wiki/Netskope|Netskope]]
- [[wiki/Nous Research|Nous Research]]
- [[wiki/Okta|Okta]]
- [[wiki/Opaque Systems|Opaque Systems]]
- [[wiki/OpenWorker|OpenWorker]]
- [[wiki/Orca Security|Orca Security]]
- [[wiki/ReversingLabs|ReversingLabs]]
- [[wiki/RSAC|RSAC]]
- [[wiki/SailPoint|SailPoint]]
- [[wiki/SentinelOne|SentinelOne]]
- [[wiki/SINET|SINET]]
- [[wiki/Technology Association of Georgia|Technology Association of Georgia]]
- [[wiki/TENEX.AI|TENEX.AI]]
- [[wiki/Torq|Torq]]
- [[wiki/TrendAI|TrendAI]]
- [[wiki/United States Department of War|United States Department of War]]
- [[wiki/Upwind|Upwind]]
- [[wiki/Veeam|Veeam]]
- [[wiki/Veracode|Veracode]]
- [[wiki/Vultr|Vultr]]
- [[wiki/Wiz|Wiz]]
- [[wiki/Zscaler|Zscaler]]
This distinction matters because image-only confirmation is still official confirmation, but it carries less detail. No uniform integration claim has been inferred for these participants. When a participant published its own launch material, that separate source can establish a more specific role: [[wiki/Absolute Security|Absolute Security]] describes Agentic Resilience work on OpenShell and Sentry; [[wiki/Bedrock Data|Bedrock Data]] describes an available Agent DLP supervisor-middleware integration that returns data-aware policy decisions for OpenShell to enforce; [[wiki/SentinelOne|SentinelOne]] identifies itself as a key collaborator focused on tamper-resistant and attestable runtime governance; and [[wiki/TrendAI|TrendAI]] describes extending the platform with threat intelligence, model and tool inspection, data controls and BlueField/DOCA-backed detection.
### Prose-only project and other non-roster names
[[wiki/OpenClaw|OpenClaw]] is the inverse edge case: NVIDIA names the open-source project in the release among organizations and projects working with platform technologies, and NVIDIA's platform FAQ identifies OpenClaw as a supported agent, but OpenClaw has no logo on the 107-entity placard. It is therefore recorded as an official prose-listed project without being miscounted as a placard company. Intel is also named in the release as a third-party compute platform to which OpenShell can be extended; the release does not present Intel as one of the launch partners, and Intel has no placard logo. The Open Secure AI Alliance, Linux Foundation and SAFE are linked ecosystem or governance initiatives rather than placard participants.
## Documented development tracks
NVIDIA's launch materials identify several relationships more precisely than the ecosystem image alone. Anthropic's Claude Managed Agents add a server-side boundary between the agent loop and execution sandboxes, with OpenShell and BlueField integrations adding controls around access through those sandboxes. SpaceXAI is using the platform with Cursor coding agents and Grok models. Scale AI is incorporating the platform into the agentic infrastructure layer of Scale GenAI Portfolio. Salesforce integrated OpenShell with Slack for activity review, audit events and permission approvals, while SAP is embedding OpenShell in the Joule Studio runtime, contributing engineering work and pursuing interoperability through the [[wiki/Open Secure AI Alliance|Open Secure AI Alliance]].
Armadin says it is contributing to OpenShell and using the platform's layered controls for offensive security agents whose authorized scope must remain enforceable in production environments.
Figure, Gecko Robotics and Skild AI are building with OpenShell for autonomous systems that act in the physical world. Citi and JPMorganChase are collaborating on shared open-source agent-safety technologies. Hitachi Energy, EPRI, NextEra Energy, Quanta Services, Southwest Power Pool, Schneider Electric, Siemens Energy and Worley form the named critical-infrastructure energy track. Canonical, SUSE and Red Hat form the named operating-system integration track, with Red Hat running OpenShell and DOCA through Red Hat AI Factory with NVIDIA. Baseten, Cisco, CoreWeave, Dell Technologies, GMI Cloud, HPE, HP Inc., Irregular, Lenovo, Microsoft, Nebius, Oracle Cloud Infrastructure, Supermicro and Together AI form the named AI-infrastructure solutions track.
The platform's contributions also support the [[wiki/Open Secure AI Alliance|Open Secure AI Alliance]], a Linux Foundation-governed initiative established with more than 120 organizations to advance open research, skills and tools for agent security. The alliance's adjacent work includes the [[wiki/Shared AI Findings Exchange|Shared AI Findings Exchange]], or SAFE, which is distinct from the Open Agent Safety Platform itself.
## Relationships
- **developer and convener:** [[wiki/NVIDIA|NVIDIA]].
- **software runtime:** [[wiki/NVIDIA OpenShell|NVIDIA OpenShell]].
- **reference-design watchdog:** [[wiki/NVIDIA Sentry|NVIDIA Sentry]].
- **hardware enforcement substrate:** [[wiki/BlueField-4|NVIDIA BlueField-4]].
- **programmable DPU software:** [[wiki/NVIDIA DOCA|NVIDIA DOCA]].
- **optimized CPU path:** [[wiki/NVIDIA Vera CPU|NVIDIA Vera CPU]].
- **technical domains:** [[wiki/Agentic AI|Agentic AI]], [[wiki/AI Safety|AI Safety]], [[wiki/Cybersecurity|Cybersecurity]], and [[wiki/Security Engineering|Security Engineering]].
- **open ecosystem:** [[wiki/Open Secure AI Alliance|Open Secure AI Alliance]] and [[wiki/Shared AI Findings Exchange|Shared AI Findings Exchange]].
- **interpretive source article:** [[articles/Safety Discourse Is Transition Discourse|Safety Discourse Is Transition Discourse]].
## Sources / Provenance
- [NVIDIA — Open Agent Safety Platform](https://www.nvidia.com/en-us/solutions/ai/agent-safety/) — official platform description and 107-logo ecosystem graphic.
- [NVIDIA Newsroom — “NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment,” September 28, 2026](https://nvidianews.nvidia.com/news/open-agent-safety-platform) — launch, component descriptions, named integrations and ecosystem tracks.
- [NVIDIA Technical Blog — “NVIDIA Open Agent Safety Platform: A Reference for Continuous In-Silicon Agent Monitoring,” September 28, 2026](https://developer.nvidia.com/blog/nvidia-open-agent-safety-platform-a-reference-for-continuous-in-silicon-agent-monitoring/) — architectural principles and implementation layers.
- [Jensen Huang on X, September 28, 2026](https://x.com/JensenHuang/status/2104499465055023424) — supplied launch statement framing the platform as an open trust layer for the AI economy.
- [NVIDIA OpenShell repository](https://github.com/NVIDIA/OpenShell) — open-source runtime and Apache 2.0 license.
- [Absolute Security — “Embedded AI Control Drives Greater Resilience,” September 28, 2026](https://www.absolute.com/blog/embedded-ai-control-drives-greater-resilience) — partner-published detail for a placard-only participant.
- [Bedrock Data — OpenShell Agent DLP integration, September 28, 2026](https://www.businesswire.com/news/home/20260928728577/en/) — partner-published detail for a placard-only participant.
- [SentinelOne — “Governing AI From Silicon to Runtime,” September 28, 2026](https://www.sentinelone.com/blog/sentinelone-and-nvidia-governing-ai-from-silicon-to-runtime/) — partner-published detail for a placard-only participant.
- [TrendAI — platform extension announcement, September 28, 2026](https://newsroom.trendmicro.com/2026-09-28-TrendAI-TM-Extends-the-NVIDIA-Agent-Safety-Platform-with-Threat-Intelligence-and-Full-AI-Factory-Security) — partner-published detail for a placard-only participant.
- [Armadin — “Safe Autonomous Security: Armadin Joins NVIDIA Agent Safety Platform,” September 28, 2026](https://www.armadin.com/blog-posts/safe-autonomous-security-armadin-joins-nvidia-agent-safety-platform) — partner-published OpenShell contribution and deployment detail.
- [OpenAI — “Introducing OpenAI,” December 11, 2015](https://openai.com/index/introducing-openai/) — founding distribution language.
- [OpenAI — “Planning for AGI and Beyond,” February 24, 2023](https://openai.com/index/planning-for-agi-and-beyond/) — gradual-transition and iterative-deployment doctrine.
- [OpenAI — “OpenAI and NVIDIA Announce Strategic Partnership,” September 22, 2025](https://openai.com/index/openai-nvidia-systems-partnership/) — separate systems relationship; not evidence of platform participation.
**As of:** 2026-09-28