On September 28, 2026, NVIDIA announced the Open Agent Safety Platform, an open software platform and reference design that puts enforceable limits on AI agents in both software and hardware, from the moment an agent is tested to the moment it is deployed. If you run a business that uses AI agents, or you are about to, this is the most important piece of AI infrastructure news you will read this year, and I want to explain why in plain language.
An AI agent is not a chatbot. A chatbot answers you. An agent acts for you. It books the flight, sends the invoice, updates the customer record, and moves money between accounts. The moment we handed AI the ability to act, the question stopped being “is the answer good?” and became “what is this thing allowed to do, and who is watching?”
Until now, the honest answer for most businesses was that the limits lived inside the model itself, in the instructions and training the vendor gave it. That is a bit like asking the new hire to supervise themselves. NVIDIA’s platform moves the supervision outside the model, into a runtime layer the agent runs inside and a hardware watchdog the agent cannot reach. Jensen Huang, NVIDIA’s founder and CEO, put it this way in the announcement: “Safety and security require full-stack engineering.”
The adopter list tells you how seriously the industry is taking this. Anthropic, Microsoft, Salesforce, SAP, ServiceNow, JPMorganChase, Citi, Accenture, Deloitte, HPE, Lenovo, and dozens more signed on at launch, alongside the Open Secure AI Alliance of more than 120 organizations governed by the Linux Foundation. The OpenShell software is open source and available on GitHub today.
How the NVIDIA Open Agent Safety Platform works
The platform works in three layers, and you do not need an engineering degree to follow them. Think of an agent as a contractor you have let into your building. The three layers are the job description, the access badge, and the security guard.
The first layer is the agent itself, running its work on the NVIDIA Vera CPU, which NVIDIA describes as the first CPU purpose built for agentic AI. The agent can be built on any model, open or closed. That matters because most businesses will end up running agents from several vendors, and a safety system that only works with one model would be no safety system at all.
The second layer is NVIDIA OpenShell, the job description and the access badge together. OpenShell is open source runtime software that sets the boundaries an agent operates inside. It defines what the agent may do, traces every action it takes, and enforces policy while the task is running rather than after the fact. NVIDIA says it runs with minimal performance overhead and extends to Arm and Intel processors, so it is not locked to NVIDIA hardware. SAP is embedding it in the Joule Studio runtime, Salesforce is bringing OpenShell management into Slack, and Anthropic is integrating it with Claude Managed Agents.
The third layer is NVIDIA Sentry, the security guard. Sentry is an out of band watchdog that runs on the NVIDIA BlueField-4 data processing unit, in an isolated trust domain that neither the agent nor an attacker can access. It inspects the agent’s requests and responses, verifies identity, and applies zero trust access policies to data, tools, APIs, and services. If an agent tries to exceed the boundaries OpenShell set, Sentry detects it and quarantines the agent in milliseconds. Because Sentry lives in hardware and does not depend on the software layer, a compromised agent cannot simply talk its way past it.
That last point is the whole story. The software layer says what the agent may do. The hardware layer makes sure that promise holds even when the software is under attack.
Why safety has to live outside the model
I learned this lesson with hot dogs.
Years ago, as Co-CEO of a leading computer vision company, I led a large deployment of AI inside a major convenience store chain. One of the requests that came across my desk was to use our cameras to monitor how long the hot dogs had been sitting on the roller warmer. We could do it. We did do it. And it worked beautifully. Then I stood in the store, wearing a staff badge, listening to cashiers and managers, and I asked myself the question that has shaped every AI decision I have made since: just because we can, does it mean we should?
Capability is never the hard part with AI. Boundaries are.
The hot dogs were harmless. The question was not. Because the same capability that watches a warmer can watch an employee, and the same agent that can update a customer record can delete one. Capability is never the hard part with AI. Boundaries are. And for the last three years the industry has been asking the model to hold its own boundaries, through system prompts and training and a great deal of hope.
Anyone who has managed people knows why that fails. You do not ask the new hire to write their own job description, approve their own expenses, and audit their own work. You give them clear permissions, you log what they do, and you make sure someone independent is watching. That is not distrust. It is how trust gets built.
NVIDIA’s platform is the industry finally applying that management wisdom to machines. OpenShell is the job description and the permission set. Sentry is the independent watcher. Neither one relies on the agent being well behaved. As Mike Nicolls, President of SpaceXAI, said in the announcement, “safety should be enforced outside the model by additional controls the agent can’t get past.” That sentence would have saved a great many companies a great deal of grief had it been the standard three years ago.
What this means for your business
You are not going to buy a BlueField-4 DPU for your dental practice or your boutique. You do not need to. The value of this announcement for a small business owner is not the hardware. It is that the tools you already use are about to inherit these controls, and you should expect them.
When Salesforce brings OpenShell management into Slack, the agent that drafts your customer replies will run inside boundaries you can see. When SAP embeds it in Joule Studio, the agent that reconciles your books will be traced. When Anthropic integrates it with Claude Managed Agents, the research assistant your team relies on will have an independent watcher. Within a year, “which safety runtime does your agent run in?” will be a normal question to ask a software vendor, the way “is my data encrypted?” became normal a decade ago.
In the meantime, the principles apply today at any size, and you can implement them this afternoon with the tools you already have. Give every agent the narrowest permissions that let it do its job. If it only needs to read your calendar, do not give it the ability to send email. Keep a log of what your agents do, even if that log is a simple spreadsheet your assistant reviews on Friday. Decide in advance which actions always require a human, and write that list down. Moving money, deleting records, and sending anything to a customer are the three I would start with.
I run my own business this way. My AI agent James manages my inbound email and calendar, and he has a hard boundary: he can decline a speaking request that does not fit, but he cannot accept one. That yes belongs to me. It is a small rule, and it has already saved me from at least one unpaid engagement I would have said yes to in a weaker moment. The agent did not need to be smarter. It needed a boundary it could not cross.
The agent did not need to be smarter. It needed a boundary it could not cross.
Five questions to ask anyone selling you an AI agent
The next time a vendor pitches you an agent, ask these five questions and watch how quickly they answer. First, what is this agent allowed to do, and where is that list written down? A good vendor hands you a permission set. A poor one says “whatever you need.” Second, what happens when it tries to do something outside that list? The answer you want is that the action is blocked and logged, not that the model has been trained to be careful. Third, can I see a record of every action it took last week? If the answer is no, you are flying blind. Fourth, which actions require a human to approve them, and can I change that list myself? Fifth, does the safety enforcement live outside the model, and if so, where?
That fifth question is the one this announcement changes. Six months ago it would have drawn a blank stare. Six months from now, the vendors worth working with will answer “OpenShell” or name something equivalent without hesitation. Until then, the fact that you asked will tell them what kind of customer you are, and that is worth something on its own.
The human side of the leash
I have spent two decades teaching people that boundaries are not the opposite of freedom. They are what makes freedom safe to use. A child with a fenced yard plays further from the house than a child with no fence at all, because the fence removes the fear. The same is true of the people on your team, and it turns out to be true of the machines we are now inviting onto that team.
Most of the anxiety I hear about AI agents, from CEOs and from solopreneurs alike, is not really about intelligence. It is about control. “What if it does something I did not ask for?” That is a fair fear, and for the last three years the industry’s answer has been “trust us, it is well trained.” NVIDIA’s platform, and the Open Secure AI Alliance behind it, offer a better answer. Trust the boundary, not the behaviour. Verify, then delegate.
Trust the boundary, not the behaviour. Verify, then delegate.
That is also, if I am honest, how I have learned to run my own life. When the terrain shifts, and it has shifted more in the last eighteen months than in the previous eighteen years, the people who adapt well are not the ones who fear the change or the ones who surrender to it. They are the ones who decide what they will and will not allow, write it down, and then move forward with confidence. Adapt to your terrain. Set the fence. Then let the agents run.
If your organization is working out how to bring AI agents into the business without losing control of it, this is the conversation I have with leadership teams and conference audiences every week as a female AI keynote speaker and AI founder. You can check my availability here.
