Nvidia has built a system that watches every action an AI agent takes and can freeze it within milliseconds if it strays outside its assigned task, the company said in its own announcement. The system, called Nvidia Open Agent Safety Platform, pairs open source runtime software named OpenShell with a hardware watchdog named Sentry that runs on Nvidia’s own networking chips, sitting outside the agent entirely so the agent cannot see or disable it.

Nvidia’s own announcement lists more than 100 organizations working with the platform’s technologies, among them Anthropic, Microsoft, Salesforce, JPMorganChase and SpaceXAI, the AI unit tied to Elon Musk’s companies. That roster is Nvidia’s own claim about its own launch, not independent confirmation that any of these companies has deployed the platform. Even so, it signals that large enterprise buyers now expect a guardrail sitting outside the model, not just a promise baked into the model’s training, before they hand agents real authority over money, code or infrastructure.

OpenShell is the software layer. It sets a boundary around how an agent executes tasks on Nvidia’s Vera CPU, tracing every action and enforcing policy at the operating system level rather than inside the model or the coding harness wrapped around it. Because it is open source, Nvidia says OpenShell can also run on chips from Arm and Intel, a concession that the safety layer needs to work across a market Nvidia does not fully control.

Sentry is the hardware piece, and it is the part of the platform actually doing the millisecond quarantine. It runs on Nvidia’s BlueField-4 networking chips as an “out-of-band” watchdog, meaning it operates on separate silicon the agent cannot reach or reason about. Nvidia says Sentry can detect an agent moving outside its permitted boundary and stop it in milliseconds, combining threat detection with identity verification and access control for the data and tools an agent touches.

Anthropic built its own layer on top of this. The company’s Claude Managed Agents already run the agent’s decision loop on a separate server from the sandbox where the work actually executes, and Nvidia’s tools extend that separation down into hardware. “Claude Managed Agents gives companies a clear view of what each agent is doing, and NVIDIA’s platform adds another layer of governance and control across hardware and software,” said Paul Smith, Anthropic’s chief commercial officer.

SpaceXAI is applying the platform to Cursor coding agents and Grok models running on its infrastructure. “Safety should be enforced outside the model by additional controls the agent can’t get past,” said Mike Nicolls, president at SpaceXAI. Scale AI is folding the same technology into its enterprise and government product line, with chief executive Francis deSouza describing the goal as “isolation, policy enforcement and auditability built in from the start.”

Nvidia is effectively selling both the chips agents run on and the layer that polices those chips, a dual role that makes its safety claims worth reading as vendor claims first. The announcement does not include independent measurements of how often OpenShell blocks a legitimate agent action by mistake, or how it holds up against attack techniques its designers did not anticipate. Those numbers, not the roster of partner logos Nvidia counts at over 100, are what would actually validate the platform.

The framing also puts Nvidia in a different lane from OpenAI and Google, both of which have leaned on training time alignment work to keep their own agents in bounds. Nvidia is instead selling enforcement as a hardware property, something a customer can point to in an audit regardless of which model is running on top. For any enterprise about to give an agent write access to production systems, the open question is whether that hardware boundary holds up under a determined attacker faster than Nvidia can patch it, and no benchmark in this announcement answers that yet.

Reported from Nvidia’s own press release on nvidianews.nvidia.com, a post the company published without a listed date.