← AI Switchboard
AI Switchboardby Waggle
SAFETY · September 28, 2026
Sep 28

Nvidia puts the agent watchdog on the network card, out of the agent's reach

The Open Agent Safety Platform pairs an open-source sandbox runtime with a monitor that runs on data processing units rather than on the host the agent controls. The architectural argument is the whole product: put the observer on the only path between the node and the model, so a compromised host cannot switch it off.

The two halves do different jobs. OpenShell is an open-source secure runtime for running autonomous agents in sandboxed environments with kernel-level isolation: before an agent starts, the operator's instructions are compiled into verifiable policies covering files, networks, tools, processes and credentials. It runs at the application layer, on the host.

Sentry is the part that answers this edition's lead story. It runs out-of-band on BlueField-4 data processing units, which Nvidia positions on the node's only path to the model, correlating agent interactions, policy decisions and tool and data access into a record of what the agent did. Nvidia's technical blog states the design intent plainly: “The controls do not live inside, or within reach of the agent. The agent does not need to know it is being watched.” That is a direct answer to an arrangement where the sandbox controls and the monitoring pipeline both sat inside the environment being watched.

Read the timing claim carefully. Nvidia says that if an agent tries to move outside its boundary, Sentry “quarantines and stops it in milliseconds”. That is the company's own assertion about its own product, with no published measurement, no benchmark and no third-party evaluation — and the technical blog, read separately, carries no latency or overhead numbers at all. What is verifiable here is the topology, not the speed. An observer on the network card is genuinely outside the blast radius of a host compromise in a way a host-resident monitor is not.

Nvidia lists more than 100 participating organisations, including Anthropic, Cisco, CrowdStrike, Hugging Face, JPMorganChase, Microsoft, Palantir, Scale AI and SpaceXAI. Partner lists of this kind measure interest, not deployment, and only one of them describes actually building on the reference design. The platform is presented as a reference design rather than a finished product, which means the security properties will depend on how each integrator wires policy to telemetry.

  • Confirmed Nvidia announced the Open Agent Safety Platform on 28 September, combining OpenShell, an open-source sandboxed agent runtime, with Sentry, an out-of-band monitor running on BlueField-4 DPUs. NVIDIA Newsroom
  • Claimed “Sentry quarantines and stops it in milliseconds” — Nvidia's own assertion, with no benchmark or third-party measurement published, and no latency figures in either of its documents. NVIDIA Newsroom
  • Confirmed Nvidia names more than 100 participating organisations, including Anthropic, Microsoft, CrowdStrike, Hugging Face, JPMorganChase, Palantir, Scale AI and SpaceXAI. NVIDIA Newsroom

Safety, security & governanceAgents in the wild

Today in the September 28, 2026 edition · front page