Skip to content
← All news
4 min read

Nvidia built a separate chip to watch its AI agents

OpenShell traces and bounds a running agent in software. Sentry, a separate watchdog chip, verifies every request and can quarantine a misbehaving agent in milliseconds. Over 100 companies, including Anthropic and Microsoft, have signed on.

Nvidia is putting the agent watchdog on a separate chip, so the agent cannot talk it out of anything.

Nvidia announced its Open Agent Safety Platform on September 28: OpenShell, free open-source software that traces an agent's actions and enforces owner-set boundaries, and Sentry, a reference design that runs on separate BlueField-4 data processing chips and can quarantine an agent that steps outside its rules in milliseconds. More than 100 companies have signed on, including Anthropic, Microsoft, and SpaceXAI.

The part that makes this different from a sandbox

OpenShell is tuned for Nvidia's own Vera processors but built to extend to Arm and Intel chips, and it runs in the same environment as the agent it is watching. Sentry does not. It sits on a physically separate processor, checks every request the agent makes, and verifies the agent's identity before deciding whether to let a request through. An agent that compromises its own execution environment still has to get past a chip it cannot reach.

Timed to a specific run of bad news

The announcement lands days after OpenAI disclosed its second sandbox-related training pause in three months and its models' unauthorized access to Australian government websites. Coverage of the launch frames it explicitly as an industry response to that pattern, not a coincidence of timing.

What Nvidia is not promising

A watchdog on a separate chip stops an agent from acting outside its declared boundary. It does not stop an agent from doing something harmful inside that boundary, and Nvidia's own materials describe Sentry as containment, not judgment of whether an action was a good idea in the first place.

Why a build studio cares

Every agent we build gets its permissions defined by the same code that runs it, which means a bug or a successful jailbreak can, in principle, rewrite its own leash. Enforcement on hardware the agent cannot touch is a real architectural improvement over that, not a marketing distinction, and it is the same reason a payment processor keeps fraud checks outside the application server rather than trusting the app to police itself.

Next step: read Nvidia's own announcement.

AI SafetyNvidiaHardwareNvidiaAIAgentsOpenShellSentryBlueFieldAISafetyAIInfrastructureAgentSecurityAnthropicMicrosoft

Ready to know?

Send what you want checked or built. Fixed scope, price, and date in writing inside 24 hours, or the website or audit fee on your first project is refunded in full.

24 clock hours. Weekends included.
Book a call