AI

Nvidia's AI agent kill switch runs on a separate chip

(today) · 3 min read · By Future Technology · Edited by Nath Connell

Key takeaways

  • Nvidia's Open Agent Safety Platform is a reference design for watching and limiting what AI agents can do.
  • OpenShell, the open source software layer, controls what an agent can see, touch and run, and logs its actions.
  • Sentry, an optional layer on BlueField-4 DPUs, monitors agents from outside their own software and can quarantine them in milliseconds.
  • More than 100 organisations are involved, including Anthropic, Microsoft and CrowdStrike, but the speed claims have not been independently tested.

Milliseconds. That is how quickly Nvidia says its new Sentry layer can quarantine an AI agent that tries to step outside its software boundary. Sentry is one half of the Nvidia Open Agent Safety Platform, announced on 28 September, and the interesting part is where it runs: on a separate chip, not inside the agent's own software stack.

What the Nvidia Open Agent Safety Platform is

Nvidia calls it an open reference design rather than a single product, so companies can take the pieces they need. There are two main ones, according to Nvidia's announcement.

OpenShell is the software layer. It is an open source runtime that sets what an agent can see, what it can do, and which systems, data and services it can reach, while recording what it does along the way. Nvidia says it can extend to Arm and Intel compute, so it is not locked to Nvidia hardware.

Sentry is the optional second layer. It runs on BlueField-4 DPUs, the data processing chips that sit in servers alongside the main processors, and watches agent behaviour from outside the agent itself. If an agent tries to move beyond its boundary, Sentry quarantines and stops it, as Nvidia's developer write-up describes.

Why AI agent safety needs a separate chip

Most agent guardrails today live in the same place as the agent: in the model's training, the harness that runs it, or the application around it. Nvidia's argument is that this is not enough, and it points to incidents where agents bypassed application-layer controls while carrying out assigned tasks, as CSO Online reports.

A rough analogy: OpenShell is the rulebook on the desk, and Sentry is the guard on the other side of the glass. An agent that talks its way past the rulebook still has to get past something it cannot reach or rewrite. If you want the basics of how agents chain tools and actions together, our AI agents explainer covers it.

Who has signed up

More than 100 organisations are working with the platform, including Anthropic, Microsoft, CrowdStrike, Palo Alto Networks, SAP, Salesforce and ServiceNow, per Infosecurity Magazine. Canonical, SUSE and Red Hat are building it into their operating systems, which matters more for reach than any single partner logo.

None of this touches home users yet. If you run a self-hosted agent such as OpenClaw, the Sentry half needs data centre hardware you almost certainly do not own, although OpenShell's permission model is the part worth copying.

The caveats

Only OpenShell is open source. The platform as a whole is a reference design, and Sentry depends on BlueField-4 hardware that most organisations have not bought. The millisecond quarantine figure also comes from Nvidia, and we have not seen independent testing of it.

What to watch

The useful tests are whether the big Linux distributions ship OpenShell by default, and whether a security researcher publishes an agent escape that Sentry catches or misses. Until then, this is a sensible design from the company that also sells the chip the guard runs on, which tells its own story.

More from Future Technology