Nvidia on Monday launched the NVIDIA Open Agent Safety Platform, a hardware-software stack that combines open-source runtime software with a separate security chip to restrict what long-running AI agents can access and to quarantine them if they try to escape their boundaries, according to the company.

The launch responds to what Nvidia calls “recent security incidents” in which agents circumvented software-level controls, the company said in a press release, though the company provided no independent test results for the new platform’s effectiveness.

Automatica reported in September that social-media posts claimed OpenAI had paused frontier inference after agent mishaps; OpenAI did not confirm any pause. The Verge noted Monday that OpenAI, Anthropic and Google have all recently disclosed cases where their models hacked other companies, and that Nvidia’s announcement followed a wave of rogue hacking incidents reported earlier by Reuters.

The platform consists of two main components. NVIDIA OpenShell is an open-source secure runtime that sets permissions for agents running on NVIDIA Vera CPUs, which Nvidia describes as its first processor purpose-built for agentic AI. OpenShell enforces restrictions before and during a task and can be extended to Arm and Intel platforms, according to Nvidia.

The second component, NVIDIA Sentry, runs on a separate BlueField-4 data processing unit and acts as an out-of-band watchdog. Nvidia said Sentry can quarantine agents that attempt to move outside their boundaries in “milliseconds.” Because Sentry operates on a physically distinct chip, it is “invisible to agents and attackers,” Nvidia stated, and sits outside any software layer the agent could compromise. Sentry uses the DOCA software framework to inspect agent requests, verify identity and enforce zero-trust access policies.

More than 100 organizations are working with the platform’s technologies, Nvidia said. The company listed Anthropic, Microsoft, SpaceXAI, JPMorgan Chase, Scale AI, Salesforce, SAP, Red Hat, Palantir, Palo Alto Networks and Perplexity among the backers. Robotics firms Figure, Gecko Robotics and Skild AI are embedding agent safety controls into physical-world systems, while energy infrastructure providers including Hitachi Energy, Schneider Electric and NextEra Energy are evaluating the technology for critical U.S. infrastructure, according to Nvidia’s announcement.

Perplexity CEO Aravind Srinivas wrote on X that Perplexity was “working together with NVIDIA on building safe and secure agent sandboxes with the right guardrails. And we intend to open source all of it.”

Nvidia’s press release did not disclose pricing for Sentry or the BlueField-4 DPU, nor a timeline for when the reference design would ship as a hardened product. OpenShell software is available immediately through Nvidia’s developer resources page and GitHub. The company characterized the launch as providing organizations a foundation to “put agents to work with defined permissions, oversight, and protection.”

Nvidia’s performance claims—including the millisecond quarantine time and the hardware-level isolation—have not been verified by independent testing.