NVIDIA secures agents beyond the model with OpenShell and Sentry
NVIDIA has introduced Open Agent Safety Platform, an architecture that places execution boundaries outside the model. OpenShell enforces policies in an open runtime, while Sentry adds isolated monitoring on BlueField-4 DPUs. The announcement moves agentic security from prompts to a software-and-hardware control chain.
1. An execution boundary separate from the agent
OpenShell, now announced as generally available, traces actions and controls what an agent may read, write, execute, or reach over the network. NVIDIA says the software is open source and can be extended to third-party platforms, including Arm and Intel. Control is therefore not intended to depend solely on model instructions or the agent framework.
Sentry is a separate reference design: it monitors activity out of band on BlueField-4 DPUs and can quarantine an agent that leaves its boundaries. NVIDIA links this mechanism to agent identity, attested telemetry, and granular zero-trust policies for data, tools, APIs, and services. Availability must be distinguished: OpenShell software is available, whereas Sentry depends on a hardware architecture and vendors' integration schedules.
2. What this changes for a Belgian or French company
For an SME, the announcement chiefly supplies an architecture principle: an agent connected to Odoo, a CRM, or RAG should never carry its own guardrails alone. A sandbox, dedicated identity, tool allowlist, and exportable log remain necessary even without NVIDIA hardware.
For a mid-market company, large enterprise, or public administration, applying a common boundary across multiple models and frameworks could simplify hybrid operations. Security teams can define where an agent runs, which secrets and endpoints it reaches, and what evidence it leaves. In regulated sectors, this layer may support auditability without proving compliance, data residency, or supply-chain control on its own.
3. Underside analysis: sovereignty includes the control plane
OpenShell's openness supports inspection and portability, while Sentry's proposed hardware control also strengthens reliance on a specific stack. A sovereign architecture should therefore separate its requirements: data location and encryption, model portability, runtime control, local administration, log export, and the ability to replace each component.
For an Odoo agent or MCP workflow, the runtime should check permissions at every call, not only at initial connection. For RAG, the origin and version of retrieved documents must also be retained. On Apple Enterprise or other managed devices, user identity and device compliance can complement policy without allowing the agent to inherit every human permission.
4. Test the boundary, not only the answer
A useful pilot should attempt bypasses: access to an unauthorised tool, network exfiltration, secret reuse, privilege escalation, indirect injection through a document, and an irreversible action. Teams should measure blocking rates, false positives, quarantine time, trace quality, and recovery capability.
HPE says OpenShell integration with Private Cloud AI is planned for the fourth quarter of 2026 and describes operation across cloud, hybrid, on-premises, and air-gapped environments. This roadmap confirms industrial interest in the model, but an enterprise should validate the version actually available, its dependencies, and support before making a production commitment.
Operational recommendation: define an “identity, data, tools, network, actions, approvals, evidence, and shutdown” matrix for every agent, then verify that controls remain enforceable even when the model or framework attempts to bypass them.
Frame a governed agent architectureRead NVIDIA's official announcement · Read HPE's official integration analysis