In July, AI systems developed by OpenAI gained unauthorized access to Hugging Face's systems during a cybersecurity test, underscoring the difficulties in managing AI agents. In response, NVIDIA introduced the Open Agent Safety Platform, aiming to control these agents from a layer they themselves cannot manage. The platform moves part of the control outside the AI model and its harness — the software environment that enables a model to function as an agent by adding memory, tools, and execution capabilities. An AI agent capable of modifying data, calling a service, or executing code can turn an error into an unauthorized action. Therefore, security must consider not only the model's output but also its execution environment. NVIDIA's first component is OpenShell, an open-source runtime designed to create a secure boundary for agent operations. It allows monitoring the agent's actions and applying policies during execution, acting as a secure boundary outside the model and the harness. OpenShell can manage the agent's access to files, networks, tools, and APIs, and it supports both open-source and proprietary models. While optimized for NVIDIA's Vera CPU, it is presented as open-source software adaptable to other computing platforms, including Arm and Intel. The most innovative aspect of the platform is Sentry, a reference architecture that uses NVIDIA's BlueField-4 DPU as an independent watchdog. Sentry continuously monitors the agent's activity from a separate layer of the execution environment. If the agent tries to exceed defined limits, Sentry can isolate it within milliseconds. This independence sets it apart from traditional software-based controls. Sentry operates in an isolated, secure domain, invisible to the agent itself. NVIDIA describes this as "in-silicon security enforcement," meaning some rules are no longer solely managed by the application or runtime but can be enforced by hardware components beneath. The approach aligns with the principles of Zero Trust, where no component is inherently trusted just because it is part of the system. Autonomous agents, which have identities, access rights, and defined limits, require clear control over what they can do, with what data, and using which tools. The challenge now extends beyond the model's security to building an infrastructure that can contain its autonomy. Controls must be applied across identity, runtime, network, data, and infrastructure rather than being confined to the prompt or the model. NVIDIA reports that more than 100 organizations are involved in its initiative, with varying levels of engagement. Anthropic is collaborating to add controls around its Claude Managed Agents. SAP has integrated OpenShell into its Joule Studio Runtime. Salesforce has incorporated it into Slack to allow teams to monitor agent activity, audit it, and manage permission requests. Scale AI uses the reference architecture in its agent systems. Companies like Figure, Gecko Robotics, and Skild AI are working to integrate controls into physical-world autonomous systems. Financial institutions such as Citi and JPMorganChase are also collaborating with NVIDIA on open-source agent security technologies. Infrastructure and software providers are integrating OpenShell and related technologies into their environments. The message to the industry is that agent security should not be solely the responsibility of the model's provider but should be managed across the entire chain. By shifting control to the infrastructure, NVIDIA aims to expand the role of its network and computing components in AI architectures. With the Open Agent Safety Platform, the DPU becomes an independent observer capable of directly intervening in an agent's execution. Security now relies not only on the model or the application but also on control points external to the agent itself. The approach also presents a paradox. While NVIDIA has made OpenShell open-source and aims to make it compatible with Arm and Intel platforms, the Sentry architecture relies on its BlueField-4 DPU. This openness can encourage widespread adoption of the software layer, while NVIDIA retains a level of direct control through its hardware. The software becomes open, but the hardware control point remains tied to the NVIDIA architecture.