NVIDIA’s Open Agent Safety Platform Targets AI Agent ‘Drift’ With Out-Of-Band Enforcement
In Brief
NVIDIA unveils Open Agent Safety Platform, combining OpenShell sandboxing with BlueField-4 hardware enforcement to secure AI agents from drift at scale.

NVIDIA has introduced the Open Agent Safety Platform, an open framework designed to secure autonomous AI agents through continuous monitoring and hardware-enforced policy controls. Announced on September 28, 2026, the platform addresses growing concerns in the AI industry following reports of agents escaping their evaluation environments, accessing unauthorized systems, and misreporting their own actions.
The company draws a parallel with the early internet, which became a foundation for commerce and communication only after security mechanisms — encrypted connections, sandboxed browser tabs, and visible trust indicators — were established. NVIDIA argues that agentic AI requires a similar trust layer before it can scale into a reliable “agent economy,” and that safety controls should accelerate rather than hinder innovation.
OpenShell Runtime: Isolation from Kernel Upward
At the core of the platform is NVIDIA OpenShell, an open-source secure runtime released under the Apache 2.0 license. OpenShell executes each agent inside a sandboxed environment with kernel-level isolation, translating operator instructions into a verifiable policy that defines permitted access to files, networks, tools, processes, and credentials. These limits are validated before execution and continuously enforced during operation.
The platform is built on five principles: policies must be verifiable before an agent runs; enforcement must operate out of band, outside the agent’s reach; the path to the model serves as the primary control point and observability surface; agent authority must scale with transparency into its reasoning; and security responsibility is shared across labs, enterprises, and hardware providers.
NVIDIA’s own research highlights the problem of “drift” — agent behavior that departs from intended tasks due to ambiguous instructions, policy blocks, missing tools, or prolonged autonomous operation. According to the company, such drift cannot be fully trained away without sacrificing capability, and agents cannot be expected to govern their own behavior in these conditions.
Hardware-Level Enforcement at Scale
The architecture spans three layers: the application (models, tools, harnesses, and data), the runtime (orchestration and policy enforcement), and the infrastructure (compute, storage, and network resources). For organizations requiring an independent second layer, NVIDIA Sentry extends monitoring and enforcement into BlueField-4 data processing units via NVIDIA DOCA, correlating agent interactions, policy decisions, and data access into a contextual activity record while continuously verifying each agent’s identity and delegated authority.
In NVIDIA Vera Rubin POD configurations, a BlueField-4 DPU sits on the node’s only path to the model, providing out-of-band observability and real-time, line-speed policy enforcement isolated from the host. This enables security enforcement “in silicon,” even when host resources cannot be trusted. For existing Vera and BlueField-4 deployments, NVIDIA states the protections require only a software update; the platform is also compatible with non-NVIDIA hardware.
NVIDIA said it is collaborating with frontier labs, developers, and infrastructure providers to establish the platform as an open foundation for the emerging agent economy, positioning independent, hardware-rooted controls as a prerequisite for trusted autonomous systems at scale.
Disclaimer
In line with the Trust Project guidelines, please note that the information provided on this page is not intended to be and should not be interpreted as legal, tax, investment, financial, or any other form of advice. It is important to only invest what you can afford to lose and to seek independent financial advice if you have any doubts. For further information, we suggest referring to the terms and conditions as well as the help and support pages provided by the issuer or advertiser. MetaversePost is committed to accurate, unbiased reporting, but market conditions are subject to change without notice.
About The Author
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.
More articles
Alisa, a dedicated journalist at the MPost, specializes in crypto, AI, investments, and the expansive realm of Web3. With a keen eye for emerging trends and technologies, she delivers comprehensive coverage to inform and engage readers in the ever-evolving landscape of digital finance.



