All field notes

Infrastructure security

NVIDIA Moves the Agent Security Boundary Off the Host

NVIDIA’s Open Agent Safety Platform makes server topology part of the agent deployment decision: OpenShell is available now, while Sentry is a BlueField-4 reference design for enforcement outside the host CPU.

MP
Max PerfiljevFounder & CEO, AES · Architect of Autonomous Organizations
Read in Russian

NVIDIA’s new Open Agent Safety Platform changes the place where an enterprise can try to stop an agent. The company is not only adding controls around an application or inside a host operating system. Its Sentry reference design puts an optional monitoring layer on a BlueField-4 data-processing unit (DPU), isolated from the host CPU and positioned on the node’s path to the model in NVIDIA’s Vera Rubin POD architecture.

That is the consequential part of the September 28 announcement. Agent security is becoming a server-architecture question: does each meaningful route an agent takes cross an enforcement point outside the workload’s own failure domain?

The announcement combines two very different deliverables. OpenShell 0.1.0 is usable open-source software available now. Sentry is a hardware reference design, not a generally available product. NVIDIA also says that many of the products and features described in its announcement remain at varying stages of development and are not delivery commitments. Those distinctions matter when a platform team decides what it can test today and what it can only plan around.

What changed: enforcement can move beyond the workload

OpenShell provides a runtime boundary around an agent workload. NVIDIA documents sandboxed execution, kernel-level restrictions on filesystems and processes, and a supervisor that runs outside the workload. That supervisor evaluates outbound requests against policy rather than asking the agent process to police itself.

The software can inspect configured HTTP, GraphQL and Model Context Protocol traffic. This gives policy a more useful unit of control than a generic network allowlist: it can distinguish, for example, an API read from an API write. OpenShell can also hold service credentials outside the agent workload and substitute them only when a request is authorized. Its policy decisions are recorded using the Open Cybersecurity Schema Framework, and its policy prover is intended to find modeled permissions that exceed an operator-defined boundary.

These are concrete runtime mechanisms, not only an architectural promise. OpenShell and associated skills are available now as open-source software. SAP says its engineers are contributing to OpenShell and embedding it in SAP Business AI Platform; NVIDIA also identifies adoption work at Cadence, Slack and Gecko Robotics. This is evidence of ecosystem activity, not evidence that any particular deployment has achieved comprehensive protection.

Sentry extends the design beyond host software. NVIDIA describes it as an optional, out-of-band layer intended for BlueField-4. In the stated Vera Rubin POD layout, the DPU is isolated from the host and lies on the path to the model. The purpose is straightforward: if a host workload is compromised, altered or simply misbehaves, a separately situated component may still observe and constrain traffic that has to traverse that path.

What did not change: topology does not erase bypasses

A DPU is not a universal answer to agent risk. It cannot make an agent safe, tamper-proof or inherently unbypassable. Its value depends on the deployment topology, the policies installed on the enforcement layer, and the completeness of the paths routed through it.

That last condition is the hard one. An agent may reach tools, data stores, models and external services through more than one route. Some traffic may remain inside a host, take a separate network interface, use a sidecar, invoke a local process, or cross an integration that was not configured for inspection. OpenShell’s inspection applies to configured HTTP, GraphQL and MCP traffic; that is useful specificity, but it is not a claim to see every possible interaction. A design only gains the protection it can actually place in the path of the relevant operation.

Nor should teams treat the Sentry performance statement as settled operating evidence. NVIDIA says Sentry can quarantine an agent in milliseconds. That is a vendor claim associated with a reference design, not an independently reproduced benchmark. The time that matters in an enterprise deployment will include detection, policy evaluation, network placement, the exact containment action and the routes that remain available after quarantine.

The optimized hardware design is also specific. NVIDIA says OpenShell can be extended to other platforms, while the described optimized architecture uses Vera CPUs and BlueField-4 DPUs. Buyers should not infer identical enforcement characteristics across processors, server layouts or cloud environments from the reference design alone.

The new deployment question is physical as well as logical

Most agent security reviews begin with the application: prompts, tools, identities, credentials, policies and logs. Those remain necessary. NVIDIA’s design adds a different review: map the actual path from the agent workload to each consequential destination, then ask where enforcement survives if the workload or host is no longer trustworthy.

This is not an argument that every agent requires a DPU. Many workloads have modest authority, limited blast radius or established control points at API gateways and service boundaries. But agents that can write to business systems, hold privileged operational credentials, or make broad outbound requests deserve a more exact infrastructure review than “the container is isolated.” A container boundary and a separately located enforcement point are not equivalent failure domains.

For infrastructure and security teams, the practical work is a path inventory rather than a product comparison. Identify every model endpoint, tool endpoint, credential route, administrative channel and fallback path. Mark which flows OpenShell is configured to inspect. For each consequential operation, establish whether an enforcement point outside the workload sees it, whether it can deny it, and what alternate route remains if the host is compromised. Then test the actual failure cases: a policy denial, a killed supervisor, a lost DPU connection, a host-side proxy change and a quarantined workload.

  • Separate available software from announced reference architecture: OpenShell 0.1.0 can be evaluated now; Sentry should be treated as a design input until its delivery and fit are confirmed.
  • Treat credential substitution and operation-aware inspection as deployment configuration, not automatic coverage. Verify which HTTP, GraphQL and MCP routes are configured and which remain outside the boundary.
  • Use the DPU question selectively: for high-consequence paths, ask whether traffic traverses a component isolated from the host and whether that component has a defined deny or quarantine action.
  • Measure containment in the installed topology. Do not substitute a vendor millisecond claim for a test of the paths and actions your environment actually uses.

A useful shift, with a narrow claim

NVIDIA has not delivered a general proof that hardware-separated monitoring solves agent security. It has made a more useful proposition: agent controls need not live entirely inside the agent’s application and host. OpenShell makes part of that proposition inspectable today. Sentry shows how the next layer could be placed in the server’s data path.

For enterprises, the operating consequence is clear. Agent deployment reviews can no longer stop at the runtime manifest or the API gateway. For consequential actions, network topology, host trust and bypass paths are now part of the security decision. The important question is not whether a platform has another guardrail. It is whether the action route crosses a boundary that the agent and its host cannot simply redefine.

BUILD WITH AES

Turn architecture into an operating company.

AES connects strategy, tasks, organizational memory, knowledge, agents, people and approvals in one execution environment.