Nvidia Releases OpenShell AI Agent Access Control Software, Unveils Hardware Monitor Design


TL;DR

  • Agent Controls: Nvidia made OpenShell broadly available for organizations to limit AI-agent access; Sentry remains a hardware monitoring reference design.
  • Runtime Rules: OpenShell confines agents to operator-set file, process and network permissions, enforced outside the agent’s own code.
  • Partner Use: Cisco’s DefenseClaw security tool already integrates OpenShell’s agent limits; broader Hypershield network controls remain under development.

Nvidia has made OpenShell, software that limits what autonomous AI agents can reach on a computer or network, broadly available and unveiled a separate hardware monitoring design called Sentry. Organizations deploying agents can use OpenShell’s software boundary as of the September 28 launch; the extra chip-based layer remains a reference design. An operator could, for example, permit an agent to read from a service while blocking a write to that same service.

OpenShell Moves Beyond Preview

Nvidia’s Open Agent Safety Platform takes an existing runtime beyond preview. The March NemoClaw launch included OpenShell, which Nvidia later described as an early preview. Developers can now get its code and installation resources from a public repository.

NVIDIA Open Agent Safety Platform Reference Design combines NVIDIA OpenShell on NVIDIA Vera and NVIDIA Sentry on NVIDIA BlueField-4

An enterprise agent can run code, read files and call outside services to complete a task. OpenShell puts each agent in a sandbox governed by permissions set by its operator. The software’s gateway manages those sandboxes and their policies; a supervisor outside the agent’s workload checks outgoing requests, while operating-system controls restrict file access and processes inside the sandbox. A model instruction alone cannot change those enforced permissions.

Nvidia’s documented policy example shows a rule that permits a read request to the GitHub API but blocks a write request to the same service. The walkthrough uses a simple command rather than a model to make those requests; an agent in that sandbox would face the same policy check.

Network permissions can be changed while an agent is running after an approval. File and process restrictions are set when its sandbox starts, so changing those requires a new sandbox. For an organization running long-lived agents, that difference determines which access can be adjusted during a task and which calls for a fresh environment.