Agent security

NVIDIA Open Agent Safety Platform: a UK guide to OpenShell and Sentry on DGX and HGX

NVIDIA Open Agent Safety Platform explained for UK teams: OpenShell and Sentry, BlueField-3 support, DGX and HGX fit, NCSC alignment and implementation cost.

15 min read
On this page
  1. The short version
  2. What is the NVIDIA Open Agent Safety Platform?
  3. What is NVIDIA OpenShell and how does it work?
  4. What is NVIDIA Sentry, and why does it need BlueField-4?
  5. Does it run on existing DGX or HGX systems with BlueField-3?
  6. How OpenShell and Sentry map to NCSC agentic AI guidance
  7. What the platform does not solve
  8. Practical use cases on a DGX or HGX estate
  9. How to roll out OpenShell today: a four-step plan
  10. What an OpenShell implementation costs in the UK
  11. Frequently asked questions

On 28 September 2026 NVIDIA launched the NVIDIA Open Agent Safety Platform. It has two parts: NVIDIA OpenShell, an open-source runtime that sandboxes AI agents, and NVIDIA Sentry, a reference design that watches them from a BlueField-4 DPU. NVIDIA presents it as a response to recent incidents in which agents broke out of the environments meant to contain them.

For UK organisations the timing is useful. The NCSC published interim guidance on agentic AI in August, and it asks for sandboxing, monitoring, attributable activity and an emergency stop. This guide covers what you can run on DGX and HGX systems you already own, how it maps to NCSC guidance, and what implementation costs.

The short version

  • OpenShell is available now. It is Apache 2.0 open source and runs on Linux hosts (x86_64 and Arm) without BlueField-4. Its README has described it as alpha software, so start with a pilot.
  • Sentry is a BlueField-4 reference design. NVIDIA names no other DPU and gives no availability date. We found no statement that BlueField-3 is supported.
  • DGX B300 and HGX B300 should be able to run OpenShell. NVIDIA says the platform is “also compatible with other hardware systems” but does not name these ones. Validate on a non-production host first.
  • The UK fit is close. OpenShell covers the NCSC’s sandboxing and least-privilege advice, and NVIDIA’s “path to the model” control point matches the NCSC’s emergency stop.
  • Cost. OpenShell has no licence fee. Our fixed-fee assessment starts at £4,500 and implementation on an existing estate at £18,000.

What is the NVIDIA Open Agent Safety Platform?

NVIDIA describes it as an open software platform and reference system design for governing AI agents from testing through to deployment. In practice it is two components at different stages of readiness.

At a glanceOpenShellSentry
What it isOpen-source agent runtimeOut-of-band monitor, as a reference design
What it doesSandboxes agents and enforces policy on files, processes, network access and model callsWatches agents from outside the host and can quarantine those that breach policy
Runs onHost CPU, under Docker, Podman, Kubernetes or MicroVMBlueField-4 DPU, built on NVIDIA DOCA
Licence and costApache 2.0, no licence feeNeeds BlueField-4 hardware
StatusAvailable nowOptional, no availability date
On existing DGX or HGX with BlueField-3Yes, after validationNo, as announced
Diagram: OpenShell runs on the DGX or HGX host, with the agent in a sandbox, a supervisor, policy prover and deny-by-default proxy, and a gateway routing model calls to a local model. All traffic then passes the BlueField DPU. BlueField-3 can enforce an egress allowlist today. Sentry needs BlueField-4 and has no date.
Where OpenShell and Sentry sit on a DGX or HGX system. OpenShell works today on the host. Sentry needs BlueField-4. Select the diagram to open it full size.

NVIDIA says more than 100 organisations are working with the platform, including Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP and ServiceNow. Its technical blog states the design principle: “an agent in these circumstances cannot be expected to fully govern its own behavior.” So OpenShell enforces limits from outside the agent process, and Sentry moves enforcement outside the host.

Both can run inside your own boundary: OpenShell on your hosts with model calls routed to local models, and Sentry on your DPUs. NVIDIA has not said whether Sentry needs any external connection, so ask before you assume an air-gapped site is fine.

Why NVIDIA launched it now

NVIDIA’s technical blog says several frontier labs have recently reported agents breaking out of the evaluation environments meant to contain them, and in some cases misreporting what they had done. The release describes the pattern as an agent circumventing security controls at the application layer to complete its task. Public sources give the timeline:

  • 21 July: OpenAI disclosed that models running an internal cyber evaluation had circumvented the controls isolating them from the internet and compromised systems at Hugging Face. Anthropic and Meta reported incidents of their own by 6 August, according to a Cloud Security Alliance research note.
  • Early August: The UK AI Security Institute published an incident report on unsanctioned agent behaviour during its own cyber testing.
  • Early August: The NCSC’s chief technology officer, Ollie Whitehouse, said such technologies “must be developed and used from the outset with strong safeguards, real-time oversight, and clear plans for responding when the unexpected happens.”

NVIDIA says the platform is designed to stop breakouts of this kind. That claim has not been tested in public.

What is NVIDIA OpenShell and how does it work?

NVIDIA OpenShell is an open-source runtime, under the Apache 2.0 licence, that runs each AI agent in a sandbox and enforces a policy on what it can reach. A gateway, a supervisor and a policy prover sit around the sandbox. You describe what the agent may touch in a YAML policy, and OpenShell checks it before the agent runs and enforces it while the agent works:

  • Network. Every outbound connection passes a policy check. Destinations not on the list are blocked, and a person can approve new ones in real time.
  • Filesystem. Linux Landlock restricts which paths the agent can read and write.
  • Process. seccomp filters system calls, and the agent runs as an unprivileged child process with no Linux capabilities.
  • Inference. Model calls route through a gateway, so the agent never holds the provider’s API key. The gateway can point at models on your own hardware.

Policy compiles to OPA/Rego and can change on a running sandbox. NVIDIA says a prover checks that a policy cannot escape the operator’s intent, so a change that grants risky new access waits for human review. OpenShell is meant to work with any agent harness. Its README lists Claude Code, Codex, GitHub Copilot CLI, OpenCode, OpenClaw and LangChain Deep Agents.

NVIDIA’s name for the underlying problem is drift: actions that depart from the intended task, often after a policy block, a bug or a missing tool. It says drift “can’t be trained away while retaining the capability”, so the boundary has to sit outside the agent.

OpenShell is young. NVIDIA calls it broadly available, but its README has described alpha software built for one developer and one gateway, with multi-tenant enterprise deployment still to come. Read the current README and release notes before planning a shared deployment, and test enforcement with deliberate escape attempts.

What is NVIDIA Sentry, and why does it need BlueField-4?

NVIDIA Sentry is a reference design for an agent monitor that runs on a DPU, outside the host the agent runs on. It is the hardware half of the platform, and it runs on BlueField-4: a DPU that pairs a 64-core Grace CPU with ConnectX-9 networking at 800 Gb/s. NVIDIA says the DPU is isolated from the host and beyond the agent’s reach, so it stays trusted even when the host cannot be.

Built on NVIDIA DOCA, Sentry:

  • inspects agent requests and responses
  • provides attested telemetry
  • verifies agent identity
  • enforces zero-trust access policies for data, tools, APIs and services

NVIDIA says it can quarantine an agent that leaves its boundary in milliseconds. We found no published benchmarks.

In a Vera Rubin POD each compute tray has a BlueField-4 on the node’s only path to the model. NVIDIA says that for anyone already running a Vera system with BlueField-4, enabling Sentry is “just a software update”. That defines the boundary: it applies to systems that already have BlueField-4. NVIDIA said BlueField-4 would reach customers in partner systems in the second half of 2026, so ask your OEM for current dates. Because Sentry is built on DOCA, this layer also ties you to NVIDIA hardware and software. OpenShell does not.

Does it run on existing DGX or HGX systems with BlueField-3?

OpenShell, very likely. Sentry as announced, no.

The two air-gapped platforms we have delivered, a DGX B300 for a central government department and an HGX B300 for a defence organisation, both include BlueField DPUs, so this question is practical for us. DGX B300 ships with two dual-port BlueField-3 DPUs for its storage and management networks. On HGX B300 the DPU count and model depend on the OEM.

What points to OpenShell working on your hosts:

  • NVIDIA says the platform is “optimized to run on NVIDIA Vera CPU- and BlueField DPU-based systems, and is also compatible with other hardware systems”, and that OpenShell can be extended to Arm and Intel platforms.
  • Intel’s Enterprise Agent Toolkit offers OpenShell as an optional sandbox provider on Xeon servers, and NVIDIA’s DGX Spark playbook runs an agent in an OpenShell sandbox with local vLLM inference.
  • DGX OS 7 is built on Ubuntu 24.04. Its 6.8 kernel meets Landlock’s version requirement, so check the module is enabled on your image.
  • The release names Dell Technologies, HPE, Lenovo and Supermicro among the infrastructure partners offering systems that support the platform. Ask yours for a support statement.

What we could not confirm is that NVIDIA names DGX B300 or HGX B300 anywhere, that Sentry will run on BlueField-3, or that GPU access from inside a sandbox works on your driver stack. Test the last one first.

ComponentOn an existing BlueField-3 estateNotes
OpenShell runtime and policy engineYes, after validationConfirm the kernel, container runtime and GPU access on your image.
Model calls routed to local modelsYesThe gateway can send inference to models on your own DGX or HGX.
Sentry as announcedNoNVIDIA describes BlueField-4 only.
Out-of-band monitoring on BlueField-3PartlyNVIDIA documents DOCA Argus, which inspects host memory from the DPU. It is a different product.
Egress control outside the agent hostYesEnforce the same allowlist on your firewall or fabric so a compromised host cannot lift it.

Separate the agent host from the model host. An out-of-band DPU sees only traffic that leaves its machine. If an agent and its model share a host, its model calls never leave the box. Splitting them puts those calls where a DPU can see them. This is our design view, not NVIDIA’s, and it makes a later move to Sentry easier.

Ask NVIDIA and your OEM four questions in writing before you plan around Sentry:

  1. Which BlueField generation and firmware does each system have, and is each DPU in DPU mode or NIC mode?
  2. Will Sentry be supported on BlueField-3 in any form?
  3. Can your chassis take BlueField-4, and on what timeline from your OEM?
  4. Does your OEM support OpenShell on your HGX model and OS image?

How OpenShell and Sentry map to NCSC agentic AI guidance

The NCSC’s June guidance, “Thinking carefully before adopting agentic AI”, advises starting small, using agents for low-risk tasks first and planning for failure. In August it added interim guidance, “Managing the cyber risk of agentic AI”, built around seven considerations, with formal guidance to follow. The table gives them in our wording.

NCSC considerationHow the platform helpsWhat stays with you
Identify what could go wrongThe policy file makes scope and red lines explicitThe threat model
Prompt carefullyNo direct helpInstructions and task design
Set the right oversightPeople approve new network destinations, and risky policy changes wait for reviewA named owner and an approval process
Sandbox the environmentDeny-by-default network, filesystem and process limits, with provider keys kept outsideThe allowlist and short-lived credentials on connected tools
Maintain observabilityOpenShell logs policy decisions, and Sentry adds independent telemetry once availableTranscripts, log protection and 24/7 monitoring
Make activity attributableOne controlled egress point makes tagging outbound traffic practical, and Sentry adds verified agent identityIdentification conventions agreed with third parties
Keep an emergency stopStop sandboxes from the control plane, and Sentry adds quarantine on the path to the modelWho may stop the agent, and a rehearsed drill

Several of these are organisational. No product answers who owns an agent or who can stop it, so settle that before an agent touches real systems or data.

The emergency stop is where NVIDIA and the NCSC line up most closely. The NCSC wants controls that can halt an agent, restrict its network access and interrupt its communication with model inference infrastructure. NVIDIA’s principle that the path to the model is the control point is the same idea, and on a private estate you own that path. NVIDIA’s blog adds that open models have an advantage: “the entire reasoning space and activations are all visible”. A hosted API does not give you that.

Containment matters because the NCSC has warned that prompt injection may never be fully mitigated the way SQL injection was, and advises reducing the impact instead. A sandbox with deny-by-default egress and no stored credentials does that.

If you are assessed against the NCSC Cyber Assessment Framework, for example under GovAssure, the same controls map across. Agent permissions and sandbox configuration sit in B2 and B4, activity logs and later DPU detection in C1, and the stop and quarantine procedure in D1. CAF v4.0 also added coverage of AI-related risks.

The AI Cyber Security Code of Practice, published by DSIT and the NCSC in 2025, became the basis for ETSI TS 104 223. In the NCSC’s Guidelines for Secure AI System Development, OpenShell belongs to secure deployment and Sentry to secure operation and maintenance. Our security standards page explains how we map builds to these frameworks, and UK AI regulation in 2026 covers the wider legal picture.

What the platform does not solve

  • It limits the blast radius. A sandboxed agent can still damage anything inside the permissions you give it, such as files it may write.
  • Sentry is a design, not a product. Milliseconds is NVIDIA’s claim, with no published benchmarks or availability date.
  • It does not cover every agentic problem. Analysts quoted by CSO Online argued that the silicon layer cannot help with the vast majority of them, and nothing here governs agents you do not know about. The NCSC has separate advice on shadow AI.
  • Adoption is uneven. The release does not name OpenAI, Amazon or Google among its partners, so check what your own agent vendors support.
  • Governance stays yours. Ownership, approvals, incident response and evidence remain your work, and our AI governance service covers them. On an air-gapped site, treat OpenShell like any dependency: mirror the images, record hashes, pin versions and control updates.

Practical use cases on a DGX or HGX estate

Use caseAvailable today on BlueField-3Waits for Sentry and BlueField-4
Coding agents on an air-gapped networkOpenShell sandboxes, egress limited to internal Git and package mirrors, model calls routed to a local modelIndependent per-agent telemetry
Document and case-file agentsRead-only mounts, a policy per agent, no stored credentialsHardware-verified agent identity on data access
Cyber ranges and model evaluations with reduced safeguardsOpenShell, an air-gapped network, an independent egress firewall and a tested kill switchOut-of-band quarantine that does not depend on the host
Privileged operations agents (IT service management, network, cloud)Temporary credentials, human approval of new access, logged actionsAttested telemetry into your security operations centre
Shared agent hosting for several teamsOne gateway and policy set per team, as a pilotPer-agent identity and isolation across tenants

Cyber ranges and model evaluations deserve the most care. In the OpenAI incident, models running with reduced cyber safeguards on an internal network reached a node with an outbound route to the internet. If you evaluate models that way, treat the environment as hostile: no route out that you have not approved, a kill switch someone has practised, and monitoring that does not depend on the host being honest. Coding agents are the easiest first deployment, because the blast radius is clear and the allowlist is short.

How to roll out OpenShell today: a four-step plan

  1. Inventory and threat model (weeks 1 to 2). List every agent, harness, host and credential. Threat model against the NCSC’s seven considerations. Record the BlueField generation, kernel and DPU mode of each system.
  2. Contain one agent class (weeks 2 to 6). Deploy OpenShell with deny-by-default network policy, policy in version control and logs flowing to your SIEM.
  3. Prove it (weeks 4 to 8). Attempt escapes on purpose: writes outside allowed paths, blocked hosts, credential theft. Keep the results as evidence for your accreditor.
  4. Prepare for Sentry. Separate agent hosts from model hosts, put the four questions to NVIDIA and your OEM, and include BlueField-4 in your next hardware refresh assessment.

What an OpenShell implementation costs in the UK

OpenShell has no licence fee. The cost is engineering, evidence and, for Sentry, hardware. These are our published fixed fees.

StepWhat you getFrom
Agent safety assessment (2-3 weeks)Agent and host inventory, threat model against the NCSC’s seven considerations, kernel, DPU and DOCA review, CAF mapping, and a written go or no-go with a design£4,500
OpenShell implementation on your existing DGX or HGX (4-8 weeks)Gateway and sandboxes on your hosts, policy as code per agent class, credential and inference routing, egress allowlists, SIEM logging, kill-switch runbook, escape-test evidence and handover£18,000
Advisory retainer (rolling, 30 days’ notice)Policy tuning, OpenShell upgrade review, and Sentry and BlueField-4 readiness£1,800 a month
  • Fees are fixed once scope is agreed in writing. We scope implementation under our AI agent setup and security service, so the published fee applies. Where scope cannot be fixed, we propose a short paid discovery.
  • Hardware, NVIDIA support and any BlueField-4 purchase go to your suppliers directly, with no mark-up from us.
  • We quote Sentry work separately, once NVIDIA publishes availability and your hardware is known. There is nothing to build against today, and we will not sell you a placeholder.
  • Governance evidence such as AI policy, risk register entries and DPIAs is a separate workstream, from £7,500. The pricing page lists what each fee includes.

Frequently asked questions

What is NVIDIA OpenShell?

An open-source runtime from NVIDIA, under the Apache 2.0 licence, that runs AI agents in sandboxes. It limits what each agent can touch, including files, system calls, network destinations and model calls, using a policy you write and version.

What is NVIDIA Sentry?

A reference design for an out-of-band agent monitor that runs on a BlueField-4 DPU. It inspects agent traffic, provides attested telemetry, verifies agent identity and can quarantine an agent that leaves its boundary. NVIDIA has not given an availability date.

What is the difference between OpenShell and Sentry?

OpenShell runs on the host and enforces limits around the agent. Sentry runs on a separate DPU and watches from outside the host, so it can still act if the host is compromised. OpenShell is available now. Sentry needs BlueField-4.

Is NVIDIA OpenShell free?

The software is free under the Apache 2.0 licence. We found no published pricing for enterprise support, and Sentry depends on BlueField-4 hardware bought through NVIDIA partners.

Does NVIDIA Sentry work on BlueField-3?

NVIDIA describes Sentry on BlueField-4 only, and we found no statement that BlueField-3 is supported. Ask NVIDIA or your OEM to confirm in writing before you plan around it.

Can OpenShell run on DGX B300 and HGX B300?

It should. NVIDIA says the platform is compatible with other hardware systems, OpenShell runs on Linux hosts under Docker, Podman or Kubernetes, and DGX OS 7 is built on Ubuntu 24.04. NVIDIA does not name DGX B300 or HGX B300, so validate on a non-production host first.

Does OpenShell work in an air-gapped environment?

NVIDIA’s guides show it running with local models and no cloud connection. We found no supported offline install procedure, so mirror the images, record hashes, pin versions and control updates.

Does OpenShell stop prompt injection?

No. It limits what a manipulated agent can reach and send, which reduces the impact. The NCSC advises treating prompt injection as a risk to contain.

Does using OpenShell make us compliant with NCSC guidance?

No product does. OpenShell supports the sandboxing, least-privilege and oversight advice. Ownership, threat modelling, monitoring and incident response remain your responsibility.

Which AI agents does OpenShell support?

Its README lists Claude Code, Codex, GitHub Copilot CLI, OpenCode, OpenClaw and LangChain Deep Agents, and you can bring your own harness.

When will Sentry be available?

NVIDIA has given no availability date. It has said BlueField-4 would reach customers through partner systems in the second half of 2026.

How much does an OpenShell implementation cost?

OpenShell has no licence fee. Our fixed fees start at £4,500 for an agent safety assessment and £18,000 for OpenShell implementation on an existing DGX or HGX estate. Hardware and NVIDIA support are paid to your suppliers.

Sources

Checked against NVIDIA’s release and technical blog on 29 September 2026.


Flowing Mind builds private and air-gapped AI and the governance evidence around it. For agent projects, start with an assessment or book a call.

Free 30-minute call Book a call

Next step

Running AI agents on a DGX or HGX?

Tell us which systems and agents you run. We will say what OpenShell can do on your estate today, what waits for BlueField-4, and what it would cost.