NewsStocksNvidia CEO Jensen Huang Unveils Open Agent Safety Platform, a 'Browser' for AI Agents

Nvidia CEO Jensen Huang Unveils Open Agent Safety Platform, a 'Browser' for AI Agents

Author: CryptoBriefing·

Key Takeaways

  • •The Open Agent Safety Platform combines OpenShell, an Apache 2.0-licensed runtime that isolates AI agents in sandboxed environments, with Sentry, a hardware-level enforcement that acts when software controls fail.
  • •The system enforces policy adherence, maintains audit trails for forensic review, and can push policy updates to running agents without shutting them down.
  • •Nvidia claims OpenShell introduces minimal performance overhead on its Vera CPUs, avoiding a steep performance tax for the safety layers.
  • •The platform targets four domains—coding, research, cybersecurity, and operations—where long-running, self-evolving agents make decisions and interact with critical business systems.
  • •More than 100 enterprise software firms, including Adobe, Salesforce, SAP, Microsoft, Red Hat, and Anthropic, had begun integrating Nvidia's agentic platform tools by September.
Nvidia CEO Jensen Huang Unveils Open Agent Safety Platform, a 'Browser' for AI Agents

Nvidia CEO Jensen Huang has unveiled the Open Agent Safety Platform, a two-part system designed to give autonomous AI agents a secure operating environment that he describes as a "browser for agents." Announced on September 28, the platform combines an open-source runtime called OpenShell with a hardware-level monitoring layer named Sentry, creating what Huang frames as a secure space where autonomous AI can operate without going rogue.

The announcement comes as enterprises accelerate deployments of AI agents capable of writing code, conducting research, monitoring cybersecurity, and running complex operations for hours or days at a stretch. Nvidia is betting that the company best positioned to build the guardrails for this shift is Nvidia itself. As those deployments move deeper into daily operations, questions about who supplies oversight—and on what basis it can be verified—have moved with them.

How the Browser Metaphor Works

OpenShell runs AI agents inside sandboxed execution environments, each one isolated the way a browser tab is. Sandboxing is a long-established technique in web browsing: each tab runs in isolation, so if one page crashes or misbehaves, the others keep working. OpenShell applies the same principle to agents. If one agent crashes or starts behaving outside its policy boundaries, the rest continue operating unaffected. The isolation model also underpins other long-standing computing practices, including containerized cloud workloads.

The system enforces strict policy adherence, maintains audit trails, and can push policy updates to running agents without shutting them down. Sentry sits underneath as the hardware-level enforcer, monitoring agent behavior and stepping in when software-layer controls prove insufficient.

Nvidia claims OpenShell introduces minimal overhead on its Vera CPUs, meaning enterprises would not pay a steep performance tax for the added safety layers. The runtime ships under an Apache 2.0 license, a widely used permissive open-source license, leaving developers and organizations free to inspect, modify, and deploy it. In safety tooling, that openness carries particular weight: organizations can examine the enforcement layer itself rather than relying solely on a vendor's description of how it behaves.

"AI's extraordinary potential for society will only be realized if we solve AI safety," Huang said during the announcement.

The Enterprise Ecosystem Taking Shape

The Open Agent Safety Platform did not emerge in a vacuum. Nvidia spent much of 2026 assembling its components. Around March and April, the company released its Agent Toolkit, a package that included the Nemotron 3 Ultra model with 550 billion parameters, purpose-built for the kind of long-running agent workflows that enterprise customers prioritize.

The toolkit also bundled skills libraries: pre-built capabilities that agents can draw on rather than learning from scratch. By September, more than 100 enterprise software firms had begun integrating Nvidia's agentic platform tools into their own products.

The roster reads like a who's-who of enterprise technology: Adobe, Salesforce, SAP, Microsoft, and Red Hat are all contributing to or building on the stack. Anthropic, the safety-focused AI lab behind Claude, is also listed among the partners.

Why Sandboxing Agents Is Harder Than Sandboxing Web Pages

According to Nvidia's description, these agents are designed to be "long-running" and "self-evolving." They can operate for hours or days at a time, make decisions, call external APIs, modify their own behavior based on new information, and interact with critical business systems.

That is precisely why Nvidia paired OpenShell's software-layer sandboxing with Sentry's hardware-level enforcement. Software guardrails can, in principle, be circumvented by sufficiently capable agents; hardware-level monitoring adds a second line of defense that does not depend on the agent's cooperation. Hardware-based controls are an established category in enterprise security, long used for tasks such as cryptographic key protection.

The platform targets four primary domains: coding, research, cybersecurity, and operations—each with its own risk profile. An agent writing code might introduce vulnerabilities, while an agent running cybersecurity operations has, by definition, access to sensitive systems. In this context, the audit trail functionality becomes critical, giving enterprises a forensic record of every decision an agent made and why. Such records are what security and compliance teams rely on when auditors, regulators, or customers ask how an automated decision was reached.

For Nvidia, the positioning is explicit: the maker of the infrastructure agents run on aims to be the layer that restrains them, too. How the platform holds up in production, and how much independent scrutiny OpenShell's openly licensed code attracts, are among the signals to watch as enterprise agent deployments continue to scale.