Nvidia has launched the Open Agent Safety Platform, designed to restrict what AI agents can access and stop them when they attempt to exceed those permissions. According to the company, its hardware monitoring component can quarantine agents within milliseconds.
More than 100 organisations are working with the platform’s technologies, including Anthropic, SpaceXAI, Salesforce and JPMorganChase. The initiative covers security across software, computing infrastructure and robotics, reflecting the growing challenge of controlling AI systems that can take action across connected environments.
For businesses adopting AI agents, the announcement addresses a practical question: how can organisations give autonomous systems enough access to perform useful work while maintaining control over their actions?
The platform combines two components. OpenShell provides the software boundary, running agents in isolated environments and enforcing policies that define which files, networks, tools, processes and credentials they can access. Those limits are checked before execution and enforced while agents work.
Sentry adds an optional, independent monitoring layer on Nvidia’s BlueField-4 data processing units. Its controls operate separately from the agent’s execution environment, creating an additional point of intervention if software restrictions are breached. Nvidia’s reference architecture pairs this hardware protection with OpenShell running on Vera CPUs.
The participating companies illustrate several enterprise use cases. Anthropic is adding access controls around Claude Managed Agents, while SpaceXAI is using the platform for Cursor coding agents and Grok models. Salesforce’s Slack integration lets teams review agent activity and approve or reject requests for additional permissions. JPMorganChase and Citi are collaborating on shared open-source agent safety technology.
The underlying engineering principle is that an agent’s security controls should sit outside its own decision-making process. Nvidia describes how agents can drift from their intended scope when faced with ambiguous instructions, missing tools or repeated unsuccessful attempts to complete a task. Its proposed response combines isolation, enforceable permissions and independent oversight.
For engineering leaders, this makes access design a central part of AI implementation. A customer support agent, for example, may need to read account information and prepare a response. Issuing refunds, changing contractual details or exporting customer records introduces different consequences and should involve separately defined permissions and approval steps.
The same reasoning applies to coding agents. Reading a repository, modifying a development branch and deploying to production represent distinct levels of authority. Treating them as separate capabilities makes it easier to control exposure and determine who is responsible when something goes wrong.
Rapid containment is valuable, but the permissions being enforced still need to be designed carefully. An agent can cause an unwanted outcome while remaining within access that was granted too broadly. Teams evaluating these tools should therefore examine policy configuration, activity records, escalation procedures and recovery alongside detection speed.
From Control F5 Software’s perspective, the practical implication is clear: agent security belongs in the architecture from the start. As AI systems gain the ability to change data and trigger operational workflows, successful adoption depends on explicit boundaries, traceable actions and a tested way to intervene.
We have helped 20+ companies in industries like Finance, Transportation, Health, Tourism, Events, Education, Sports.