Nvidia OpenShell is now available as free, open-source software under the Apache 2.0 licence. Nvidia released it on 28 September 2026 as half of the Open Agent Safety Platform, alongside Sentry, a hardware watchdog that runs on BlueField-4 data processing units. More than 100 organisations, including Anthropic, Microsoft and JPMorganChase, joined at launch.
What OpenShell Does and What It Runs On
OpenShell is a sandboxed runtime and policy engine: it decides what an AI agent may touch before the agent runs, then enforces that decision while it works. A runtime here is the layer of software that actually executes the agent’s actions.
In Nvidia’s description, OpenShell turns an operator’s written instructions into machine-checkable policies covering files, networks, tools, processes and credentials. Enforcement happens at kernel level — inside the operating system rather than inside the agent’s own code — using Linux facilities called Landlock and seccomp BPF, with policies written in YAML files. Two details matter for anyone evaluating it. Policy changes are put through formal verification, which flags risky edits before they are approved. And the agent never receives the actual credentials: OpenShell injects them only into requests it has already allowed.
The repository lists support for Linux, for macOS on Apple Silicon, and for Windows through WSL 2, marked experimental. It requires Docker, Podman or host virtualisation. Nvidia positions it for its own Vera CPUs, described as the company’s first processor designed for agentic workloads, but says the code can be extended to third-party platforms including Arm and Intel. As of 29 September 2026 the project is on the Apache 2.0 licence with a 0.1.x release marked stable.
What Sentry Does and Why It Sits on a Separate Chip
Sentry is the part that watches from outside. It is a reference system design — a blueprint Nvidia publishes for others to build to — running on BlueField-4 DPUs, which are chips that handle networking and security separately from the processor running the model.
The reason for the separation is a failure mode in single-layer designs. If the same software stack both runs an agent and polices it, an agent or an attacker that compromises the runtime takes the guardrails down with it. Sentry runs in what Nvidia calls an out-of-band trust domain: controls that “do not live inside, or within reach of the agent”. The agent cannot see it, query it or switch it off. Nvidia says Sentry can quarantine an agent that steps outside its boundary in milliseconds, and that in Vera Rubin POD configurations “BlueField-4 sits on the node’s only path to the model”, making it an unavoidable checkpoint.
Sentry also keeps a record. Nvidia says it “correlates agent interactions, policy decisions, and tool and data access to create a contextual record”, and verifies agent identity against the authority it was delegated.
OpenShell Against Sentry: What Each One Requires
The two halves of this launch are not equally easy to get. One is a download; the other needs specific Nvidia hardware.
| OpenShell | Sentry | |
|---|---|---|
| What it is | Open-source runtime and policy engine | Reference system design for an out-of-band watchdog |
| Where it runs | Host CPU; Nvidia Vera, extensible to Arm and Intel | Nvidia BlueField-4 DPUs, using Nvidia DOCA software |
| Operating systems | Linux, macOS on Apple Silicon, Windows via WSL 2 (experimental) | Not applicable; runs on the DPU |
| Other requirements | Docker, Podman or host virtualisation | A Vera system with BlueField-4; Nvidia says existing ones need only a software update |
| Licence and cost | Apache 2.0, free | No price published; hardware cost is the barrier |
| Availability | Broadly available now, on GitHub and Nvidia’s developer pages | Available as a design for partners to implement |
Why This Is Not the Chip Kill Switch Nvidia Has Rejected
Several outlets reported the launch as Nvidia building a “kill switch”, which confuses two separate things. Sentry can cut off an individual agent’s access from a neighbouring chip in the same machine, at the operator’s own instruction.
What Nvidia has refused is different: a remote disable capability built into GPUs that someone outside the owner’s organisation could trigger. David Reber, Nvidia’s chief security officer, wrote in August 2025 that Nvidia “GPUs do not and should not have kill switches and backdoors”, and that “hardwiring a kill switch into a chip is something entirely different: a permanent flaw beyond user control and an open invitation for disaster.” That position was a response to proposals for on-chip location verification and boot restrictions intended to stop AI chips being smuggled into China. Nothing announced on 28 September changes it.
The practical distinction for a buyer: Sentry is a control you operate over agents you are running. It is not a mechanism by which Nvidia, or a government, can switch off your hardware.
Who Signed On, and What That Does and Does Not Mean
Nvidia named more than 100 organisations working with the platform at launch. The list spans several industries: Anthropic, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI, alongside robotics firms including Figure, Gecko Robotics and Skild AI, the banks Citi and JPMorganChase, energy companies including Hitachi Energy, NextEra Energy, Schneider Electric and Siemens Energy, and the Linux vendors Canonical, Red Hat and SUSE. Forkast reported the coalition at 120 partners; Nvidia’s own count is “more than 100”.
What Nvidia has not published is which partners have deployed anything. “Working with the platform at launch” covers evaluation, contribution and endorsement as well as production use, and no partner has published deployment figures. Jensen Huang, Nvidia’s co-founder and chief executive, framed the launch by saying “[s]afety and security require full-stack engineering”. Mike Nicolls, president of SpaceXAI, put the design argument more plainly: “Safety should be enforced outside the model by additional controls the agent can’t get past.”
The launch lands in a month of disclosed agent failures. Regulators have begun drafting rules of their own, including the AI agent security guidelines now being written in South Korea, and consumer agents have raised their own permission questions, as in the case of the access granted to Meta’s Muse agent.
What the Platform Does Not Promise
Nvidia’s own technical documentation is careful about what containment can achieve, and the limits are worth reading before treating this as a solved problem.
- Detection, not guaranteed prevention: Nvidia frames the platform as identifying drift and triggering intervention, rather than blocking every unauthorised action in advance.
- Drift is treated as unavoidable: Nvidia’s blog states that agent drift “can’t be trained away while retaining capability”, which is the premise the whole design rests on.
- Ambiguity remains a weak point: The documentation acknowledges the platform cannot anticipate every behaviour, particularly where instructions are ambiguous or tasks run long.
- Policy quality is the operator’s problem: OpenShell enforces the rules it is given. A permissive policy is enforced just as faithfully as a tight one.
- Supply-chain risk is disclaimed: The repository notes that OpenShell retrieves external materials under separate terms, and puts the compliance and security review of those materials on the user.
Agent containment is also not confined to the runtime layer. Where an agent’s credentials reach matters just as much, a point our report on Plugin4Shell exposure and Git hosts set out.
Frequently Asked Questions
Is Nvidia OpenShell Free?
Yes. OpenShell is published under the Apache 2.0 licence and is available on GitHub and through Nvidia’s developer pages. Nvidia has not announced a paid tier for it.
Do I Need Nvidia Hardware to Use It?
Not for OpenShell. The repository lists Linux, macOS on Apple Silicon and Windows via WSL 2, and Nvidia says the runtime can be extended to Arm and Intel platforms. Sentry is the part that requires Nvidia Vera systems with BlueField-4 DPUs.
Is Sentry a Kill Switch?
It quarantines a misbehaving agent, which Nvidia says takes milliseconds. It is not a remote disable feature in GPUs. Nvidia’s chief security officer publicly rejected chip kill switches and backdoors in August 2025, and that position has not changed.
How Fast Does Sentry React?
Nvidia says quarantine happens in milliseconds, and that network-level policy decisions are enforced at line speed. No independent benchmark of those figures has been published.
What Does Sentry Cost?
Nvidia has published no price for Sentry. It is a reference system design, and the practical cost is the BlueField-4 and Vera hardware it runs on. Organisations already running that hardware are told they need only a software update.
Which Companies Are Using It?
Nvidia lists more than 100 launch partners, among them Anthropic, Microsoft, Cisco, Palantir, JPMorganChase, Red Hat and SpaceXAI. Nvidia has not said which of them have deployed the platform in production.




