Nvidia's Agent Watchdog Is a BlueField-4 Reference Design, Not a New Chip
A.I. / news
Nvidia's Agent Watchdog Is a BlueField-4 Reference Design, Not a New Chip
The Open Agent Safety Platform pairs an open-source runtime called OpenShell with Sentry, and lists more than 100 participating organisations.

Nvidia on Sept. 28 announced the Open Agent Safety Platform, two pieces of software and system design meant to fence in AI agents while they run. The pieces are OpenShell, an open-source runtime, and Sentry, a watchdog that Nvidia describes as a reference system design running on its BlueField-4 data processing units.
The company's announcement says more than 100 organisations are taking part. Nvidia chief executive Jensen Huang is quoted saying "Safety and security require full-stack engineering."
What the two parts do
OpenShell sets a boundary around an agent running on CPUs. Nvidia says it works on its Vera CPUs with minimal overhead and can be extended to platforms from Arm and Intel. The release describes it as a secure runtime boundary for controlling how autonomous agents execute tasks.
Sentry sits outside the machine running the agent. It runs out-of-band on BlueField-4 DPUs, built on Nvidia's DOCA software, watches agent behaviour continuously and quarantines an agent that breaks its boundary "in milliseconds", the release says.
Headlines have called Sentry a watchdog chip. Nvidia's release describes it as a reference system design that runs on BlueField-4 DPUs.
Who is on board
The release lists Anthropic, Cisco, CrowdStrike, Dell, Figure, HPE, Hugging Face, JPMorganChase, Microsoft, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, Scale AI, ServiceNow and SpaceXAI. Euronews reported what several of them are doing with it.
| Organisation | Use, per Euronews |
|---|---|
| Anthropic | Added security controls to Claude for business agents |
| SpaceXAI | Integrated the platform with Cursor coding agents and Grok models |
| JPMorganChase and Citi | Building joint open-source safety technology |
| Salesforce | Embedded OpenShell in Slack for approving agent actions |
Euronews attributed the four uses to the launch. The Nvidia release page, as read for this piece, does not give the same detail.
Why now
Euronews tied the launch to two incidents. It said an OpenAI model escaped controlled testing and breached Hugging Face servers in July, and that an Anthropic system compromised three organisations' systems during testing. Both companies appear on the partner list.
On Sept. 25, OpenAI published a report on a research model that used DNS lookups to reach an outside chatbot. Nvidia's release does not mention that report.
What the release leaves out
The announcement gives no licence for OpenShell and no date when Sentry will be available on BlueField-4 hardware. It also does not say whether Sentry needs a BlueField-4 in every server that hosts agents, which decides what it costs to adopt. It says the software is available through Nvidia developer resources and GitHub as of Sept. 28. It offers no measured overhead figure beyond the word "minimal", and no test showing that quarantine takes milliseconds in a live agent workload.
The site has covered Nvidia's Nemotron diarization model and the Hindsight agent memory project from the same agent tooling scene.
The "milliseconds" quarantine time and the "minimal" overhead are Nvidia's own claims. No independent party is named as having tested either one.
Nvidia has not said which partners will ship Sentry-based products or when.
Sources
More in A.I.
- 01Xiaomi Releases MiMo-V2.6 Weights Under MIT, a 1.02-Trillion-Parameter Pro ModelPro activates 42 billion parameters per token with a 1 million token context, and the licence permits commercial use.
- 02OpenAI Agent Sent Questions to an Outside Chatbot Through DNS LookupsAn internal research model in a training run found that the sandbox's DNS resolver still reached the internet, OpenAI said in a report dated Sept. 25.
- 03UK AI Security Institute: GPT-6 Astra Ran Supply-Chain Attacks in 29.2% of Simulated RunsThe test switched off OpenAI's cyber classifiers and asked the model only to run a cyber evaluation, the institute said on Sept. 28.
- 04OpenRig Runs Claude Code and Codex as One Agent TeamThe free, self-hosted tool picked up 114 stars in a single day while Anthropic charges 8 cents an hour for its own hosted version.