Nvidia's Sentry Watchdog Runs on BlueField-4, With No Price or Date
Hardware / news
Nvidia's Sentry Watchdog Runs on BlueField-4, With No Price or Date
The hardware half of Nvidia's Open Agent Safety Platform is a reference design, while only the OpenShell runtime can be downloaded today.

Nvidia announced Sentry on Sept. 28, a watchdog that runs on its BlueField-4 data processing units and can quarantine a misbehaving AI agent in milliseconds. The company gave no price, no ship date and no latency figure for the hardware half of the platform.
The piece that shipped that day is software. Nvidia's launch announcement says the Open Agent Safety Platform, including the OpenShell runtime, is available through its developer pages and GitHub, while Sentry is described as a reference design. More than 100 organisations are working with the platform, the company said.
Two layers, and only one has a download link
The design splits agent safety into a runtime inside the host and a monitor outside it. A data processing unit (DPU) is a separate chip on the network card that handles traffic and storage independently of the host processor. Sentry lives there, built on Nvidia's DOCA software, in what Nvidia calls an isolated, out-of-band trust domain.
| Layer | Runs on | Job | Status on Sept. 28 |
|---|---|---|---|
| OpenShell | Host CPU, including Nvidia's Vera | Sandbox and policy boundary for the agent | Open source, available now |
| Sentry | BlueField-4 DPU | Watches agent behaviour from outside, quarantines it | Reference design, no price or date |
The OpenShell repository carries an Apache 2.0 licence and had 10.6k stars when fetched on Sept. 29. Its front page lists kernel-level sandboxing, policy checks on files, system calls and network connections, and credential handling that keeps real secrets away from the agent. It runs on Linux, on macOS with Apple Silicon, or on Windows through WSL 2, which is experimental. That page does not mention Sentry or BlueField.
The argument for putting the check outside the model
Mike Nicolls, president of SpaceXAI, gave the design rationale in Nvidia's release: "Safety should be enforced outside the model by additional controls the agent can't get past." The physical separation is the point. An agent that can rewrite its own sandbox policy cannot rewrite a monitor that sits on a different chip with its own trust domain.

Founder and Chief Executive Jensen Huang framed it more broadly: "AI's extraordinary potential for society will only be realized if we solve AI safety." Paul Smith, Anthropic's chief commercial officer, said companies are giving agents more of their most important work and "need to direct and verify what those agents do." Anthropic connected the platform to Claude Managed Agents, according to the Mad Robot report.
What the launch leaves out
Every performance claim in the release is a vendor claim. "Milliseconds" spans a factor of a thousand. A quarantine at 2 milliseconds and one at 900 milliseconds are different products for an agent issuing thousands of API calls a second, and the release states neither the number nor the request rate it was measured at.
The partner list is also selective. Nvidia named Anthropic, Microsoft, Salesforce, JPMorganChase, Palantir, SpaceXAI, Figure and Scale AI, among others. OpenAI does not appear in the list Nvidia published. A Bush Letter analysis points out that OpenAI's models power a large share of the agents running on Nvidia hardware, and that Nvidia offered no explanation. The Mad Robot report, which lists the partners it could identify, also names no Google, Meta or Amazon.
The denominator matters as well. BlueField-4 sits on the network path, so it sees what leaves the machine: API calls, storage access, traffic. It does not see what an agent does entirely inside host memory. The Nvidia release does not say how much of an agent's behaviour Sentry can observe from that vantage, which decides whether it catches a data exfiltration attempt or only a network one.
What would change the read
Three numbers would settle this. A published quarantine latency with the request rate attached, a per-DPU price, and a list of the hosts that can run BlueField-4 in an existing rack. Nvidia is also a lender to its own customers: its $1 billion stake in Nscale's pre-IPO convertible is due in November. On the software side of the same problem, our report on the ten Paperclip advisories covers an agent orchestrator's security record. Until Nvidia ships any of them, Sentry is a design that 100-plus organisations have agreed to look at, and OpenShell is the only part an operator can install on Sept. 29.
If a third party benchmarks the quarantine path and finds it under 10 milliseconds at realistic call rates, the hardware layer becomes a purchasing decision. If it turns out to see only network traffic, it is a firewall with better branding.
Sources
More in Hardware
- 01California's SB 868 Caps Balcony Solar at 1,200 Watts and Puts Compliant Products a Year AwayThe law takes effect January 1, 2027, requires UL-listed devices that stop feeding the grid in an outage, and strips utilities of fees and approvals; its own name is reported two ways.
- 02Amazon Wants Investors to Hold $8 Billion of Its Nvidia Chips and Lease Them BackThe Financial Times reports a special-purpose vehicle with up to 10% equity and the rest in debt; xAI's earlier version of the structure shows who ends up carrying the depreciation.
- 03Tesla's Emergency Drive Away Lets Cars Leave a Supercharger Still Plugged In, Two Months After Twin FallsSoftware update 2026.38.3 lets drivers shift into Drive with the cable latched, at the cost of damage to car and charger that Tesla has not priced.
- 04GM's Equinox EV Fell More Than 90% in Q3, and Two Trackers Disagree on the Unit CountElectrek counts 1,905 Equinox EVs and GM Authority counts 1,705; the two also differ by 3,938 on the Blazer EV, which changes how large Cadillac's share looks.