NVIDIA Open Agent Safety Platform just validated what we’ve been saying for years. Software can’t hold an AI agent. You need a boundary it cannot argue its way past.

NVIDIA Open Agent Safety Platform just validated what we’ve been saying for years. Software can’t hold an AI agent. You need a boundary it cannot argue its way past.


Today NVIDIA launched its Open Agent Safety Platform, built around OpenShell (a secure runtime boundary) and Sentry (a hardware watchdog running on BlueField DPUs that can quarantine a misbehaving agent in milliseconds). More than 100 organizations, including Anthropic, Microsoft, Palantir, and CrowdStrike, are already lining up behind it. 

It has become clear we cannot trust application layer controls to contain autonomous agents. NVIDIA’s own announcement points to the reason why: recent incidents show agents circumventing security controls at the application layer to meet objectives they were given.  

We agree with the diagnosis completely. We’d push the prescription one step further. 

Where the NVIDIA Open Agent Safety Platform Stops Short 

OpenShell and Sentry are a real step forward, and they live inside the compute stack that runs the agent. That works for monitoring and governance at the silicon level. But a boundary built on the same hardware and software ecosystem the agent operates in is still, by definition, a boundary the agent’s environment can influence. If you want a boundary to hold, it can’t live inside the thing it’s guarding, a distinction that matters most in OT threat detection environments like power grid cybersecurity, SCADA network security, and oil and gas cybersecurity, where a single breach cascades into physical consequences. 

The Liability Question for AI Agent Deployments 

That is what a data diode and a Cross Domain Solution give you. Not another layer of monitoring inside the stack, but a physically enforced, non-bypassable checkpoint between the agent and everything on the other side of it. Data moving in or out gets verified against known good policy, not just screened for known bad behavior. There is no software path around it because there is no software involved in the enforcement. It cannot be socially engineered, misconfigured into an open state, or exploited through a flaw in its own implementation, because the mechanism is hardware, not code. 

This is exactly the gap CDS and diodes were built to close, long before “agentic AI” was a category. Owl’s hardware enforced architecture has been built and evaluated to meet the assurance standards required for the most demanding government and regulated environments in the world, and the nuclear industry relies on Owl to meet its own rigorous compliance requirements. Most security vendors were never built to that standard. AI agents now demand it. 

There is also a question every general counsel in this space is about to start asking. When an agent breaches a boundary and causes harm, and courts are still sorting out who bears that liability, “we had a software runtime policy” is a very different answer than “we had a physically enforced boundary and an independent audit trail.” One is a control. The other is a defensible position. 

NVIDIA building this out in the open, with the Linux Foundation and the Open Secure AI Alliance behind it, is good for the entire industry. It puts real weight behind the idea that agent safety has to be enforced outside the model, not requested from it. Policy can be argued with. Hardware can’t.  

If you’re deploying AI agents in environments where a breach isn’t an option, let’s talk about what a hardware enforced boundary looks like for your stack. Contact us to start the conversation. 

 

Frequently Asked Questions 

 

What is the NVIDIA Open Agent Safety Platform?

It’s NVIDIA’s new framework for keeping autonomous AI agents in check. It pairs OpenShell, an open-source secure runtime that enforces policy on what agents can do, with Sentry, a hardware watchdog on NVIDIA BlueField DPUs that can quarantine a misbehaving agent in milliseconds. More than 100 organizations back it, including Anthropic, Microsoft, Palantir and CrowdStrike. 

Where does the NVIDIA Open Agent Safety Platform fall short? 

NVIDIA’s OpenShell and Sentry run inside the same hardware and software ecosystem the agent operates within. That enables valuable silicon-level monitoring and governance — but a boundary built inside the agent’s environment can still be influenced by that environment. Owl’s architecture enforces control from outside the compute stack entirely. 

How is a data diode different from software-based AI agent security?

Software controls run in the same environment as the agent, so they can be bypassed, misconfigured or exploited. A data diode enforces one-way data flow physically, in hardware. Because that guarantee holds at the physical layer regardless of what an agent does. A hardware-enforced boundary like a data diode is critical even when an agent is working to get around its controls. 

When should an organization use a Cross Domain Solution for agentic AI? 

Use one when an AI agent operates across a security or classification boundary, for example, in government, defense, critical infrastructure, nuclear, or other regulated operations. A Cross Domain Solution governs what’s allowed to cross boundaries; checking every piece of data that moves across the boundary against a defined policy and keeping an independent audit trail, giving you a defensible position if you ever have to answer for a breach. 

Insights to your Inbox

Stay informed with the latest cybersecurity news and resources.

Scott Orton CEO, Owl Cyber Defense

The National Cyber Strategy: “Nuclear-Grade” is the Way Forward

Late March 6, 2026, the White House released a new National Cybersecurity Strategy. While the strategy outlines a broad and ambitious roadmap for our digital future, the real challengeÂ...
March 13, 2026
Amalia Rosen

Forrester Report: Zero Trust for Critical Infrastructure

Why Zero Trust Needs Hardware to Secure Critical Infrastructure: Insights from a New Forrester Report In 2025 alone, ransomware attacks on critical infrastructure caused over $10 billion...
February 18, 2026
Daniel Crum Director, Product Marketing

AI’s Role in Defense – Accelerating Decision Dominance in the Next Era of Warfare

"AI is not just another technology. It is a transformative technology that will change the way we fight and defend our nation." Kathleen Hicks, Deputy Secretary of Defense   Techn...
November 26, 2024