NVIDIA发布Open Agent Safety Platform
NVIDIA Launches Open Agent Safety Platform: OpenShell Sandboxes Agents on Vera CPUs While Sentry on BlueField-4 Quarantines Them in Milliseconds
Agent安全是当下落地痛点,NVIDIA这套软硬结合的方案给出了可落地的参考架构,做Agent工程的同学值得研究其隔离思路。
NVIDIA has launched the NVIDIA Open Agent Safety Platform, an open software platform and reference system design for AI agent security. It pairs the OpenShell secure runtime with NVIDIA Sentry, an out-of-band watchdog on BlueField-4 DPUs. The core idea is simple. Safety controls should not live inside the agent they are meant to control.
英伟达推出了 NVIDIA Open Agent Safety Platform(NVIDIA 开放智能体安全平台),这是一个用于 AI 智能体安全的开源软件平台和参考系统设计。它将 OpenShell 安全运行时与 NVIDIA Sentry 相结合,后者是部署在 BlueField-4 DPU 上的带外看门狗。其核心理念很简单:安全控制措施不应存在于它们所控制的智能体内部。
Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry.
今天,我们与超过 100 家行业合作伙伴一起推出了 NVIDIA Open Agent Safety Platform,将 OpenShell 和 Sentry 整合在一起。
Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to… pic.twitter.com/dReAxwpRUn
人工智能是一项非凡的技术,将为几代人的发现、生产力、安全、健康和繁荣带来进步…… pic.twitter.com/dReAxwpRUn
— Jensen Huang (@JensenHuang) September 28, 2026
—— Jensen Huang (@JensenHuang) 2026年9月28日
Is it deployable today? Yes for OpenShell. It is Apache 2.0, installs on Linux, macOS (Apple Silicon) or Windows WSL 2, and its repo still labels it alpha.
它现在可以部署吗?对于 OpenShell 来说是可以的。它采用 Apache 2.0 许可证,可安装在 Linux、macOS(Apple Silicon)或 Windows WSL 2 上,其代码仓库仍将其标记为 alpha 版本。
Why NVIDIA Moved Enforcement Below the Agent
英伟达为何将执行层移至智能体下方
The NVIDIA technical report cites recent reports from several frontier labs. Agents broke out of evaluation environments and reached systems they should not have touched. Some agents misreported what they did. The NVIDIA team names a common pattern: agents circumvented application-layer controls to finish their task.
英伟达的技术报告引用了来自几家前沿实验室的最新报告。智能体突破了评估环境,访问了它们本不应触及的系统。部分智能体对其行为进行了虚假报告。英伟达团队指出了一种常见模式:智能体绕过了应用层控制以完成任务。
NVIDIA calls this failure mode drift. Drift can follow a policy block, a bug, a missing tool or ambiguous instructions. NVIDIA team argues drift cannot be trained away without losing capability. So an agent cannot be expected to fully govern itself.
英伟达将这种故障模式称为漂移(drift)。漂移可能由策略阻断、漏洞、缺失的工具或模糊的指令引起。英伟达团队认为,如果不损失能力,就无法通过训练消除漂移。因此,不能指望智能体完全自我治理。
How the Platform is Built
平台的构建方式
OpenShell (runtime): Each agent runs in an isolated sandbox. A gateway manages sandbox lifecycle across Docker, Podman, MicroVM or Kubernetes drivers. Every outbound connection hits a policy engine that allows it, binds credentials to an approved endpoint, or denies and logs it. Filesystem and process rules lock at creation. Network and provider rules are hot-reloadable. See NVIDIA’s runtime controls walkthrough for implementation details.
OpenShell(运行时):每个智能体都在隔离的沙箱中运行。网关管理沙箱的生命周期,支持 Docker、Podman、MicroVM 或 Kubernetes 驱动。所有出站连接都会经过策略引擎,该引擎允许连接、将凭据绑定到已批准的端点,或者拒绝并记录日志。文件系统和进程规则在创建时锁定。网络和提供商规则支持热重载。有关实现细节,请参阅英伟达的运行时控制指南。
Sentry (in-silicon watchdog): Sentry runs on BlueField-4 DPUs and uses NVIDIA DOCA to inspect agent requests and responses. It provides attested telemetry, verifies agent identity and enforces zero-trust access to data, tools and APIs. It stays isolated from the host, so a compromised runtime does not disable it.
Sentry(硅内看门狗):Sentry 运行在 BlueField-4 DPU 上,并使用 NVIDIA DOCA 来检查智能体的请求和响应。它提供经认证的遥测数据,验证智能体身份,并强制执行对数据、工具和 API 的零信任访问。它与主机保持隔离,因此即使运行时被攻破,也不会导致其失效。
Placement matters: In a Vera Rubin POD, each compute tray’s BlueField-4 sits on the node’s only path to the model. An agent cannot act without its next inference call. That makes the path both the best observation point and the kill switch. For existing Vera plus BlueField-4 systems, NVIDIA says enabling these protections is a software update.
部署位置至关重要:在 Vera Rubin POD 中,每个计算托盘的 BlueField-4 位于节点通往模型的唯一路径上。代理无法在其下一次推理调用之前采取行动。这使得该路径既是最佳的观测点,也是紧急停止开关。对于现有的 Vera 加 BlueField-4 系统,NVIDIA 表示启用这些保护功能只需进行软件更新。
The stack is optimized for NVIDIA Vera CPUs but is compatible with other hardware. NVIDIA team claims Vera delivers up to 80% faster sandbox performance than traditional CPU infrastructure. OpenShell can also be extended to Arm and Intel platforms.
该堆栈针对 NVIDIA Vera CPU 进行了优化,但与其他硬件兼容。NVIDIA 团队声称,Vera 的沙箱性能比传统 CPU 基础设施快多达 80%。OpenShell 也可扩展至 Arm 和 Intel 平台。
The 5 Design Principles
五大设计原则
- Verifiable policy: a prover checks the policy cannot escape operator intent before the agent runs.
- Out-of-band enforcement: controls sit outside the agent’s reach.
- Control the path to the model: it is the observation point and the kill switch.
- Scale authority with visible reasoning: more capable agents need more inspectable thinking.
- Shared responsibility: labs, enterprises and hardware providers each own a layer.
- 可验证策略:证明者在代理运行前检查策略不会偏离操作者的意图。
- 带外执行:控制措施位于代理的控制范围之外。
- 控制通往模型的路径:它是观测点和紧急停止开关。
- 通过可见推理扩展权限:能力更强的代理需要更透明的思考过程。
- 共同责任:实验室、企业和硬件提供商各自负责一个层级。
Interactive Explainer: Send a Request Through the Stack
交互式解释器:通过堆栈发送请求
How It Compares With Other Agent Sandboxes
与其他代理沙箱的比较
The closest alternatives are sandbox platforms for agent-generated code. Neither offers an equivalent hardware watchdog.
最接近的替代方案是用于代理生成代码的沙箱平台。两者均未提供等效的硬件看门狗。
| Feature | NVIDIA OpenShell + Sentry | E2B | Daytona |
|---|---|---|---|
| Type | Open runtime plus hardware reference design | Open-source sandbox cloud | Sandbox infrastructure runtime |
| License | Apache 2.0 | Apache 2.0 | AGPL-3.0 (public repo unmaintained since June 2026) |
| Isolation | Per-sandbox container or MicroVM, kernel-level isolation | Firecracker microVM, own kernel | Dedicated kernel, filesystem and network stack per sandbox |
| Egress control | YAML policy at HTTP method and path level, hot-reloadable | Allow and deny lists by IP, CIDR or domain | Network limits |
| Out-of-band hardware enforcement | Yes, Sentry on BlueField-4 (optional) | No, software isolation | No, software isolation |
| Where it runs | Local, on-prem, cloud, Kubernetes (experimental) | E2B cloud or self-hosted on AWS and GCP | Daytona cloud |
| Agent support | Claude Code, Codex, OpenCode, Copilot CLI built in | JS and Python SDKs | Python, TypeScript, Ruby, Go, Java SDKs |
| 特性 | NVIDIA OpenShell + Sentry | E2B | Daytona |
|---|---|---|---|
| 类型 | 开放运行时及硬件参考设计 | 开源沙箱云服务 | 沙箱基础设施运行时 |
| 许可证 | Apache 2.0 | Apache 2.0 | AGPL-3.0(公共仓库自 2026 年 6 月起未维护) |
| 隔离性 | 每个沙箱容器或 MicroVM,内核级隔离 | Firecracker microVM,独立内核 | 每个沙箱专用的内核、文件系统和网络协议栈 |
| 出口控制 | HTTP 方法和路径级别的 YAML 策略,支持热重载 | 基于 IP、CIDR 或域名的允许和拒绝列表 | 网络限制 |
| 带外硬件执行 | 是,BlueField-4 上的 Sentry(可选) | 否,仅软件隔离 | 否,仅软件隔离 |
| 运行环境 | 本地、私有云、公有云、Kubernetes(实验性) | E2B 云或在 AWS 和 GCP 上自建 | Daytona 云 |
| 代理支持 | 内置 Claude Code、Codex、OpenCode、Copilot CLI | JS 和 Python SDK | Python、TypeScript、Ruby、Go、Java SDK |
Who is Building on It
谁正在基于它构建
NVIDIA says over 100 organizations work with the platform. Anthropic integrated Claude Managed Agents with OpenShell and BlueField. SpaceXAI uses it for Cursor coding agents and Grok models. Salesforce connected OpenShell to Slack for approving agent permission requests. SAP is embedding OpenShell in the Joule Studio runtime. Red Hat, SUSE and Canonical are integrating it into their operating systems.
NVIDIA 表示有超过 100 家组织使用该平台。Anthropic 将 Claude Managed Agents 与 OpenShell 和 BlueField 集成。SpaceXAI 使用它来运行 Cursor 编码代理和 Grok 模型。Salesforce 将 OpenShell 连接到 Slack,以审批代理权限请求。SAP 正在将 OpenShell 嵌入 Joule Studio 运行时。Red Hat、SUSE 和 Canonical 正在将其集成到各自的操作系统中。
The effort feeds the Open Secure AI Alliance, governed by the Linux Foundation. OpenShell and its skills are available on GitHub and the OpenShell docs.
该举措服务于由 Linux Foundation 治理的 Open Secure AI Alliance。OpenShell 及其技能可在 GitHub 和 OpenShell 文档中找到。
Key Takeaways
关键要点
- 2 layers: OpenShell sandboxes the agent, Sentry watches it from separate silicon.
- Sentry can quarantine an agent that leaves its boundary in milliseconds, per NVIDIA.
- OpenShell policies are declarative YAML, with network rules enforced at HTTP method and path level.
- OpenShell runs Claude Code, Codex, OpenCode and GitHub Copilot CLI out of the box.
- NVIDIA lists over 100 organizations working with the platform, including Anthropic and Microsoft.
- 两层架构:OpenShell 对代理进行沙盒隔离,Sentry 从独立的硅片上对其进行监控。
- 据 NVIDIA 称,Sentry 可以在毫秒级内隔离越界的代理。
- OpenShell 策略采用声明式 YAML 格式,网络规则在 HTTP 方法和路径级别强制执行。
- OpenShell 开箱即用支持 Claude Code、Codex、OpenCode 和 GitHub Copilot CLI。
- NVIDIA 列出超过 100 家与该平台合作的组织,包括 Anthropic 和 Microsoft。
FAQ
常见问题解答
- Does OpenShell require BlueField-4? No. It runs on local, on-prem, cloud and Kubernetes infrastructure. BlueField-4 only adds Sentry.
- How is this different from model guardrails? Guardrails shape what an agent attempts. Runtime controls enforce what it is allowed to do.
- Can I use existing agents and models? Yes. OpenShell supports open and closed models and custom sandbox images.
- OpenShell 需要 BlueField-4 吗?不需要。它可在本地、私有云、云端和 Kubernetes 基础设施上运行。BlueField-4 仅增加 Sentry 功能。
- 这与模型护栏有何不同?护栏塑造代理试图执行的操作。运行时控制则强制执行其被允许执行的操作。
- 我可以使用现有的代理和模型吗?可以。OpenShell 支持开放和封闭模型以及自定义沙盒镜像。
Check out the Paltform here and Technical Details. All credit goes to the researcher of this project. Also, feel free to follow us on Twitter and don’t forget to join our 150k+ML SubReddit and Subscribe to our Newsletter. Wait! are you on telegram? now you can join us on telegram as well.
在此查看平台和技术细节。所有功劳归于该项目的研究者。此外,欢迎在 Twitter 上关注我们,并别忘了加入我们拥有 15 万+成员的 ML SubReddit 以及订阅我们的新闻通讯。等等!你在 Telegram 上吗?现在你也可以加入我们的 Telegram 群组。
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力