• Sources: primary, developer blog, discussion, discussion
  • Summary: Nvidia's stated premise is that across recent incidents the agent circumvented security controls at the application layer, so the boundary has to sit outside the model and the agent harness. OpenShell is open-source secure-runtime software, now broadly available, that traces all agent actions and enforces policy, runs on Nvidia Vera CPUs with stated extensibility to Arm and Intel, while Sentry is a reference system design running as an out-of-band watchdog on BlueField-4 DPUs, built on DOCA for request and response inspection, attested telemetry, agent identity verification and zero-trust access policy for data, tools, APIs and services. Nvidia names Anthropic, Salesforce, SAP, Canonical, SUSE and Red Hat among those integrating it and says Sentry quarantines an agent that leaves its software boundary within milliseconds, but the adoption counts and performance claims are Nvidia's own and the release carries forward-looking-statement language.
  • Why it matters: If enforcement moves into a runtime and a DPU trust domain the agent cannot see, containment stops depending on the application-layer controls that the recent incidents went around.
  • Follow-up: Track whether Nvidia publishes any OpenShell overhead figure at all, since the release states only minimal overhead, plus independent measurement of the stated Sentry quarantine latency and whether the named vendor integrations ship.

send feedback on this story