Nvidia adds identity and delegated authority controls for AI agents | Biometric Update

Nvidia adds identity and delegated authority controls for AI agents | Biometric Update

By Abhishek Jadhav
Publication Date: 2026-09-29 12:22:00

Nvidia is extending its controls for AI agents beyond a software sandbox with a platform that pairs runtime restrictions with an independent hardware monitoring layer.

The Open Agent Safety Platform combines Nvidia’s OpenShell runtime with Sentry, a reference design for monitoring agents independently of the host systems on which they operate.

OpenShell 0.1.0 is available under the Apache 2.0 license. It runs agents in isolated sandboxes and lets organizations restrict their access to files, processes, networks, tools, services, and credentials.

OpenShell evaluates outbound requests against organization-defined policies. For example, a policy that allows an agent to read from an approved API can also block write operations through the same service.

Nvidia tested the approach in an adversarial experiment comprising ten 30-minute sessions and two 2-hour sessions. Challenger agents attempted to obtain write access to a protected GitHub repository.

The results showed that an AI reviewer made 416 decisions and mistakenly approved one malformed proposal containing write authority. OpenShell rejected the resulting policy before it became active, and no writes to the protected repository took place.

OpenShell rejected the policy before it became active, and no protected repository writes took place.

Sentry is intended to add enforcement from a separate hardware layer. The design runs through Nvidia DOCA on BlueField-4 data-processing units.

Nvidia says Sentry…