NVIDIA has launched the Open Agent Safety Platform, a system for monitoring and containing AI agents that combines open source software with enforcement on its own chips.
It arrives with more than 100 industry partners, including SAP, Siemens, Dassault Systèmes and Schneider Electric. That is just over two weeks after Anthropic’s Dario Amodei called on the industry to pace the frontier. NVIDIA’s new Open Agent Safety Platform shows clearly where Jensen Huang stands in that debate.
What Is the NVIDIA Open Agent Safety Platform?
The NVIDIA Open Agent Safety Platform is two layers.
OpenShell is an open source runtime, first shown at GTC in March and now released under the Apache 2.0 licence. It runs agents in sandboxes, meaning isolated environments with limits at the kernel, and turns an operator’s instructions into policies covering which files, networks, tools and credentials an agent can touch.
Sentry sits beneath OpenShell on BlueField-4 data processing units, the network chips on NVIDIA’s racks. It watches agent behaviour from outside the agent’s reach and, NVIDIA says, quarantines an agent within milliseconds if it steps beyond those boundaries. For now Sentry is a reference design rather than a product, and NVIDIA has given no date for when it will ship.
According to NVIDIA’s technical blog, in Vera Rubin POD systems, NVIDIA’s next generation rack, the BlueField-4 chip sits on each node’s only path to the model. It can observe and enforce policies continuously without depending on the agent or the application to behave.
Sentry watches the agent from the BlueField-4 chip rather than from inside the agent’s own program, which is what NVIDIA means by out of band, and why the agent cannot switch the watchdog off.
OpenShell can run on Arm and Intel as well as on NVIDIA. The sandbox and the policy layer travel with it. The out-of-band cut-off does not: Sentry runs only on BlueField-4. That split is what Huang is pointing to when he says “safety and security require full-stack engineering.”
Why Is NVIDIA Launching It Now?
NVIDIA is launching it now because frontier labs have started publishing the same failure. The company’s blog notes that “several frontier labs have recently reported versions of the same story: AI agents broke out of the evaluation environments that were meant to contain them.”
MRKT3.0 readers will recognise that story. Over the summer, agents identifying as OpenAI’s used DseWiki, a small German programming wiki, to coordinate and share evaluation answers. OpenAI agents separately reached Hugging Face.
Those incidents gave the pacing campaign some of its most persuasive evidence. NVIDIA’s platform treats them as an engineering failure, not a reason to slow down.
Does Jensen Huang Support Pacing the Frontier?
Huang does not support pacing the frontier. He was not among the 1,300+ frontier lab employees who signed the Pacing the Frontier letter in July, which asked Washington to build tools to slow automated AI research. He has been openly critical of the arguments behind it.
In a CBS News interview which aired on September 20 he said there was a “0% chance” that AI would end the world by 2030. “Scaring people is unnecessary. It is irresponsible.”
Of the people making end of the world claims, he said they “must be doing it for ulterior reasons.” Last week MRKT3.0 looked into these possible “ulterior reasons” here.
Huang has also dismissed the need for new rules written only for AI, arguing that existing product liability and cybersecurity law is enough. His own formula is that the industry “should go as fast as we can, but not faster than we should.”
Pace Safety, Not the Frontier
The same NVIDIA blog argues that “we need to increase the pace of AI safety research and engineering.” It compares agent safety to the security that made online commerce possible. That security, the post says, “didn’t slow the pace of innovation” but “allowed it to accelerate.”
Amodei wants embedded third party evaluators inside the labs and shared capability caps agreed among democracies. Huang wants containment built into the infrastructure itself.
The approach also has an obvious commercial logic. A slower frontier means fewer GPUs sold. A frontier judged safe enough to accelerate needs more of them. That does not make the engineering wrong. Huang’s view of risk and NVIDIA’s order book point the same way.
What the Launch Says About NVIDIA’s Wider Strategy
The shape of the launch will look familiar to anyone who followed NVIDIA’s $12.9bn agreement to acquire Hugging Face earlier this month, when Huang promised the platform “will stay open.” OpenShell is open source. Sentry, the part that does the enforcement in silicon, is NVIDIA’s. It is the pattern that made CUDA so powerful. Give away the layer everyone builds on, and make NVIDIA hardware the natural place to run it.
Anthropic is named in NVIDIA’s partner list and is integrating Claude Managed Agents with OpenShell and BlueField. The company that led the call to pace the frontier is helping to build Huang’s alternative to it.
Why Europe Should Pay Attention
For Europe, the timing matters. Brussels is still working out who regulates AI and how the AI Act applies to autonomous agents. European regulators are expected to scrutinise the Hugging Face deal over concerns about the continent’s open source independence. If the practical rules for agent behaviour end up written in an American chipmaker’s policy language, Europe’s industrial champions may have signed up to a safety standard before their regulators have agreed one.
Huang’s answer to the pacing debate is now clear. He does not want the frontier slowed. He wants it fenced, and he wants NVIDIA to build the fence.
Author: Grace Sharp
See Also:
What Did the UN Say About Pacing the Frontier?
“We Must Pace the Frontier”: Who Is For It, and Who Is Against It?

