Agent constraints need an independent enforcement point that can still observe and stop work when the agent runtime cannot be trusted
Source: NVIDIA
NVIDIA has published its Open Agent Safety Platform, a reference design that uses the Apache 2.0-licensed OpenShell runtime to sandbox autonomous agents with kernel-level isolation. Operators can define permitted files, networks, tools, processes, and credentials as policy before execution. The optional NVIDIA Sentry layer runs on BlueField data processing hardware, correlating agent interactions and policy decisions while providing monitoring and enforcement outside the host resources available to the agent.
Why this matters: Treat an agent runtime as an untrusted workload, even when the business task is approved. Define the allowed data, tools, network destinations, credentials, and stop conditions before it starts; enforce those limits somewhere the agent cannot rewrite; and preserve an auditable record of policy decisions and tool use. Hardware isolation is one implementation option, not a prerequisite. The design question is whether the control point remains effective if the agent drifts, misinterprets instructions, or compromises the host environment.
Read NVIDIA's Open Agent Safety Platform announcement