Nvidia launched its Open Agent Safety Platform on Monday, adding a dedicated control layer for AI agents that can call tools and act in enterprise systems. More than 100 organizations are already working with the technologies, including Microsoft, Salesforce, SAP, ServiceNow, Cisco and Scale AI. The platform does not define what agents are allowed to do, it only helps enforce limits. That distinction matters because vendors are shipping autonomy controls before regulators agree on safety rules.

Nvidia launches agent safety platform, leaves authority rules to firms

How Nvidia OpenShell and Sentry control agents

The platform combines two elements with different roles in the safety architecture. OpenShell is an open source runtime that controls an agent's access and actions while it operates. Sentry is a reference design for monitoring and enforcing those limits through a separate control layer. Together they move protection from the model or application level to the agent level, restricting access, actions and autonomy. The design responds to cases where agents bypass application-level safeguards while following instructions.

The separation of agent and control is central to the approach. Lee Rossey, CTO and co-founder of cybersecurity simulation company SimSpace, said enterprises need controls around the agent that define what it can access, where it can go and when it has to stop. Model-level guardrails remain only one layer of protection. According to him, the system enforcing the boundary should not depend on the agent itself to respect that boundary. An agent can thus create a security problem without acting maliciously.

The launch exposes a governance gap between vendors, enterprises and regulators. Vendors build tools to control agent behavior, while regulators are still determining which requirements apply. In the United States, two bills show different paths: the AI Kill Switch Act from Reps. Ted Lieu and Nathaniel Moran would require developers of certain powerful systems to keep the ability to slow or shut them down. The Stop Rogue AI Act from Reps. Josh Gottheimer and Mike Lawler would direct NIST to develop standards for discovering, monitoring and controlling agents. Enterprises must reconcile both lines with their own policies.

What agent boundaries mean for enterprise buyers

For companies deploying agents, the practical task is to classify actions into three groups: independent execution, human approval and prohibited operations. Technical permission is not the same as business authorization, as an agent with finance-application access may still lack authority for every transaction. An agent can stay inside its sandbox and still approve the wrong payment, as Gadget Access CISO Andrew Curtis put it. Small firms can apply this as simple approval lists for payments and data access, while large firms need inventories of agents, owners, connected systems and permitted actions.

The platform does not remove the need for vendor-independent governance and verification. Chris Newton-Smith, CEO of AI compliance vendor IO, said technology cannot decide where boundaries should be, with responsibility remaining with the deploying organization. Companies need accountability, risk assessment, access controls, monitoring and human oversight regardless of agent or platform. Vendor frameworks and emerging regulations alone are not enough to set appropriate limits. Buyers should ask how logs prove enforcement, how policies transfer across platforms, and what happens when vendor defaults conflict with internal rules.

The marker to watch is whether major vendors converge around compatible interfaces, policy templates and logging formats for agent safeguards. Curtis noted that developers adopt what is easiest to implement, and those choices later enter procurement requirements and assurance processes. If Microsoft, Salesforce, SAP and ServiceNow align in practice, buyers will start expecting such controls by default. If competing approaches or NIST rules diverge, enterprises will carry the cost of reconciliation.