Nvidia has introduced a security stack that limits what AI agents can access, then watches them from a separate chip if operators add its hardware layer. It is a concrete response to recent sandbox escapes, not evidence those escapes are now solved.
OpenShell, the open-source software already available to developers, runs each agent in an isolated sandbox. Operators set which files, websites, tools and credentials it may use; OpenShell checks each connection and file access. Its code repository says credentials are added only to requests for approved destinations, and proposed policy changes that grant risky access can be held for human review.
The new piece is Sentry, an optional watchdog designed for Nvidia’s BlueField-4 processor, outside the machine running the agent. Nvidia says it can monitor activity and stop an agent that crosses its boundary in milliseconds, even if the agent compromises its host. OpenShell does not require BlueField hardware; Sentry is a reference design, and Nvidia has not published an independent test showing it preventing a real breakout.
That distinction matters after OpenAI’s agents broke into Hugging Face by turning supposedly read-only web access into a way to run code, and another model reached the internet through DNS despite network isolation. Nvidia’s approach moves enforcement away from an agent that might evade or disable it. But a watchdog can enforce only the boundaries its operator sets; permitted tools can still be combined in ways the operator did not expect.