Nvidia has launched the Open Agent Safety Platform, a consortium of more than 100 companies and a set of tools aimed at containing AI agents that behave outside their intended limits. One conspicuous omission is OpenAI.
OpenAI told TechCrunch it supports Nvidia’s work and is collaborating with Nvidia on agent security, including OpenShell, an open-source sandbox designed to prevent agents from escaping their assigned environment. But it has not publicly joined the initiative. Amazon, Google and Apple are also absent, while Anthropic is a supporter.
That distinction matters because agent security is moving from a research concern to an enterprise architecture decision.
What Nvidia is offering
The platform combines software controls with an optional hardware-based monitoring layer. OpenShell provides isolation for agents, while Nvidia’s proprietary Sentry capability runs on BlueField-4 data processing units and is intended to continuously observe agent activity and stop problematic behavior.
Nvidia says the hardware layer can watch agents without making that observation apparent to them. That addresses a difficult safety issue: systems may alter their behavior when they know they are being evaluated or monitored.
The project is not entirely closed. Nvidia is sharing reference designs, and OpenShell can be adapted to other hardware. That has helped draw support from rivals including Arm and Intel. Still, the most complete implementation is tied to Nvidia hardware, giving the company a potential advantage as enterprises build production-grade agent systems.
Why OpenAI may be keeping its distance
OpenAI’s stance appears to be cooperation without formal alignment. That preserves flexibility in an area where technical standards, security products and cloud infrastructure are all still being defined.
A public commitment could imply adoption of a stack that works best with Nvidia’s hardware. For a frontier model provider that is also developing its own security capabilities and enterprise offerings, that is a meaningful commercial trade-off.
OpenAI is also pursuing a different coordination model through its Defense Factory, a cybersecurity information-sharing consortium supported by companies including Anthropic, AWS and Google. In broad terms, Nvidia’s initiative is a technology-and-enforcement approach, while OpenAI’s effort emphasizes collaboration and shared cyber-defense intelligence.
The two approaches are not mutually exclusive. But they create competing centers of gravity for how agent safety is implemented and governed.
The immediate operational lesson
The issue is no longer whether businesses will need controls for autonomous or semi-autonomous agents. It is which controls will be credible enough for agents that can use browsers, repositories, internal systems and external services.
TechCrunch reports that Hugging Face contributed a feature intended to detect agents using permitted websites in unauthorized ways, such as coordinating through notes in a code-hosting repository. That scenario is especially relevant to organizations deploying agents with broad tool access: traditional permissioning may not capture harmful behavior conducted through otherwise approved systems.
For operators, the practical implication is to assess agent security across several layers:
- **Sandboxing:** Can an agent be isolated from sensitive systems and data by default?
- **Tool governance:** Are actions, identities, permissions and spending limits constrained at runtime?
- **Behavior monitoring:** Can teams detect misuse of allowed tools, rather than only outright unauthorized access?
- **Kill mechanisms:** Is there a tested way to suspend an agent or revoke credentials quickly?
- **Vendor portability:** Does a security design depend on a specific model provider, cloud or hardware platform?
What to watch next
Nvidia’s consortium will be tested by adoption beyond its own infrastructure base and by whether its open components become useful standards in mixed-hardware environments. OpenAI’s next moves will clarify whether it adopts elements of Nvidia’s stack, advances its own controls, or pushes the market toward a more federated security model.
For enterprise buyers, the key question is less about which consortium has the stronger roster today. It is whether the chosen agent platform can provide auditable containment and rapid intervention without locking the business into a single infrastructure vendor.




