NVIDIA Open Agent Safety Platform Secures Manufacturing AI
NVIDIA launched its Open Agent Safety Platform, a hardware-enforced security system for AI agents in manufacturing and critical infrastructure.

NVIDIA announced the Open Agent Safety Platform, introducing hardware-enforced boundaries to secure AI agents in manufacturing and critical infrastructure. The platform features Sentry, an out-of-band watchdog that runs on BlueField-4 data-processing units to continuously monitor agent behavior. Sentry monitors outcomes against policies and can quarantine agents that attempt to move outside their boundaries in milliseconds.
This open software platform and reference system design spans software, hardware, computing, and robotics systems. Its OpenShell component is an open-source secure runtime that establishes and enforces boundaries around AI agent access and actions. OpenShell traces agent actions, enforces policies governing task execution, and controls access to files, networks, tools, processes, and credentials. Sentry operates from an isolated, out-of-band trust domain not visible to agents or attackers.
Security Architecture Built on DOCA and OpenShell
The platform leverages NVIDIA DOCA software for programmable policy enforcement and OpenShell as an open-source runtime boundary that controls access to hardware resources. Sentry is built on NVIDIA DOCA software, which provides programmable functions for inspecting agent requests and responses, generating attested telemetry, verifying agent identity and applying zero-trust access policies.
OpenShell is an open source runtime boundary for agents. It is broadly available, runs on NVIDIA Vera CPUs, traces agent activity, and enforces policy. The software can be extended to work with third-party compute platforms, including those from Arm and Intel. DOCA enables inspection of agent requests and responses, attested telemetry, identity verification, and granular access policies.
Industry Adoption Across Critical Infrastructure and Robotics
Over 100 organizations are implementing the platform to secure AI agents in energy, robotics, and critical infrastructure applications. The list includes Siemens, SAP, Gecko Robotics, Accenture, Microsoft, and Palo Alto Networks.
Energy organizations including Hitachi Energy, EPRI, NextEra Energy, and Siemens Energy are working with NVIDIA on technologies for energy and critical infrastructure applications. Robotics companies Figure, Gecko Robotics and Skild AI are using OpenShell to add agent safety controls to autonomous systems that operate in physical environments.
Pittsburgh-based Gecko Robotics is using NVIDIA OpenShell for secure runtime boundaries that developers can use to define what actions systems can take and what is not permitted. SAP embeds OpenShell in its Joule Studio runtime, part of its Business AI Platform, and contributes engineering to the project.
NVIDIA partners including Cisco, Dell Technologies, HPE, Lenovo, and Oracle Cloud Infrastructure offer AI infrastructure solutions that use or support the platform technologies. Organizations span cybersecurity, critical infrastructure, financial services, and robotics.
Gecko Robotics Validates Platform for Physical AI Safety
Gecko Robotics uses OpenShell to establish enforceable boundaries for autonomous robots operating on critical infrastructure, addressing safety concerns raised by recent AI agent incidents. Ariel Weingarten, director of engineering at Gecko Robotics, said its agents have access to the same system commands as its field operators, including starting and stopping data collection, robot motion controls and path planning, and raising and lowering payloads.
The company's goal is to establish the safeguards needed to deploy greater autonomy responsibly. Gecko Robotics uses robots that can climb, crawl, fly and swim on critical infrastructure, including for Fortune 100 energy companies, the U.S. Air Force, and the U.S. Navy. Its systems inspect everything from fuel tanks to nuclear submarines and aircraft carriers.
Gecko’s Komodo robot, deployed with the U.S. Navy, places an independent enforcement layer between the AI agent and the hardware. The developer decides what Komodo should do; OpenShell ensures it stays within the rules. Gecko Robotics asserted that physical AI and robotics represent the next frontier of technology and that model-level safety alone is not enough.
Because Gecko Robotics already follows well-defined security controls for U.S. Military assets, implementing them in OpenShell was less of a challenge. The company said deterministic control could also help at the swarm level. It is helpful to have invariants at the individual unit level that can be used to reason about swarm dynamics.
Salesforce and NVIDIA have integrated OpenShell with Slack, allowing teams to view agent activity and audit events and approve or reject permission requests. NVIDIA Founder and CEO Jensen Huang announced the platform. He said, "As we continue to discover the frontier of AI capabilities, we must accelerate discovery at the frontier of AI safety."
Justin Boitano, vice president of enterprise AI at NVIDIA, added, "For the agent economy to grow, we need a trusted foundation across silicon and software." The platform software, including OpenShell, is available through the NVIDIA developer resources page and GitHub. The close of development is Gecko Robotics' deployment of OpenShell in Komodo robots for U.S. Navy critical infrastructure inspection.




