Red Hat and NVIDIA put agent controls outside the agent’s reach
OpenShell and DOCA are coming to Red Hat AI Factory, while NVIDIA’s BlueField-based Sentry design adds an independent enforcement plane for agent workloads.
NVIDIA has launched an Open Agent Safety Platform that combines an open-source runtime boundary with a hardware-isolated monitoring design, and Red Hat says it is integrating parts of that stack into Red Hat AI Factory with NVIDIA. The announcement moves agent security beyond model guardrails toward controls that the agent workload cannot directly change or bypass. (Red Hat; NVIDIA)
What changed
The platform has two main pieces. OpenShell is a broadly available secure runtime intended to trace agent actions and enforce policies while agents run. NVIDIA says the open-source software targets its Vera CPUs but can be extended to third-party compute platforms, including Arm and Intel systems. (NVIDIA)
The second piece is NVIDIA Sentry, a reference design for an out-of-band watchdog on BlueField-4 data processing units. NVIDIA says Sentry uses DOCA software to inspect requests and responses, verify agent identity, produce attested telemetry and enforce access policies for data, tools, APIs and services from an isolated trust domain. NVIDIA describes Sentry as able to quarantine an agent that crosses its boundary in milliseconds, but its release also cautions that many described products and features remain subject to availability. (NVIDIA)
Red Hat’s contribution is the enterprise platform around those controls. The company says it runs OpenShell and DOCA on Red Hat AI Factory with NVIDIA, the combined stack built from Red Hat AI, OpenShift AI, OpenShift, RHEL and NVIDIA infrastructure. Red Hat presents BlueField as an additional enforcement boundary alongside identity, authorization, workload isolation, network policy, observability and software-supply-chain controls—not as a complete answer by itself. (Red Hat; NVIDIA)
Who it affects
The immediate audience is platform and security teams preparing to let autonomous agents call enterprise APIs, use credentials, reach files and invoke tools. Red Hat’s architecture assumes those agents can behave unexpectedly and therefore treats the model as an untrusted participant rather than the primary security boundary. (Red Hat)
That design matters most for agents with meaningful authority. Runtime sandboxing can constrain processes, OpenShift can supply workload and network isolation, and a DPU-based monitor can remain outside the host environment where the agent executes. The layers address different failure modes; none replaces the others. (Red Hat)
What to do
Teams evaluating the stack should separate what is available now from the reference architecture. OpenShell is available through NVIDIA’s developer resources and GitHub, while Sentry is described as a BlueField-4 reference design. A practical evaluation should test whether policies survive a compromised or misbehaving agent, whether tool and network permissions are independently enforced, and whether audit data crosses a trust boundary the agent cannot alter. (NVIDIA)
The strategic change is the placement of control. Instead of asking only whether an agent follows instructions, Red Hat and NVIDIA are asking which identity, policy and monitoring functions must remain outside the agent’s reach. (Red Hat)
sources
comments · 0