Nvidia launches AI agent safety platform and expands share buyback by $150 billion
OpenShell is broadly available, while Nvidia describes a separate hardware monitoring design. Its board raised the remaining share repurchase authorization to $235 billion.
Nvidia made its OpenShell security software broadly available on Monday as part of a platform intended to keep autonomous AI agents within set boundaries. The company also authorized another $150 billion in share repurchases, bringing the amount remaining under its buyback program to $235 billion. For organizations putting agents to work across their systems, the launch offers a new way to set operating limits; whether those limits prevent real incidents remains an open question.
The Open Agent Safety Platform combines OpenShell, which Nvidia says controls an agent while it runs, with Sentry, a hardware monitoring reference design. Nvidia announced both on September 28. The two components address a problem that becomes more consequential as agents gain access to files, tools and external services: how to allow a task while restricting actions outside its assigned scope.
How the controls are meant to work
Nvidia says OpenShell traces an agent’s actions and enforces policies in a secure runtime boundary. Operators can set limits on its access to files, networks, tools, processes and credentials. The software is designed for agents using either open or closed models, so the proposed control sits around the agent’s activity rather than depending on changes to a particular model.
OpenShell is open source, and Nvidia says developers can extend it beyond the company’s own computing platforms, including to Arm and Intel systems. WIRED reported that the software is designed to isolate an agent’s activity at the operating system kernel level. It also reported that OpenShell was first announced at Nvidia’s GTC conference in March; Monday’s change is its broader release.
Sentry is a separate layer in Nvidia’s reference design. The company says it runs on BlueField-4 data processing units, monitors agent behavior independently of the software boundary and can quarantine an agent in milliseconds if it tries to cross that boundary. Those performance and containment descriptions are Nvidia’s claims. The cited coverage does not independently demonstrate that Sentry or OpenShell would prevent a real world breach.
In a media briefing reported by The Guardian, Nvidia vice-president Justin Boitano said the platform could have stopped an incident involving OpenAI agents and Hugging Face if it had been used in early model evaluation. That is a counterfactual assessment by Nvidia, rather than evidence that the system was tested against that incident. It illustrates the use case the company is targeting without establishing a result.
Partners and the limits of the announcement
Nvidia says more than 100 organizations are working with technologies associated with the platform. Its announcement names companies including Anthropic, Microsoft, JPMorganChase, Salesforce, SAP and Perplexity. That broad description does not mean every named organization has deployed OpenShell. WIRED reported that adoption across Nvidia’s wider partner list was unclear.
The announcement gives some more specific examples. Nvidia says it has worked with Anthropic on additional controls for Claude Managed Agents. Anthropic chief commercial officer Paul Smith said the Nvidia platform adds governance across hardware and software. Nvidia also says SpaceXAI is using the platform for Cursor coding agents and Grok models. Those statements describe different relationships with the platform, and do not establish the same level of deployment for every partner.
A study listed by Google Research provides context for the underlying security challenge. It examines autonomous agent risks involving channel access, session state, tool execution, outside content and extension supply chains, and discusses defenses such as isolating boundaries and limiting tool capabilities. The study is background on the kinds of exposure agent developers face; it is not an evaluation of Nvidia’s newly launched platform.
What the buyback authorizes
In a separate September 28 announcement, Nvidia said its board increased its existing share repurchase authorization by $150 billion. That takes the remaining authorized amount to $235 billion. An authorization permits repurchases; it does not mean Nvidia has already spent that sum or committed to buying shares on a specified day.
Nvidia said it expects to execute the remaining program through fiscal year 2028, but its announcement gave no schedule for individual purchases. Chief executive Jensen Huang said the company’s cash generation lets it invest in technology while returning capital to shareholders, and described the authorization as a sign of confidence in its long term opportunity. How much Nvidia ultimately repurchases, and when, remains to be seen.
Sources and context
- Nvidia unveils security platform to rein in AI agents and $150bn stock buybackThe Guardian
- NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to DeploymentNVIDIA via GlobeNewswire
- NVIDIA Announces a $150 Billion Share Repurchase Authorization IncreaseNVIDIA via GlobeNewswire
- Nvidia’s Answer to Rogue Agents Is an Open-Source AI Security SystemWIRED
- OpenClaw in the Wild: Security Analysis of Autonomous AgentsGoogle Research; study published in IEEE/CAA Journal of Automatica Sinica
AI-assisted article checked against the listed sources. NewsJaws did not conduct interviews or attend the reported events.
About NewsJaws Desk
AI-assisted reporting and explainers reviewed against the linked source documents. No claim of on-scene reporting or original interviews.