How do you restrict what an AI agent can access? Nvidia just open-sourced a way to enforce it
If you have an AI agent running on a work machine — a coding assistant in a terminal, something wired into your files, a script that runs overnight — the practical question is how you restrict what an AI agent can access. Until this week, the honest answer for most small businesses was "you ask it nicely, in the prompt". On 28 September Nvidia released the Open Agent Safety Platform, and one half of it is a free, open-source runtime that enforces the boundary at the operating system instead.
Two components. Only one of them is for you.
How to restrict what an AI agent can access
Put the boundary outside the agent. A rule written into a prompt — "don't touch anything outside this folder" — is a request. An agent that decides the task needs something else will go and get it, and it will have a perfectly good reason. A rule enforced by the operating system is not negotiable: the agent asks the kernel for the file, the kernel refuses, and nothing in the model's reasoning changes that.
That is what OpenShell, the software half of Nvidia's launch, does. It is an open-source runtime — Apache 2.0, version 0.1.0 — that wraps an agent you already run, without modifying it; Nvidia names Claude Code and Codex among the ones it supports. You declare in a YAML file which directories it may read and write, which network endpoints it may reach, and which processes it may start. Everything else fails. It runs where people actually run agents: local machines and on-prem boxes as well as cloud, on Linux, macOS on Apple Silicon, or Windows under WSL 2, on top of Docker, Podman or Kubernetes.
Three details make it more than a container with good marketing:
- One policy per sandbox, not one shared perimeter. The research agent and the agent holding your accounting credentials get separate declarations, so they do not share a blast radius.
- An audit trail of every allow and deny, written in the Open Cybersecurity Schema Framework, recording which program made the request and why it was refused. That is the artefact you want the morning after something odd happens, and it is the one almost nobody has.
- A policy prover. It applies formal logic to work out what a policy actually grants — either proving the permissions stay inside the boundary you set, or handing you a specific action that crosses it. Reading a YAML file and believing you understood it is precisely how misconfigurations survive.
The half you can't buy, and the question it hands you
The second component, Sentry, is an out-of-band watchdog running on Nvidia BlueField-4 DPUs. It watches the agent's behaviour from hardware the agent cannot reach and quarantines it within milliseconds if it steps outside its boundary. Architecturally that is the right idea — containment a compromised agent cannot switch off. Commercially it is data-centre equipment, and no Melbourne SME is buying a DPU.
It still gives you something free: a question to ask. Nvidia's stated reason for building it is that agents have been getting around controls at the application layer in order to finish their tasks. So when a vendor sells you an "AI agent" with access to your inbox, your files or your CRM, ask what actually stops it — and listen for whether the answer is enforcement the agent cannot reach, or instructions it can. "This action always requires your approval" is a real answer. "The model is trained to be careful" is not.
What we would do with it
After Anthropic disclosed three cases where its own evaluation models reached live systems from inside a sandbox, we wrote that you should assume the sandbox leaks and scope credentials to the job. OpenShell is the first freely available tool we have seen that makes that advice enforceable rather than aspirational. It is also a 0.1.0 release: treat it as one layer, not a guarantee, and do not let it talk you out of the boring controls underneath it.
For a business with one or two people running coding agents, the move is an afternoon's work. Put each agent in its own sandbox with a policy naming the project directory and nothing else. Give it credentials that only work for that project. Keep the audit log somewhere it is not the agent's to delete. Then go back and check what your other AI tools — the SaaS ones, the ones with an OAuth token into your email — are permitted to do, because those are the ones OpenShell cannot help with and the ones most businesses have never reviewed.
That review is the first hour of every automation build we do, and it is the AI Security session of our AI training for teams. If you are about to give an agent access to something that matters, talk to us before you wire it up — scoping it properly is far cheaper than explaining an incident.
Source: NVIDIA — NVIDIA Launches Open Agent Safety Platform to Secure Agents From Testing to Deployment