What is NVIDIA OpenShell?
NVIDIA OpenShell is an open and secure runtime environment tailored for the operation of autonomous AI agents, managing their execution, access privileges, and the routes for inference traffic. Rather than incorporating security measures directly into the model or application, it upholds safety protocols in the surrounding infrastructure, ensuring that nothing is permitted by default; permissions are allocated through predefined policies, with enforcement mechanisms acting outside the agent's process to avert any potential bypass through prompts. Each autonomous agent is confined within a controlled sandbox, which limits direct network access, restricts file visibility, and employs kernel-level monitoring of system calls to guarantee stringent oversight. Serving as the control plane, a gateway handles user authentication, manages the lifecycle of sandboxes, and provides the agents with policies, configurations, credentials, and settings for inference. Furthermore, an external supervisor evaluates network requests based on policies at multiple levels—including binary, destination, method, and path—and grants access to credentials only when expressly authorized, thereby bolstering the overall security architecture. This comprehensive and layered framework ensures that the agents operate efficiently while upholding strict security measures throughout their processes, ultimately fostering a trustworthy environment for AI interaction. The attention to detail in security design reflects a commitment to safeguarding both the agents and the systems they interact with.