KDCube

Agent Control Drops Into Silicon as OpenAI's DevDay Opens

NVIDIA's new Open Agent Safety Platform pushes agent enforcement below the app layer with OpenShell sandboxing on the CPU and a Sentry watchdog on DPUs — though only OpenShell v0.1.0 actually ships today. Meanwhile OpenAI's DevDay opens with code hinting at a managed-agents service (and Agent Builder's Nov 30 sunset), ...

Highlights

  • NVIDIA shipped an Open Agent Safety Platform that moves agent enforcement below the app layer: OpenShell sandboxes agents on the CPU and Sentry watches them out-of-band from a DPU, with 100+ orgs from Anthropic to JPMorganChase signed on (NVIDIA).
  • Only half of it actually ships today — OpenShell is at v0.1.0, while the silicon-level Sentry watchdog is a reference design tied to BlueField-4 hardware (FourWeekMBA).
  • OpenAI DevDay opens this morning (keynote 10a.m. PT), and OpenAI's own code points to a managed agents service with Agent Builder slated to shut down after Nov 30 (runtimewire).
  • Salesforce's long-horizon runtime — agents that pursue goals across days and weeks with persistent memory and durable execution — is now live under its first job-ready agent (Salesforce).

Key Signals

  1. NVIDIA puts agent guardrails outside the agent's reach — Sept 28

    OpenShell is an open-source runtime (v0.1.0) that runs an agent in a sandbox and inspects its HTTP, GraphQL, and MCP traffic — default-deny, every allow/deny logged, enforcement running outside the agent's process so it holds even if the agent is compromised (MarkTechPost). Paired Sentry runs on BlueField-4 DPUs and can quarantine a misbehaving agent in milliseconds, giving operators an out-of-band view of identity, policy decisions, and tool access (NVIDIA). This extends the governance thread from prior issues (Dataiku, Collibra) but shifts the control point from policy software into the runtime and the hardware — with the caveat that the silicon half depends on gear most teams don't have yet (FourWeekMBA).

  2. DevDay's real story may be managed agents, not "o" — Sept 29

    The pre-event buzz is an always-on consumer agent reportedly named "o" that keeps working after the chat closes — still unverified on name, tiers, and permissioning (TestingCatalog). The more concrete signal for builders: OpenAI's codebase references a managed agent service for "hosted and self-managed environments, skills and plugins," while Agent Builder (the Oct 2025 drag-and-drop canvas) is set to sunset after Nov 30, 2026, redirecting teams to the Agents SDK and Workspace Agents (runtimewire). That would put OpenAI's hosted-runtime pitch head-to-head with Anthropic's managed agents on credential handling and audit logs.

  3. Long-horizon runtimes go from concept to shipping surface — Sept 11

    Salesforce's new Agentforce runtime lets agents pursue business goals over days and weeks with persistent memory, durable execution, and dynamic steering — its outbound-sales agent "Hunter" is the first to run on it, in pilot with GA targeted for November (Salesforce, Unite.AI). Durable, multi-day execution is quietly becoming a distinct platform primitive alongside the request/response agent loop.

Why It Matters / What To Watch

  1. Runtime enforcement is the new governance frontier
    • If you run agents against internal APIs, note OpenShell's read-allow/write-block model on the same endpoint via MCP inspection — a pattern worth prototyping even without NVIDIA hardware (MarkTechPost).
    • Watch whether Sentry's out-of-band model gets a software fallback; today it's gated on BlueField-4 (FourWeekMBA).
  2. Hosted agent runtimes are consolidating
    • If you built on OpenAI's Agent Builder, plan a migration path before the Nov 30 sunset toward the Agents SDK (runtimewire).
    • Compare durable-execution semantics across vendors before committing — Salesforce's long-horizon runtime and OpenAI's rumored managed service target the same days-to-weeks workload (Unite.AI).

Quick Links