Tuesday, September 29, 2026 Newsletter Advertise
Breaking
AI

Red Hat backs NVIDIA agent safety platform with OpenShell, BlueField

Red Hat's CTO says model guardrails alone cannot secure AI agents, and outlines layered controls spanning identity, sandboxing, network policy and hardware isolation.

Red Hat backs NVIDIA agent safety platform with OpenShell, BlueField. Source: Red Hat

Red Hat chief technology officer Chris Wright argued in a company blog post dated September 28, 2026 that enterprises cannot rely on model safeguards to secure AI agents, and must instead build independent controls into the platforms, networks and hardware around them. The post also details Red Hat's participation in the NVIDIA Open Agent Safety Platform, the asago open source community and an IBM supply-chain initiative called Lightwell.

Why Red Hat says the model is the wrong boundary

Wright wrote that enterprise AI is shifting from software that generates information to software that can take action, with agents able to call APIs, invoke tools, access files and credentials, communicate over networks and interact with business systems.

According to the post, that reach changes what must be secured: organizations need to control an agent's identity, permissions, access to tools and data, runtime environment, network connections and underlying infrastructure. Controls "should not depend solely on the agent behaving as intended," Wright wrote, and should assume an agent may behave unexpectedly.

Red Hat frames the answer as defense in depth, listing layers that already exist: model and application guardrails, identity and authorization, tool controls, sandboxing, workload isolation and network policy, plus observability and AgentOps for tracing agent activity and outcomes.

Platform and hardware enforcement points

The company said Red Hat AI brings these layers together across hybrid cloud, with Red Hat OpenShift AI supporting development and operation of AI workloads, Red Hat OpenShift providing workload isolation, policy and networking, and Red Hat Enterprise Linux serving as the operating system foundation. Red Hat AI Inference provides a model-serving layer, and the technologies are combined with NVIDIA accelerated computing, networking and AI software in Red Hat AI Factory with NVIDIA.

Wright said that as part of the NVIDIA Open Agent Safety Platform, OpenShell introduces sandboxing and policy mechanisms intended to constrain autonomous agents, while NVIDIA BlueField data processing units provide a hardware-isolated environment for networking, security and other infrastructure services, separate from applications on host compute.

NVIDIA is introducing an architectural approach in which the agent workload stays on host compute while selected supervisory, networking, security or policy functions move across an independent hardware boundary on BlueField, according to the post. Red Hat cautioned that this "should not be viewed as a single answer to AI safety or agent security."

From governance policy to testable controls

Red Hat said the asago open source community, which it founded with NVIDIA and other industry and research collaborators, is exploring how organizations can translate AI governance policies into identified risks, test scenarios and technical controls, with an auditable path from policy to implementation. The post said agent runtimes such as OpenShell are one potential enforcement point for policy-derived controls, with infrastructure outside the agent workload as another.

On the software beneath agents, Wright pointed to Lightwell, described as a joint initiative with IBM focused on securing the open source software supply chain through validated remediation, signed artifacts and software provenance. Red Hat also said it is an inaugural participant in NVIDIA's Open Secure AI Alliance, working with other companies on open tools and techniques for protecting the AI stack, including models and agent infrastructure.

What to do

  • Do not treat the model as the primary security boundary; enforce controls on the systems the agent can reach.
  • Apply layered controls: model and application guardrails, identity and authorization, tool controls, sandboxing, workload isolation and network policy.
  • Keep enforcement points independent of the agent where possible, and assume the agent, its instructions or a dependency may behave unexpectedly.
  • Use observability and AgentOps to trace agent activity, tool interactions and outcomes for post-incident review.
  • Secure the software stack beneath agents, including open source dependencies, using validated remediation, signed artifacts and software provenance.
  • Translate organizational AI policies and risk requirements into technical controls that can be independently tested and enforced.
Key facts and where they come from
  • Red Hat argues model safeguards cannot carry all of the security burden for agents that act on enterprise systems.
    Model safeguards remain important, but they cannot carry the entire security burden.
  • The company lists layered controls including guardrails, identity, tool controls, sandboxing, workload isolation and network policy.
    Tool controls to limit which capabilities are available to an agent. Sandboxing to restrict files, processes and execution environments.
  • asago was founded by Red Hat with NVIDIA and other collaborators to map governance policy to technical controls.
    Founded by Red Hat with NVIDIA and other industry and research collaborators, asago is exploring how organizations can translate AI governance policies into identified risks, test scenarios and appropriate technical controls
  • OpenShell adds sandboxing and policy mechanisms as part of the NVIDIA Open Agent Safety Platform.
    OpenShell introduces sandboxing and policy mechanisms intended to constrain autonomous agents
  • NVIDIA BlueField DPUs are presented as a hardware-isolated environment separate from host compute.
    NVIDIA BlueField data processing units (DPUs) provide a hardware-isolated infrastructure environment for networking, security and other infrastructure services, separate from applications running on host compute.
  • Lightwell is Red Hat's joint initiative with IBM on open source supply chain security.
    Through Lightwell, our joint initiative with IBM focused on securing the open source software supply chain
  • Red Hat says it is an inaugural participant in NVIDIA's Open Secure AI Alliance.
    As an inaugural participant in NVIDIA's Open Secure AI Alliance, Red Hat is working with other industry leaders on open tools and techniques for protecting the AI stack

Read the original from Red Hat →

The TechUpscale Brief

The day's cyber, AI and tech news in one short email, every weekday morning. Free. Unsubscribe anytime.

I'm most interested in

More AI