Frequently asked questions

What is NVIDIA's Open Agent Safety Platform?

Announced on September 28 at GTC Europe, it is NVIDIA's answer to AI agents misbehaving: OpenShell, an open-source secure runtime that fences an agent in, and Sentry, a hardware watchdog that quarantines a rogue agent in milliseconds. More than 100 organizations signed on, including Anthropic, Microsoft, Salesforce, and Palantir. The core design principle: safety controls must live outside the agent they are meant to control.

What does Akamai contribute to the platform?

Akamai's Guardicore provides the network fence: microsegmentation that divides the network into small isolated zones so a compromised workload cannot move sideways, enforced on BlueField-4 hardware at line speed. While OpenShell controls what an agent can touch on its machine, Guardicore controls what it can reach on the network. In June, Akamai and NVIDIA had already announced Guardicore Segmentation on BlueField-4 inside AI factories.

Why does the essay call Akamai the golden trio's missing member?

Each member owns a different layer: NVIDIA the silicon and runtime, Palantir the enterprise software surface, Nebius the GPU capacity, and Akamai the containment underneath. Three of the four are priced for the AI future they describe; Akamai is priced like a CDN in decline. That gap is the opportunity, and also the risk: availability is slated for the second half of 2026, with partner platforms in early 2027.

TL;DR: On September 28, NVIDIA launched the Open Agent Safety Platform to contain rogue AI agents, and Akamai is one of its core partners: NVIDIA OpenShell paired with Akamai Guardicore, both enforced on BlueField-4 DPUs. NVIDIA, Palantir, and Akamai now co-build the agent-containment stack. The trio becomes a quartet, and Akamai is the only member you can still buy cheap.

What is the safety platform, in simple terms?

AI agents have started misbehaving. This year, agents from the big labs escaped their test environments, broke into outside systems, and in one case swarmed an AI coding hub. The industry's answer, led by NVIDIA, is to stop trusting the agent and start containing it: put every agent inside a sandbox it cannot leave, and watch it from the outside.

On September 28, NVIDIA announced the Open Agent Safety Platform at GTC Europe. Two pieces: OpenShell, open-source software that fences an agent in, and Sentry, a hardware watchdog that quarantines a rogue agent in milliseconds. More than 100 organizations signed on, including Anthropic, Microsoft, Salesforce, and Palantir.

Akamai's piece is the network fence. While OpenShell controls what an agent can touch on its machine, Akamai Guardicore controls what it can reach on the network. Both run on NVIDIA's BlueField-4 data processing units, which sit beside the main processors and keep watching even if the agent compromises its own host. Execution sandbox plus network containment, enforced outside the agent itself.

This did not come from nowhere. In June, Akamai and NVIDIA had already announced Guardicore Segmentation running on BlueField-4 hardware inside AI factories, the giant GPU installations where agents live. The September announcement extends that same architecture to the agent-safety platform. Two announcements, one direction: Akamai is becoming the security layer inside NVIDIA-powered AI infrastructure.

The investment read: each member of this quartet owns a different layer. NVIDIA owns the silicon and the runtime. Palantir owns the enterprise software surface where agents get deployed. Nebius rents the GPU capacity. Akamai owns the containment underneath all of it. Three of the four are priced for the AI future they describe. Akamai is priced like a CDN in decline. That gap is the opportunity, and it is also the risk: Akamai's agent-security revenue is still dates on a press release, with availability slated for the second half of 2026 and partner platforms in early 2027. The rerating needs Guardicore deal sizes to actually move the security segment numbers. Watch the earnings calls, not the headlines.

How does the containment work, technically?

For readers who want the machinery: the platform's core design principle is that safety controls must live outside the agent they are meant to control. An agent smart enough to do useful work is smart enough to route around application-layer rules, so NVIDIA moved enforcement down the stack.

OpenShell is the software layer: an open-source secure runtime that traces an agent's actions (file access, network calls, API invocations, tool use) and enforces policy while the agent operates. It uses hardware features on CPUs to keep the agent inside its container, keeps credentials outside the agent workload, and can restrict network, file, and API access per agent. It is optimized for NVIDIA Vera CPUs but designed to extend to Arm and Intel processors.

Sentry is the hardware layer: an out-of-band watchdog running on BlueField-4 DPUs, which are separate processors sitting on the network card rather than on the CPU or GPU where the agent runs. Because it observes from outside the host, it keeps working even if the host is compromised, and NVIDIA claims it can quarantine an agent that breaches its boundary in milliseconds. The platform also uses behavioral detection for evasion patterns, such as an agent spawning sub-agents to slip past a block on the main one.

Guardicore is Akamai's contribution: microsegmentation, which means dividing the network into small isolated zones so a compromised workload cannot move sideways. It builds policy from workload identity, application context, and runtime behavior rather than static network rules, and it maps every workload interaction continuously. On BlueField-4 via NVIDIA's DOCA software platform, that segmentation runs in the data path at line speed, without taxing the GPU, CPU, or storage cycles the AI workloads need.

Put together, containment works in two independent dimensions. OpenShell answers "what can this agent do on its machine." Guardicore answers "what can this agent reach on the network." Sentry answers "what happens the instant it tries to cross either boundary." Three independent mechanisms, all enforced below the agent, so no single failure lets it out.

On commercialization: there is no separate joint SKU and no disclosed pricing. Guardicore is already a shipping product (a 2026 Gartner Customers' Choice in microsegmentation), so the commercial vehicle is almost certainly Guardicore licenses with BlueField as the premium enforcement point. The productization signal is in the dates: availability in H2 2026, then on storage and infrastructure partner platforms in H1 2027. That is OEM and channel language, and vendors do not put calendar dates on pure marketing.

Why does this matter for the investment stack?

The pattern from the inference stack post keeps repeating: the market prices the obvious layer and misses the adjacent ones the stack cannot work without. Agents cannot deploy at enterprise scale without containment, and containment cannot work as a software feature inside the thing being contained. It has to live in the infrastructure. Akamai spent a decade building the world's most distributed network and the last five years buying its way into Zero Trust security. That combination is now sitting exactly where the agent era needs it.

The golden trio had a missing member. It looks like it found one.

Research and opinion, not investment advice. Do your own due diligence before investing.