Ackuity is building an integration with NVIDIA OpenShell that adds context-aware decisions on top of OpenShell's sandbox policy. OpenShell policy sets what an agent may touch. Ackuity checks whether a specific action makes sense right now, using live context, behavioral baselines and threat patterns.
Ackuity is a member of NVIDIA Inception. The integration described here is our own engineering work, and it is still in development.
What did NVIDIA launch?
On September 28, 2026, NVIDIA announced the Open Agent Safety Platform. It has two parts and a reference system design that combines them. OpenShell is open source software, released on GitHub under the Apache 2.0 license, that runs each agent in a sandbox with kernel-level isolation. Sentry is an out-of-band watchdog that runs on NVIDIA BlueField-4 DPUs and, according to NVIDIA, can quarantine an agent that tries to move outside its boundaries in milliseconds.
Inside OpenShell, a supervisor sits on the trusted side of the sandbox boundary. NVIDIA's architecture documentation describes it as the workload's only allowed egress path. The supervisor is the agent's only way out, inspecting outbound HTTP, GraphQL and MCP traffic against policy before it leaves, and it supplies credentials only where policy allows. Operators define in policy which files, networks, tools, processes and credentials an agent can access. NVIDIA says the platform's products are in various stages of availability; OpenShell is available now. Our explainer on what NVIDIA OpenShell is and how it works covers the platform in more depth.
Why does control belong outside the agent?
We built Ackuity, the Agent Execution Control Switch for AI agents, on the same principle OpenShell uses. You cannot write rules inside an agent and expect the agent to follow them. An agent that can reason can also reason around its own instructions, so the control has to be independent of the agent and sit outside its scope.
Placement matters too. We call the right spot the Goldilocks zone: not inside the agent, not at the gateway. Inside the agent, the controlled party is also the control. At a gateway, the control sees the call without its context, and most agent actions never cross a gateway at all. That zone is beside the agent, in the execution path: close enough to see intent, plan and history, and out of the agent's reach. OpenShell's supervisor occupies that kind of position, which makes it a natural place to attach an Ackuity decision.
What does OpenShell policy decide, and what does Ackuity add?
OpenShell policy answers a scope question. May this agent read this path, reach this destination, send this kind of request? Every deployment needs that answer. Scope alone cannot say whether a permitted action is a good idea at this moment. A finance agent may be allowed to call the payments API, and the question of whether this payment, for this user, after these earlier steps, should go through still remains.
Ackuity answers that question with three checks on each action.
Does the action fit the enterprise security context?
Ackuity keeps a live picture of the users, agents and their entitlements, target systems and intent behind each action. We call it the Agent Security Context Graph. It gathers 29 signals across six dimensions, outside the agent and before the action runs, so the agent cannot edit it:
- User: identity, permissions, attributes and risk status.
- Agent: identity and credentials, permissions and scope, tools, business rules and risk status.
- Intent: the user's request, the agent's goal and any delegations.
- Reasoning: planning steps, chain of thought, and the integrity of memory and context data.
- Systems: system and data policies, regulations, owner and provenance, state change impact, tool integrity and vulnerabilities.
- History: earlier actions in the session, prior alerts, user and agent action history, and baseline drift.
Is the action anomalous?
Ackuity compares each action with historical baselines for the agent, the user, the tool and the target system. A large export can be routine for one reporting agent and far outside the norm for another, or for the same agent acting for a different user.
Do the cumulative actions form a threat pattern?
Steps that look harmless one at a time can add up to an attack. Reading a config file, searching for credentials and opening a new outbound connection may each pass policy. Together they look like credential theft followed by exfiltration. Ackuity checks sequences against 60+ threat models in 14 categories, mapped to MITRE ATLAS, OWASP and NIST. The engine combines rules, behavioral baselines and small language models and correlates them across steps, an approach we call neurosymbolic verification. A decision takes 40 to 100 ms. That figure is decision time, not end-to-end latency.
How does the OpenShell integration work?
OpenShell has an extension point called supervisor middleware. It is a set of gRPC services that the supervisor calls after policy evaluation and before it injects provider credentials. Middleware lets an external service allow, deny or modify agent traffic. NVIDIA's documentation says the middleware API is still evolving.
We are connecting Ackuity's threat and context engine to that hook. When OpenShell policy permits a request, the supervisor hands it to Ackuity, which runs the three checks and returns a verdict. The verdicts map onto part of Ackuity's response ladder:
- Allow: the request goes through as sent, and Ackuity logs the decision.
- Constrain: Ackuity modifies the request, for example by masking a field or narrowing a query, and the scoped version goes through.
- Block: Ackuity denies the request before it reaches the target.
Human in the loop and Terminate are also on Ackuity's ladder. We have not yet settled how they will map onto OpenShell's interfaces, and we will document that once the design is stable.
What is the integration status?
The integration is in development. The middleware contract is still changing, and we will follow it as NVIDIA updates it. Sentry integration is a future direction that depends on NVIDIA's partner interfaces. Quarantine is a sound last resort, and we explain where it fits beside per-action decisions in kill switch or control switch. Current status and answers to common questions live on our NVIDIA OpenShell integration page.
What if you do not run OpenShell?
The same decision layer runs with Ackuity's own sidecar in the agent's pod, on any Kubernetes cluster, including NVIDIA-based infrastructure. The sidecar is software only and needs no changes to agent code. It sits in the same place as the supervisor hook, beside the agent and outside its scope. How the Ackuity platform works covers the sidecar and the other ways to deploy.
NVIDIA, OpenShell and BlueField are trademarks of NVIDIA Corporation.