Nvidia launches OpenShell, open-source runtime for securing AI agents

Editorial illustration: Three robotic arms handle metallic cubes inside a transparent enclosure with green illuminated edges. A conveyor extends through a framed opening on the right.

In brief

  • Nvidia unveiled OpenShell, an open-source runtime for securing autonomous AI agents at GTC San Jose 2026
  • OpenShell enforces policy-based controls via YAML and kernel-level isolation using Landlock LSM and seccomp BPF
  • Integration with Nvidia Agent Toolkit and partners including Cisco, SAP, and Cadence enables enterprise deployment
  • GitHub repository reached 8.6k stars and 1,390 commits as of September 2026

Security Through Isolation and Policy

OpenShell enforces strict rules about what AI agents can and cannot do, defined through flexible YAML policy files. The runtime achieves this via kernel-level isolation using Landlock LSM and seccomp BPF — Linux security mechanisms that restrict process access at the operating system level. Landlock controls filesystem access, while seccomp BPF filters system calls.

Administrators can modify agent behavior without downtime. The runtime supports live policy updates, allowing rule changes without shutting down the agent. Every action gets logged in comprehensive audit trails, creating a full record of agent activity for compliance and debugging.

Integration and Enterprise Adoption

OpenShell integrates with Nvidia's existing Agent Toolkit and is frequently deployed alongside NemoClaw, Nvidia's agent orchestration framework. The project has gained traction in the developer community — as of September 2026, the GitHub repository had accumulated 8.6k stars and 1,390 commits.

Enterprise adoption is accelerating. Nvidia secured partnerships with Cisco, SAP, and Cadence to integrate OpenShell into enterprise workflows. On the hardware side, the runtime supports deployment across platforms from Dell, HPE, and Lenovo, ensuring compatibility across major infrastructure vendors.