Every enterprise AI conversation we’ve had this year ends in the same place. A team has an agent that works. It writes code, calls internal APIs, fixes its own mistakes. Then someone asks what happens when 1,000 of these run across the company, and the room goes quiet. That is the problem we kept hearing from teams building agentic systems. Those teams weren’t necessarily blocked on model quality or inference throughput; they were blocked on a question nobody's stack could answer cleanly: How do you let an agent execute code against real systems and still account for exactly what it touched and who approved it?

When an agent can only generate text, the worst outcome is a bad answer. When an agent can execute, the worst outcome is a deleted production database. Every customer we talked to was solving this in isolation, ineffectively, and through fragmented approaches. Security for agents has to be a default of the platform they run on, not something each team rebuilds in isolation with an ad-hoc stack. That’s what we are encoding into Red Hat AI with OpenShell — an open source project and a secure agent runtime also part of the NVIDIA Open Agent Safety Platform launched today.

Alongside NVIDIA and the open source OpenShell community, we’re building the security layer that lets enterprises benefit from autonomous agents without giving up control. This is infrastructure the industry needs, and it’s better built in the open, where trust boundaries can be inspected and challenged by everyone relying on them. OpenShell puts enforcement directly in the environment rather than relying solely on the model. Prompt-level guardrails matter , but a model that’s been talked into misbehaving still holds whatever credentials you gave it.

OpenShell governs how an agent executes, what it can see and do, and where inference goes. It is an infrastructure policy layer underneath whatever the agent happens to be. It delivers agent sandboxes built for long-running workloads. A policy engine evaluates filesystem, network, and process access. A gateway checks every action before it reaches the host. It doesn’t make the agent helpless, either. When an agent hits a constraint, it can reason about the roadblock and propose a policy change. A human keeps the approval.