NVIDIA OpenShell drops out-of-process agent governance
NVIDIA OpenShell is an open-source security runtime providing a kernel-level sandbox for autonomous AI agents. By moving governance outside the agent's process, it prevents prompt injection from overriding safety constraints and resource limits.
OpenShell addresses the "inverted" threat model of AI agents where the risk isn't just escaping the sandbox, but the agent misusing its legitimate access. It provides kernel-level isolation via Linux Landlock, out-of-process enforcement to block prompt injection, and a model-agnostic privacy router for local context management. Declarative YAML policies allow developers to define granular access without modifying code, and integration with the NemoClaw stack bridges the gap between local RTX development and enterprise DGX deployment.
DISCOVERED
22d ago
2026-03-21
PUBLISHED
22d ago
2026-03-21
RELEVANCE
AUTHOR
Better Stack