CH NEO-ZÜRICH EDITION
WEATHER · CLEAR 14°C
BLEND OF THE DAY · 07/ROGUE
EST. 2027
THE AEC CYBER MORNING NEWS

PAZ Kaffi

DESIGN · DEMOLITION · CAFFEINE · DISPATCH
EDITION 1007 · 7 October 2026
BROADCAST 04:42 CET
2,400 BROADSHEETS PRINTED
READ TIME · 47 MIN
The Fence Goes Below the Agent: What NVIDIA's OpenShell Means for Design Offices
CODE
FRAME · 06:55
07-10-2026

The Fence Goes Below the Agent: What NVIDIA's OpenShell Means for Design Offices

NVIDIA's OpenShell sandbox and BlueField-4 Sentry watchdog fence AI agents from below. What Swiss architecture offices should write before any agent pilot.

On 28 September 2026, NVIDIA released a fence. The Open Agent Safety Platform has two parts. OpenShell is an open-source runtime that gives each AI agent its own sandbox. Sentry is a watchdog that runs on separate hardware and can stop an agent that crosses a line. Ana-Maria Stanciuc at TheNextWeb reports that more than 100 organisations are adopting it at launch, including Anthropic, Microsoft, SAP, Scale AI and JPMorgan Chase.

Start with what it is. Before the agent runs, the operator writes down which files, networks, tools and credentials it may use. Everything else is closed. According to Miles Okada at Unite.AI, policies are written in YAML and compiled to OPA/Rego. That is the policy language of the Open Policy Agent project, whose maintainers spent years building the layer most cloud permissions already rely on. OpenShell supports the Codex, Claude Code, Pi and Hermes agent frameworks. Harold Fritts at StorageReview reports that the code is on GitHub now, under the Apache 2.0 licence. It is tuned for NVIDIA Vera processors but also runs on Arm and Intel chips.

Sentry is the second line. It runs on NVIDIA BlueField-4 data processing units, physically separate from the agent’s own machine. If the agent breaks its boundary, Sentry can quarantine it within milliseconds. The rule is enforced by different hardware, and the model cannot negotiate with it. Jose Antonio Lanz at Decrypt sums up the background in one sentence: in recent incidents, agents worked around application-layer controls to finish their tasks. Hence the line StorageReview quotes from Mike Nicolls, president of SpaceXAI: “Safety should be enforced outside the model by additional controls the agent can’t get past.”

Jensen Huang, NVIDIA’s founder and CEO, puts the ambition plainly: “AI’s extraordinary potential for society will only be realized if we solve AI safety.” Paul Smith, Anthropic’s chief commercial officer, gives the buyer’s version: “Companies are giving AI agents more of their most important work, and they need to direct and verify what those agents do.” Per Decrypt, Anthropic has connected its Claude Managed Agents service to both OpenShell and BlueField, and SpaceXAI applies the controls to Grok and to its Cursor coding agents.

Who governs the fence

The work sits with the Open Secure AI Alliance, now governed by the Linux Foundation, with 120+ member organisations. Unite.AI also names a Shared AI Findings Exchange (SAFE) where members pass on what they learn. Neutral governance matters more than any single feature. Here is the trade-off, stated plainly: the sandbox is open, but the hardware watchdog runs on one vendor’s silicon. That is a procurement fact, and procurement facts tend to stick around for years — write the exit clause before the entry contract.

The adopter list reaches the physical world. Figure, Gecko Robotics and Skild AI are adding the controls to robots. Citi and JPMorganChase are building shared open-source agent-safety tools with Hitachi Energy, headquartered in Zürich, along with Schneider Electric and Siemens Energy. These are grid and plant operators. The rules that will govern robots on a building site are being written in rooms like these.

←TODAY: Agent permissions became an open, inspectable YAML file this week, rather than a setting hidden inside a vendor’s product.
→3012: Offices that kept their agent policies in version control passed every audit by showing the file.
Fulcrum: Permission written before the work starts is the only kind anyone can check afterwards.

The desk

Architecture offices are being offered agents that edit models, batch-annotate drawing sets and talk to site machines. Every office manager asks the same thing: what exactly can it touch? Computational designers already have the answer. A Grasshopper C# component declares its inputs and outputs, and nothing else gets through. A GDL object exposes only the parameters it lists. An agent deserves the same discipline. That holds for a Python bot doing Archicad automation and for a cloud copilot alike. Swiss and EU data-protection duties already apply to client files, so “enforced outside the model” belongs in the tender as a question for any vendor. Teams that want to read and write these rules themselves, rather than inherit them, can learn the scripting side in a hands-on Grasshopper and C# workshop.

Atelier: For an office trying out agents, the risk to watch is reach: an agent that can open the live central file and send email has more access than most interns. Monday move: before any pilot, write a one-page permission list. Name the project folders, the model versions, the cloud services, and state that no client credentials are allowed. File it next to the BEP.

Hack: Give every agent run its own copy of the project and a log that someone can read. Branch the exchange folder (IFC exports, scripts, schedules), let the agent work only there, then review the changes before anything goes back to the central model. The branch is your sandbox, and the diff is your audit trail.

git clone //nas/projects/P2026-exchange ~/agent-runs/P2026
cd ~/agent-runs/P2026 && git switch -c agent-$(date +%F)
# agent works here only; never in the central file
git add -A && git commit -m "agent run: annotation batch"
git diff --stat main

OpenShell promises a boundary and a watchdog — a smaller and more honest claim than good behaviour. Write your office’s version of that boundary before the next agent asks for access.

FILED FROM
CO-SIGNERS
PAZ Academy
CONFIDENCE
HIGH
REPRINTS
© PAZ - PARAMETRIC ACADEMY ZURICH · ALL RIGHTS RESERVED

PAZ Kaffi · multidisciplinary editorial, led by PAZ Academy

⚑ REPORT AN ERROR · SUBMIT A CORRECTION
◂ BACK TO FRONT PAGE · PAZ KAFFI

© 2026 PAZ Academy.