· David

NVIDIA at GTC 2026: a sandbox for agents, and what it leaves to integration

NVIDIA launched Agent Toolkit and the OpenShell runtime at GTC 2026, with SAP, Salesforce and ServiceNow among the adopters. What it means for governing agent access.

Les på norsk

NVIDIA is best known for chips, but at its GTC conference on 16 March the company launched software for building and running AI agents. NVIDIA Agent Toolkit is an open-source package, and the most interesting part for integration teams is OpenShell, a runtime that puts each agent in a sandbox with its own rules.

What was launched

  • OpenShell runs agents with isolation at the process level, least-privilege access and policies that decide what the agent may reach on the network. A privacy router removes personal data from prompts before they are sent to external models.
  • AI-Q is an open blueprint for research agents. It uses a frontier model for planning and NVIDIA’s own open Nemotron models for the rest of the work, and NVIDIA says this can cut the cost per query by more than half.
  • Nemotron models and ready-made skills for specialised agents.

NVIDIA lists 17 software companies that are adopting parts of the toolkit, among them SAP, Salesforce, ServiceNow, Atlassian, Box, Cisco, CrowdStrike, Palantir, Red Hat and Siemens. Security vendors Cisco and CrowdStrike work with NVIDIA on OpenShell.

Why it matters for integration

Until now, discussions of agent security have mostly been about the model: what it can be tricked into saying or doing. OpenShell moves the focus to the runtime: what the agent process is allowed to do, which network addresses it can reach, and what data leaves the company.

That is close to the questions integration teams already answer every day. An agent that updates an order in the ERP system or reads customer data from the CRM is, in practice, an integration. It needs a limited identity, a limited set of systems it can reach, and a log of what it has done.

What the sandbox does not solve

The analysts at Futurum make a useful point: agent trust is an infrastructure problem, but runtime security alone is not enough. A sandbox can stop an agent from reaching the wrong network address. It cannot tell whether the agent should be allowed to approve a payment, or whether the data it reads is correct.

Those decisions still sit in the systems and platforms the agent calls: in API management, in the integration platform and in the business applications’ own access control. For companies, the picture is layered:

  1. The runtime (for example OpenShell) limits what the agent process can do technically.
  2. The gateway and integration layer decide which APIs and tools the agent can call, with which rights, and log everything.
  3. The business systems enforce their own rules for what each identity may do.

What you should do

If your company is starting to run agents, do not make the runtime the only line of defence. Make sure every agent has its own identity, that all calls to internal systems go through a layer you control, and that there is a log that says which agent did what. Ask your iPaaS and API management vendors how their platforms fit together with runtimes like OpenShell.

Sources

This post was written with AI assistance and reviewed by the editor before publishing.

← All posts