Every enterprise AI conversation we’ve had this year ends in the same place. A team has an agent that works. It writes code, calls internal APIs, fixes its own mistakes. Then someone asks what happens when 1,000 of these run across the company, and the room goes quiet.

That is the problem we kept hearing from teams building agentic systems. 

Those teams weren’t necessarily blocked on model quality or inference throughput; they were blocked on a question nobody's stack could answer cleanly: How do you let an agent execute code against real systems and still account for exactly what it touched and who approved it?

When an agent can only generate text, the worst outcome is a bad answer. When an agent can execute, the worst outcome is a deleted production database. Every customer we talked to was solving this in isolation, ineffectively, and through fragmented approaches. Security for agents has to be a default of the platform they run on, not something each team rebuilds in isolation with an ad-hoc stack. That’s what we are encoding into Red Hat AI with OpenShell — an open source project and a secure agent runtime also part of the NVIDIA Open Agent Safety Platform launched today.

Why OpenShell

Alongside NVIDIA and the open source OpenShell community, we’re building the security layer that lets enterprises benefit from autonomous agents without giving up control. This is infrastructure the industry needs, and it’s better built in the open, where trust boundaries can be inspected and challenged by everyone relying on them.

OpenShell puts enforcement directly in the environment rather than relying solely on the model. Prompt-level guardrails matter, but a model that’s been talked into misbehaving still holds whatever credentials you gave it. OpenShell governs how an agent executes, what it can see and do, and where inference goes. It is an infrastructure policy layer underneath whatever the agent happens to be. It delivers agent sandboxes built for long-running workloads. A policy engine evaluates filesystem, network, and process access. A gateway checks every action before it reaches the host.

It doesn’t make the agent helpless, either. When an agent hits a constraint, it can reason about the roadblock and propose a policy change. A human keeps the approval.

Red Hat is invested in OpenShell for the long term, contributing upstream as maintainers alongside NVIDIA and the broader community because we believe this is the layer that matters right now. 

How it runs

OpenShell runs each agent, session, or both as its own execution environment with multiple enforcement layers, including Landlock, seccomp, user and network namespace isolation, and L7 inspection.

Policy is process-aware. OpenShell identifies the specific binary making each outbound connection and verifies its SHA-256 hash before evaluating the rule, so a policy can permit the agent runtime to reach 1 endpoint while nothing else in the sandbox can.

Credentials live outside the agent's workload and are injected only at the network boundary. A compromised agent holds nothing worth exfiltrating. Blocked connections surface as structured Open Cybersecurity Schema Framework (OCSF) denials rather than silent failures, which is what makes them useful to a security team.

One pattern we actively advocate for, and have been validating across various agent archetypes, is separating the thinking from the execution. Reasoning and orchestration stay with a model provider. Code execution and file access happen inside a sandbox on infrastructure the customer controls. The platform will enforce that split rather than trusting the agent. Today that answers a data residency requirement, but we think it is where agent security ends up more broadly.

What we validated

Earlier this year we set out to answer "what does a secure agent deployment actually look like, regardless of which harness or framework a team picks?" We observed that teams sandbox agents in 1 of 3 ways: the whole agent, the execution environment, or only the generated code. A runtime that covers 1 of them pushes the problem somewhere else. We validated OpenShell's enforcement layer across all 3, including agents built on different frameworks and running on both Podman and Red Hat OpenShift.

That validation work led to reference architectures for secure agentic workspaces. These are patterns for how agents handling sensitive workloads can run most securely. The first is NVIDIA's Secure Agent Workspace reference design. Each user gets a dedicated workspace virtual machine (VM) with OpenShell sandboxing the agent execution boundary, with enterprise single sign-on (SSO), GitOps-managed policy, and no shared agent process space. 

The reference architecture is available as a validated pattern, and we are actively looking for feedback as we continue to evolve it.

Where this goes next

Red Hat is actively collaborating with NVIDIA and the community to integrate OpenShell into Red Hat AI as a native platform capability, so that agent security becomes a default rather than an assembly exercise.

Start by auditing what your agents can reach today, including credentials, databases, and internal services. The list is always longer than you expect. When you’re ready to go further, the OpenShell documentation and the OpenShell repository are the places to start.

리소스

적응형 엔터프라이즈: AI 준비성은 곧 위기 대응력

Red Hat의 COO 겸 CSO인 Michael Ferris가 쓴 이 e-Book은 오늘날 IT 리더들이 직면한 AI의 변화와 기술적 위기의 속도를 살펴봅니다.

저자 소개

Adel Zaalouk is a product manager at Red Hat who enjoys blending business and technology to achieve meaningful outcomes. He has experience working in research and industry, and he's passionate about Agentic AI and how it can be used to address real problems.

Younes Ben Brahim is a Principal Product Marketing Manager at Red Hat, focusing on the strategic positioning and market adoption of Red Hat's AI platform offerings. Younes has spent over 15 years in the IT industry leading product marketing initiatives, managing product lifecycles for HPC & AI, and delivering consulting services.
Prior to Red Hat, he has worked with companies like NetApp, Dimension Data, and Cisco Systems, providing technical solutions and product strategy for enterprise infrastructure and software projects.

UI_Icon-Red_Hat-Close-A-Black-RGB

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Virtualization icon

가상화

온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래