Partnerships

Anthropic Adds NVIDIA OpenShell Controls to Claude Managed Agents

mm
Add Unite.AI to your preferred sources on Google

Anthropic on September 28, 2026 announced a collaboration with NVIDIA that pairs Claude Managed Agents, its suite of composable APIs for building and deploying production-grade agents, with NVIDIA’s open-source OpenShell runtime software. Managed Agents is available now.

NVIDIA the same day announced the Open Agent Safety Platform, an open software platform and reference system design for strengthening AI security. According to NVIDIA’s OpenShell page, that platform combines the OpenShell secure runtime and NVIDIA Sentry with BlueField-4 in-silicon security enforcement. Anthropic said it worked with NVIDIA to add layers of security and control to the agent stack.

Anthropic framed the release around a shift it says is under way in how companies use AI. Companies are moving from using AI to answer questions toward deploying agents that handle complex work across business units, use proprietary data and take actions on behalf of users, according to the company’s post on the Claude blog. As models improve, agents find more uses and get more access, and Anthropic said the more access an agent has, the more its company needs to control and check what it does.

Managed Agents Architecture and Features

Claude Managed Agents runs the agent loop on a separate server from the sandbox, the isolated environment where the agent’s work happens. Passwords and access keys sit in a separate vault, out of the agent’s view.

The suite provides audit trails that record what each agent did, and it integrates with a company’s existing access controls. Companies can bring their own sandbox setup and choose where and how it runs.

Anthropic describes the overall protection as layered. Safeguards sit inside the model, while Managed Agents and OpenShell add limits outside the model that apply to what the agent does. Each layer enforces its limits independently, so protection does not depend on any single layer, and the company said the layers are modular so customers can adopt the ones that fit their setup.

Listed capabilities include secure sandboxing with authentication and tool execution handled for the user; long-running sessions that operate autonomously for hours, with progress and outputs persisting through disconnections; multi-agent orchestration, in which agents can spin up and direct other agents to divide complex work; and governance features that give agents access to real systems with scoped permissions, identity management and execution tracing built in.

OpenShell Policy Enforcement

OpenShell is open-source secure runtime software from NVIDIA that governs and monitors AI agent behavior and enforces a policy on every action. It denies actions by default, permitting only what a written rule allows, and it screens each tool an agent attempts to use while applying rules to the files, network connections and data the agent touches. Enforcement happens outside the agent, and OpenShell logs every decision it allows or blocks.

According to Anthropic, teams can start with narrow permissions, review the log, and use Claude to tighten the rules toward the least access a task needs. OpenShell’s policy prover then uses mathematical proof to confirm what the agent can reach under the rules the team wrote.

NVIDIA’s OpenShell product page describes policy enforcement running outside the agent’s own process rather than depending on the agent’s cooperation, with every allow and deny decision auditable. NVIDIA documents four components. Agent sandboxes run each agent with kernel-level isolation and no direct network access, monitoring and filtering the agent’s system calls in the kernel. A gateway acts as the control plane, authenticating users, managing the sandbox lifecycle and brokering all access to sandboxes. A supervisor evaluates every network request against policy at the binary, destination, method and path levels and supplies credentials only where policy allows, with policy updates applying live. The policy prover uses formal verification to check whether policies stay within an allowed access boundary and whether proposed network rules add risky access.

The OpenShell documentation states that policies are declared in YAML and that controls span four layers: filesystem, network, process and provider credentials. Its risk table lists mitigations for data exfiltration, credential theft, unauthorized API usage and privilege escalation. NVIDIA describes OpenShell as model-agnostic and harness-agnostic, naming supported agent paths that include Claude Code, Codex, GitHub Copilot CLI, Hermes, LangChain Deep Agents, OpenClaw and OpenCode, deployed across cloud, hybrid, on-premises, edge and air-gapped infrastructure.

Early Customers and Availability

Anthropic named three companies already using Managed Agents. Notion lets teams hand work to Claude inside their workspace, where engineers use it to ship code and other employees use it to produce websites and presentations, with dozens of tasks able to run in parallel. Rakuten runs specialist agents across engineering, product, sales, marketing and finance, each deployed within a week. Asana built AI Teammates, agents that work alongside people in Asana projects, pick up tasks and draft deliverables, and Anthropic said Managed Agents let Asana’s team add advanced features faster than it could have otherwise.

Managed Agents can operate in a sandbox the customer controls, either running on the customer’s own infrastructure or with a managed provider. OpenShell is available on GitHub and on NVIDIA’s developer resources page under the Apache 2.0 license.

Aiden Cross is an AI-generated strategist at Unite.AI, covering AI product strategy, execution, and the practical challenges of turning experimental models into scalable, market-ready products. His work focuses on how startups and enterprise teams move from prototypes and demos to reliable systems used by real customers.

With a pragmatic and detail-oriented perspective, Aiden analyzes product roadmaps, go-to-market strategies, platform decisions, and organizational trade-offs that determine whether AI initiatives succeed or stall. He pays particular attention to deployment realities, user adoption, infrastructure constraints, and the alignment between technical capability and business value.

Articles authored by Aiden Cross are AI-generated and reviewed by Unite.AI’s editorial team to ensure clarity, accuracy, and responsible coverage of how AI products are built, shipped, and scaled in the real world.