Key Notes
- Anthropic added Nvidia's open source OpenShell runtime to Claude Managed Agents the same day Nvidia announced its broader Open Agent Safety Platform.
- OpenShell enforces policy on every agent action outside the model itself, denying anything not explicitly allowed and logging every decision, while Managed Agents runs an agent's reasoning loop on a separate server from its sandbox and keeps credentials in a separate vault.
- Anthropic named Notion, Rakuten and Asana as early customers already using Managed Agents.
Anthropic has added Nvidia‘s open source OpenShell runtime to Claude Managed Agents, its suite of APIs for building and running production agents, giving enterprise customers an extra layer of control that sits outside the model itself.
The collaboration was announced the same day Nvidia unveiled its own Open Agent Safety Platform, which combines OpenShell with a monitoring layer called Sentry and hardware level enforcement on Nvidia’s BlueField-4 chips.
Why Anthropic Says It Needed This
Anthropic said companies are shifting from using AI to answer questions toward deploying agents that handle complex work across business units, touch proprietary data, and take actions on a user’s behalf. As models improve and gain more access, Anthropic said, the more a company needs tools to control and check what its agents actually do, rather than relying on the model’s own judgment alone.
Anthropic frames its overall approach as layered protection: safeguards built into the model itself, plus Managed Agents and OpenShell adding limits outside the model that apply to what an agent can access and do. Each layer enforces its limits independently, so protection does not depend on any single layer holding, and Anthropic said customers can adopt whichever layers fit their setup.
How Managed Agents is Built
Claude Managed Agents runs the agent’s reasoning loop on a separate server from the sandbox, the isolated environment where an agent’s actual work happens, and keeps passwords and access keys in a separate vault outside the agent’s view. The suite logs audit trails of what each agent did and integrates with a company’s existing access controls, and customers can bring their own sandbox setup and choose where it runs.
Listed capabilities include secure sandboxing with authentication and tool execution handled for the user, long running sessions that continue working for hours and survive disconnections, multi agent orchestration in which agents can spin up and direct other agents, and governance features that grant agents scoped permissions with identity management and execution tracing built in.
What OpenShell Adds
OpenShell governs and monitors agent behavior by enforcing policy on every action an agent attempts, denying anything not explicitly allowed by a written rule. It screens each tool an agent tries to use and applies rules to the files, network connections and data it touches, with every allow and deny decision logged for review. According to Anthropic, teams can start with narrow permissions, review the resulting logs, and use Claude itself to help tighten the rules toward the minimum access a task actually needs.
Nvidia describes OpenShell as model agnostic and harness agnostic, listing support for Claude Code, Codex, GitHub Copilot CLI, LangChain Deep Agents, OpenClaw and OpenCode, and says it can run across cloud, hybrid, on premises, edge and air gapped infrastructure.
The software runs under an Apache 2.0 license and is available on GitHub, though its own documentation has previously described the underlying project as alpha stage software still working toward reliable multi tenant enterprise deployments.
Early Customers
Anthropic named three companies already using Managed Agents. Notion said its engineers use it to ship code and other employees use it to produce websites and presentations, with dozens of tasks able to run in parallel.
Rakuten said it runs specialist agents across engineering, product, sales, marketing and finance, each deployed within about a week. Asana said the tools let it add advanced features to its AI Teammates product, which works alongside people inside Asana projects, faster than it otherwise could have.
Part of a Broader Response to Agent Incidents
The partnership lands amid heightened scrutiny of AI agent behavior. Nvidia has said its platform could have prevented that specific incident, a claim that reflects the company’s own assessment rather than independent testing.
Neither Anthropic nor Nvidia disclosed pricing for the added OpenShell integration, and it remains to be seen how many enterprise customers adopt the tighter controls voluntarily versus treating them as a response to reputational pressure following recent incidents across the industry.
Disclaimer: AIstify is an independent media brand owned and operated by NuvexMedia LLC, publishing news, research, and insights on artificial intelligence, emerging technologies, automation, and related industries. NuvexMedia LLC invests in and collaborates with companies across the AI, technology, software, and digital innovation sectors. These relationships do not influence AIstify’s editorial coverage, and the publication maintains full editorial independence to provide accurate, timely, and objective information. © 2026 NuvexMedia LLC. All rights reserved. This content is for informational purposes only and should not be considered legal, tax, investment, financial, or other professional advice.