Summary
- SAP engineers are contributing directly to NVIDIA’s OpenShell codebase and embedding it into SAP Business AI Platform.
- The architecture is intended to connect runtime isolation with business authorisation, IAM, and audit trails.
- The work shows agent security moving from model safeguards towards execution controls and enterprise accountability.
SAP is building NVIDIA’s OpenShell secure runtime into its enterprise AI platform, creating a layered control model intended to restrict what autonomous agents can execute and connect those actions to existing identity and business-authorisation systems.
SAP said its engineers are contributing directly to the OpenShell codebase while embedding the runtime into SAP Business AI Platform. NVIDIA has made OpenShell broadly available as part of its wider work on agent safety.
The proposed architecture separates two related control questions. SAP’s Joule Studio runtime determines whether an action should be permitted from a business perspective, using role, authorisation, and process context. OpenShell provides an execution boundary governing how an agent runs, what resources it can access, and where inference takes place.
SAP and NVIDIA are working to connect those layers so runtime isolation can be associated with enterprise IAM frameworks, authorisation models, and audit trails. The companies also plan further hardening for regulated environments and work towards compliance-related capabilities on their product roadmap.
The integration remains vendor technology under development, and claims about improved safety or accountability will need to be demonstrated in deployed environments. The design direction is nevertheless relevant because autonomous agents create control problems that conventional chatbot deployments do not.
An assistant that generates text can produce inaccurate or inappropriate output. An agent with access to enterprise applications, data, credentials, development tools, or transaction systems can also take actions. Security therefore shifts from controlling what a model says to controlling which systems it can reach, which identities it can assume, what operations it can perform, and how those actions are recorded.
Traditional identity and access management provides part of the answer, but agentic systems can create dynamic execution paths that do not map neatly onto a human user’s session. A model may decide which tool to invoke, assemble several operations into a workflow, and act at machine speed across services.
Runtime containment offers another layer by limiting the environment in which an agent operates. Used properly, that can reduce the consequence of a model attempting an unexpected action, although it depends on configuration, isolation quality, credential handling, and the completeness of the controls surrounding the runtime.
The SAP-NVIDIA design also reflects a broader shift in enterprise AI procurement. Organisations evaluating agent platforms increasingly need evidence around identity boundaries, logging, privilege, data access, software execution, and incident investigation rather than relying solely on assurances about model behaviour.
Auditability will be especially important in regulated settings. If an autonomous system changes a business record, invokes code, makes a payment-related decision, or interacts with a critical workflow, the organisation needs to know which identity authorised the action, what context was supplied, what the agent attempted, and which control allowed or blocked it.
OpenShell does not remove the need for those governance decisions. Its significance is that large enterprise software providers are beginning to treat execution containment as a separate architectural requirement for autonomous AI rather than assuming model-level safeguards alone can carry the security burden.





