Intel® AI for Enterprise Agent Toolkit Adds NVIDIA OpenShell for...
Intel integrates NVIDIA OpenShell into its AI for Enterprise Agent Toolkit to enforce policy-based sandboxes for AI agents. The Apache-2.0 runtime uses YAML to restrict file, network, and process access, preventing credential leaks. It operates within Intel TDX confidential VMs, adding a kernel-level enforcement point outside the model's reach.

Intel has added NVIDIA OpenShell as an optional component of its AI for Enterprise Agent Toolkit. The open‑source runtime enforces declarative policies written in YAML, controlling file, network and process access for AI agents. It runs inside Intel Trust Domain Extensions confidential VMs, so the enforcement point sits outside the model’s own context. Every outbound request passes through a policy engine that can allow, deny or log the traffic and can attach endpoint‑bound credentials. The new layer closes a gap that has kept agentic pilots from passing security reviews, because it can stop an agent from leaking data even when the workload itself is isolated. By minting a dedicated model key for each sandbox, the toolkit can track usage separately and enforce budgets through the GenAI Gateway. The approach reuses the existing sandbox controller, inference gateway and proxy settings, making it additive rather than disruptive. It is not yet proven how the policy engine will perform at scale in production environments, and Intel has not published quantitative results on overhead. The effectiveness of OpenShell against sophisticated adversarial prompts remains uncertain, as does the impact on latency for high‑throughput workloads. Further independent testing will be needed to confirm the claimed security benefits.