IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
SAP & NVIDIA expand OpenShell for AI agent governance

SAP & NVIDIA expand OpenShell for AI agent governance

Tue, 29th Sep 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

SAP has expanded its collaboration with NVIDIA on the OpenShell runtime for AI agents, focusing on governance, security and auditability for autonomous systems used in business software.

SAP engineers are contributing directly to the OpenShell codebase, while the company is also embedding the software in its Business AI Platform. NVIDIA has announced broader availability of OpenShell alongside its Open Agent Safety Platform.

The effort aims to connect technical controls over how an AI agent runs with the business controls that determine whether it should act in the first place. SAP said its Joule Studio runtime applies business authorisation, role-based policy and process context before a request reaches the execution layer, while OpenShell manages the runtime boundary around the agent itself.

The combined approach is designed to address two questions for enterprise users: whether an agent is permitted to carry out an action, and how that action is contained and monitored once execution begins. This is intended to support customers that need stronger oversight of AI systems, particularly in regulated environments.

Technical work

SAP outlined four areas where its engineers are working on OpenShell. In platform architecture, it said, they have helped break the runtime into independently deployable components, separating the supervisor and agent execution layers so they can scale independently.

For Kubernetes-based operations, SAP said its contributions include operator support, image pull secret management for private container registries, custom volume claim templates and foreground deletion of sandbox resources. It has also worked to reduce the gateway image footprint and extend compute driver support across mixed enterprise infrastructure.

SAP added that its engineers have contributed to supervisor health monitoring and structured log-level configuration to help meet enterprise observability requirements. Those changes are aimed at giving customers more consistent oversight of runtime behaviour in production.

Governance layer

SAP said Joule Studio is designed to sit above the execution layer as a governance framework for AI agents. In practice, that places business rules, identity and access management controls, and audit trail requirements ahead of runtime execution.

OpenShell, by contrast, is positioned as the environment that controls what an agent can see, what it can do and where model inference is directed. By linking the two, SAP and NVIDIA aim to provide a system in which technical isolation and business accountability work together.

The companies are also working to strengthen the OpenShell runtime for deployment at enterprise scale, including in industries with strict compliance demands. The roadmap includes work towards FedRAMP, FIPS and other regulated-industry requirements.

Broader context

The collaboration reflects a wider industry effort to place controls around autonomous AI agents as businesses move from experimental tools to systems that can act across workflows, data sources and software environments. Unlike conventional software automation, agentic systems can make sequential decisions and trigger actions with less direct human involvement, increasing attention on containment, authorisation and audit records.

SAP and NVIDIA are also members of the Open Secure AI Alliance, which focuses on open research and safety practices for AI systems. Their work on OpenShell is part of that broader push to shape common approaches to securing agent-based software.

Joule Studio, which SAP describes as an AI-first development environment, includes the runtime and governance tools it wants developers and customers to use for enterprise agents. SAP said the runtime is available free to its customers and partners through October 2026.

The joint work is intended to tie runtime isolation to enterprise authorisation models, identity frameworks and audit trails.