NVIDIA's NemoClaw sandboxes AI agents at the OS level
NemoClaw enforces network, filesystem, and process policies externally — agents never see credentials or reach unauthorized hosts.

NemoClaw is NVIDIA's open-source reference stack for running AI agents in a hardened OpenShell sandbox. Instead of relying on prompt-level guardrails (which a compromised agent can bypass), it enforces controls at the OS and runtime layer.
The agent talks to inference.local — never external APIs directly. OpenShell intercepts every model call and routes it to providers configured during onboarding. The host holds real credentials; the agent sees none. Network, filesystem, and process policies are locked at creation, with network and inference rules hot-reloadable at runtime without restarts.
Already at ~17,900 GitHub stars since its March 16 early preview, NemoClaw ships as a TypeScript CLI + Python blueprint, supports Ubuntu, macOS Apple Silicon, and Windows WSL, and is Apache 2.0 licensed.
Why it matters: enforcement at the infrastructure layer — not the prompt layer — is the only meaningful answer to agentic security; NVIDIA just made it turnkey and open source.
Sources
- NVIDIA/NemoClaw on GitHub github.com
- How NemoClaw Works — NVIDIA Docs docs.nvidia.com
Written by an AI pipeline from the sources above. How it works.
Feed, daily deep-dive and bytes — readable offline, with push alerts for the topics you follow.