From finance and procurement to supply chain and manufacturing, specialized AI agents are moving into the enterprise systems where business decisions are made and workflows run at scale. The challenge now is trust: agents that touch systems of record need boundaries, policy enforcement and an audit trail before they can reach production.
The Announcement
Announced at SAP Sapphire — where NVIDIA founder and CEO Jensen Huang joined SAP CEO Christian Klein’s keynote by video — the expanded collaboration helps enterprises run specialized agents with security and governance controls. SAP is embedding NVIDIA OpenShell, an open source runtime for securely developing and deploying autonomous AI agents, into SAP Business AI Platform.
SAP engineers are codesigning OpenShell alongside NVIDIA, contributing back to the open source project. OpenShell provides isolated execution environments, policy enforcement at the filesystem and network layers, and infrastructure-level containment that guards against damage when agent logic fails.
Why the Application Layer Matters
Huang has described AI as a five-layer cake: energy, chips, infrastructure, models and applications. Applications sit on top, where AI creates economic value for knowledge workers. As a global leader in enterprise applications and business AI, SAP runs finance, procurement, supply chain and manufacturing workflows where agents must operate within policy, identity and process controls.
That makes SAP’s position at the core of enterprise operations a key driver of agentic AI adoption. Business agents need to understand roles, processes, permissions and data boundaries — and an execution environment that limits what an agent sees, what it can do and where inference runs.
OpenShell in the Agent Runtime
Within SAP Business AI Platform, OpenShell is the runtime security layer for all SAP AI agents, including custom agents built in Joule Studio, SAP’s environment for building and managing end-to-end enterprise agents. The two companies frame their technologies as complementary questions:
- NVIDIA OpenShell asks: Can this agent action safely execute?
- Joule Studio runtime asks: Should this action happen at all?
Together, the pair closes a gap that application-layer security alone cannot address, combining runtime hardening, policy modeling, enterprise identity integration and auditing hooks.
A Faster Start for Agent Builders
SAP customers building custom agents will get a faster path to production. NVIDIA NemoClaw, a reference blueprint for developing and deploying autonomous agents, will be available directly in Joule Studio — giving development teams a structured route from initial build to trusted production deployment without engineering security scaffolding from scratch.
What This Means
AI agents create value only when enterprises can trust them with their data — and for many organizations, that data lives in SAP, the system of record for finance, procurement and supply chain. By pairing NemoClaw blueprints with OpenShell’s runtime boundaries, SAP and NVIDIA are making agents ready to act while staying inside the boundaries enterprises require.