
Agent safety has become top of mind in recent weeks, specifically focused on where failure modes lie and how to address them. We’re thrilled to support NVIDIA’s Agent Safety Platform, which addresses safety across three critical areas: the application layer, runtime, and infrastructure.
As a launch partner for NVIDIA OpenShell and part of the Open Secure AI Alliance, we are working together to further the open, secure frontier, including the stack powering agents in production.
Building open safety controls for agentic infrastructure
At Baseten, we believe openness is an advantage for AI safety. We continue to invest in building safety controls for the open frontier across inference, training, and sandboxes.
Base Labs develops and publishes methods for training and monitoring open models, and Baseten builds that work into our deployment infrastructure at runtime. We recently launched our safety infrastructure effort with Base Labs, Hugging Face, and Goodfire AI in this vein; joining the Open Secure AI Alliance extends that commitment.
Monitoring only helps if its signals connect to permissions, isolation, and checks before an agent executes code. Blaxel's sandboxes and networking layer are where those controls live for agents running on Baseten. Blaxel also supports OpenShell, NVIDIA’s open-source runtime that enforces policy at the kernel level; OpenShell is agnostic to the compute the agent runs on.
Why Blaxel: secure sandboxes for agents
We acquired Blaxel to build the cloud for the next trillion agents. While Baseten builds the infrastructure to train and serve models, Blaxel is the execution layer agents need to act: microVM sandboxes, persistent storage, and networking with tight access controls.
Today we're introducing a private preview of Carbon, Blaxel's fourth infrastructure generation built to support trillions of agents in production. Coming to Baseten soon, Carbon will provide the backbone for sandboxes and broader execution infrastructure for agentic workflows on the Baseten platform.
Introducing Carbon: Blaxel’s fourth-generation infrastructure
When Astra-grade agents are writing and running their own code, hardware-level isolation becomes a necessity (we've written before about why containers break down once agents start generating their own code). Carbon still runs on microVMs, and every Carbon sandbox gets its own dedicated IPv6 address. Somewhere between billions and trillions of agents will be running in parallel this decade; IPv6 is the only addressing scheme with room to spare.
Carbon is much more flexible and configurable than any previous infrastructure generation we built. Beyond IPv6, the main features shipping with Carbon are a wider kernel surface and runtime enforcement, manual snapshotting, forking, and a direct path from snapshot to production within milliseconds.
Because Carbon brings additional kernel capabilities to the sandbox, it can run heavier runtime software directly inside it. That opens the door to a new generation of tooling built specifically for frontier agentic AI, including NVIDIA's newly announced OpenShell. We built a ready-to-use template so you can boot a Carbon sandbox with OpenShell already installed.
If OpenShell flags an agent mid-task and quarantines it, Carbon's snapshots mean you roll back to the last known-good state instantly instead of losing the run.
Get early access to Carbon
Carbon is currently in private preview and rolling out progressively by region and workspace. The full snapshot and fork API reference is available in the Blaxel docs.
Upcoming posts will go deeper into security inside and outside Carbon sandboxes, forking and snapshotting workflows, and the application model that Carbon makes possible. If you're already on 3.0 and want access to Carbon, reach out!