On March 16, 2026, Nvidia CEO Jensen Huang stood on stage at GTC 2026 and announced something that had less to do with chips than with plumbing. The Nvidia Agent Toolkit launched with 17 enterprise software partners attached from day one: Adobe, Salesforce, SAP, Atlassian, ServiceNow, Cisco, CrowdStrike, Palantir, Siemens and nine others. That is not a partner list you build for a demo. It is a bet that whoever supplies the models, the runtime and the guardrails underneath enterprise AI agents ends up owning more of the stack than whoever ships the agent’s chat window.
What’s Actually Inside the Agent Toolkit
Strip away the keynote language and the toolkit breaks into four pieces. Nemotron supplies the open reasoning models. AI-Q is the blueprint for autonomous knowledge agents that, per Nvidia, “perceive, reason and act on enterprise knowledge.” According to eWeek’s coverage, its hybrid frontier/open-model architecture currently tops both DeepResearch Bench leaderboards while cutting cost per query by more than 50%. cuOpt handles GPU-accelerated optimization for agents that need to plan, not just chat. And OpenShell, the piece most vendors will care about first, is an open-source runtime that enforces policy-based security, network and privacy guardrails on whatever an agent tries to do.
None of these pieces are novel in isolation. What’s new is Nvidia shipping them as one stack that a software vendor can drop underneath an existing product, instead of asking that vendor to assemble a model provider, an orchestration layer and a security framework from three different companies.
Why Adobe, Salesforce and SAP Signed On
Adobe is using the toolkit for what Nvidia describes as “hybrid, long-running” creativity and marketing agents, the kind that stay active across a campaign instead of answering one prompt and stopping. Salesforce’s integration is more concrete: customers building on Agentforce for service, sales and marketing get Nemotron models under the hood, plus a reference architecture where Slack becomes the conversational and orchestration layer for Agentforce agents running on Nvidia infrastructure. SAP took a similar path, wiring the open Agent Toolkit, NeMo included, into Joule Studio so customers design agents directly on SAP’s Business Technology Platform.
The pattern across all three: none of them are replacing their own product surface. They’re outsourcing the parts that are expensive to build well (model serving, inference optimization, security enforcement) to the one vendor selling GPUs to everyone else anyway.
The Real Product Is Governance, Not Model Size
The most telling adoption data doesn’t come from a tech company. IQVIA, the healthcare data and clinical-trial firm, has already deployed more than 150 agents built on the toolkit across internal teams and client environments, reaching 19 of the top 20 pharmaceutical companies. That’s not happening in a regulated industry like pharma without a security runtime a compliance team is willing to sign off on.
That lines up with what the broader market is telling researchers. An OutSystems survey cited by EnterpriseDNA’s analysis found 96% of organizations already using AI agents in some form, but 94% also reported concern that agent sprawl is adding complexity, technical debt and security risk. Inference speed stopped being the bottleneck a while ago. Getting a security team to approve an agent that can act, not just answer, is the bottleneck. OpenShell is Nvidia’s answer to that specific problem, and it’s arguably a bigger reason IQVIA and CrowdStrike showed up on the partner list than any benchmark score.
Nvidia vs. Microsoft, Google and AWS: A Platform War Underneath the Platforms
Nvidia isn’t the only company chasing this layer. Microsoft is building Azure AI Foundry around Copilot Studio, the Azure AI Agents service and tight integration with Entra ID and Power Platform, leaning on the fact that most enterprises already run Microsoft’s productivity stack. Google is pitching Vertex AI and the newer Gemini Enterprise Agent Platform as a neutral coordination layer built on the open A2A protocol and its Agent Development Kit, betting that openness wins over lock-in. AWS is doing the same thing through Bedrock, turning what could be a commodity model endpoint into a marketplace of agents and tools tied to the rest of AWS.
Nvidia’s angle is different from all three: it doesn’t own a cloud platform or a productivity suite, so it’s selling the infrastructure layer directly to software vendors instead of competing for the end-user relationship. Adobe, Salesforce and SAP get to keep their front doors. Nvidia gets to be underneath all of them, including, on May 31, an expanded version of the same push that added Microsoft, Canonical and Red Hat as partners, plus Nemotron 3 Ultra, a 550-billion-parameter model claiming 5x faster inference at up to 30% lower cost than comparable open models.
What This Means If You’re Evaluating an Agent Stack
For technical teams choosing how to build or buy AI agents in 2026, the partner list matters less than the questions it should prompt before signing anything:
- Which runtime enforces security and privacy policy on this agent, and can your compliance team actually audit it, or is “guardrails” a marketing word with no enforcement layer behind it?
- Is the cost model built for occasional prompts or for an agent running continuously? The unit economics are not the same, and vendor pricing pages rarely make the difference obvious.
- If you standardize on one vendor’s agent runtime today, how hard is it to move a workflow to a different model or orchestration layer in 18 months?
- Does the vendor’s agent stack integrate with the tools your team already lives in, like Slack, ServiceNow or your CRM, or does it require a parallel interface nobody will actually use?
These are infrastructure decisions dressed up as feature announcements. Nvidia, Microsoft, Google and AWS are all betting that enterprises will standardize on one agent stack rather than stitching together several, and each is trying to make itself the default before that decision gets made by accident.
Conclusion
The headline from GTC 2026 was the partner logos. The substance was Nvidia making a case that it should own the layer nobody sees: the runtime enforcing what an agent is allowed to touch, and the models deciding what it does next. Whether Adobe, Salesforce and SAP end up dependent on that layer or simply renting it for now is the question worth watching over the next year, not the announcement itself. If your team is evaluating agent platforms, start with the governance question, not the model benchmark. That’s where the real lock-in lives.
