Key Takeaways
- NVIDIA and 35 other technology firms launched the Open Secure AI Alliance to create open, inspectable security tools for AI agents and software.
- The alliance builds on the Linux Foundation’s Akrites project and the Open Source Security Foundation (OpenSSF), aiming to give defenders transparent, locally controllable defenses alongside closed‑source AI products.
- While open models are not inherently safer, the group argues that access to both open and frontier closed models is essential for security teams to choose and control the right tools for each situation.
- A recent Hugging Face security incident highlighted the limits of closed AI: closed models blocked forensic analysis, whereas an open‑weight GLM 5.2 model enabled detailed investigation and containment.
- Partner contributions span model weights, agent harnesses, identity standards (SPIFFE/SPIRE), model storage formats (Safetensors), supply‑chain signing (Lightwell), and vulnerability‑scanning harnesses (MDASH).
- The alliance calls for treating open AI security components as defensive infrastructure, urging policymakers and investors to support shared datasets, evaluation frameworks, attack simulators, and red‑teaming tools while pairing openness with safeguards, usage rules, and rapid vulnerability remediation.
Formation and Membership of the Open Secure AI Alliance
NVIDIA, together with 36 other organizations spanning AI research, cloud computing, cybersecurity, enterprise software, and open‑source development, announced the creation of the Open Secure AI Alliance. Founding partners include Adobe, Cisco, Cloudflare, CrowdStrike, Databricks, Hugging Face, IBM, the Linux Foundation, Microsoft, Palantir, Red Hat, Salesforce, SAP, ServiceNow, Siemens, and Snowflake, among others. The broad coalition reflects a cross‑industry recognition that securing AI agents requires collaborative, openly inspectable technologies that can operate alongside proprietary solutions.
Alliance Objectives and Relationship to Existing Projects
The alliance’s stated goal is to develop and share open technologies that protect software and AI agents from cyber threats. NVIDIA explained that the initiative will build on the Linux Foundation’s Akrites project and the work of the Open Source Security Foundation (OpenSSF). By leveraging these existing foundations, the alliance aims to produce security systems that defenders can inspect, adapt, and run on their own infrastructure, thereby avoiding lock‑in to any single vendor while still being able to use closed‑source AI products when appropriate.
Balancing Open and Closed Models
A central tenet of the alliance is that openness alone does not guarantee safety. NVIDIA acknowledges that open models can be repurposed for cyberattacks or have their safeguards stripped. Instead, the group argues that security teams need access to both open and frontier closed models so they can select and control the tools best suited to each defensive scenario. “The world needs both closed and open models,” NVIDIA states, emphasizing that transparency and local control from open models complement the performance and robustness of proprietary systems.
The Hugging Face Incident as a Proof‑Point
To illustrate the practical limits of relying exclusively on closed AI, NVIDIA cited a recent security incident at Hugging Face. Closed AI tools were unable to differentiate malicious activity from legitimate forensic investigations, effectively blocking essential analysis. In response, Hugging Face deployed the open‑weight GLM 5.2 model on its own infrastructure, where it examined more than 17,000 actions and helped contain the breach. NVIDIA Founder and CEO Jensen Huang reinforced this point on LinkedIn, noting that an open‑weight frontier model enabled the critical forensics that closed systems had obstructed.
Reducing Vendor Dependency and Single Points of Failure
The alliance contends that concentrating cyber defenses within a small number of closed providers creates dangerous dependencies and single points of failure. By fostering an open, multi‑vendor ecosystem, organizations can diversify their defensive stack, reduce reliance on any single supplier, and maintain the ability to audit and modify security components as threats evolve. This perspective remains a position of NVIDIA and its partners rather than a settled conclusion about the relative security of open versus closed models.
Partner Contributions to an Open Defense Stack
Beyond sharing model weights, the alliance envisions an AI agent as a holistic system comprising models, identity controls, permissions, harnesses, guardrails, logs, and evaluation tools. NVIDIA is contributing open models, model weights, data, and research into agent harnesses through its new NVIDIA Labs Object‑Oriented Agent (NOOA) project—an open‑source framework designed to simplify testing, tracing, auditing, and governing AI agent behavior.
Other founding partners are developing complementary components:
- HPE advances SPIFFE and SPIRE, zero‑trust identity standards for verifying AI agents and workloads.
- Hugging Face offers Safetensors, a format for storing model weights that prevents remote code execution, to the PyTorch Foundation.
- IBM and Red Hat’s Lightwell provides digitally signed patches across the open‑source software supply chain.
- Microsoft’s MDASH harness coordinates multiple specialized AI agents to identify, assess, and demonstrate exploitable software vulnerabilities.
These efforts demonstrate the alliance’s intent to integrate existing open projects while also generating new research, although the exact contribution matrix, governance model, and licensing terms for future releases remain unspecified.
Governance and Unanswered Questions
While the announcement lists the full roster of 37 members—including firms such as Cadence, Capital One, Cloudera, Cognition, DoorDash, Elastic, LangChain, NAVER, NetApp, Nous Research, OpenClaw, Palo Alto Networks, Reflection AI, SK Telecom, Synopsys, and TrendAI—it does not detail how joint projects will be governed, what decision‑making processes will apply, or which open‑source licenses will cover forthcoming artifacts. Clarifying these aspects will be crucial for ensuring sustained collaboration and trust among participants.
Policy Advocacy: Treating Open AI Security as Defensive Infrastructure
Parallel to its technical work, the alliance is making a policy case that policymakers should regard open models, harnesses, and security tools as defensive infrastructure rather than treating openness itself as a vulnerability. NVIDIA urges companies and governments to invest in shared datasets, evaluation frameworks, attack simulators, and red‑teaming tools. The alliance acknowledges that powerful open models pose misuse risks—such as attempts to strip safeguards or repurpose them for attacks—but proposes a combined strategy: open access paired with robust safeguards, clear rules against malicious use, rigorous evaluations, and rapid vulnerability remediation processes.
Addressing Misuse Risks While Preserving Openness
The announcement openly accepts that widening access to frontier AI models can enable malicious actors to remove protections or re‑engineer systems for offensive purposes. In response, the alliance advocates a layered defense: maintaining transparency and inspectability while enforcing usage policies, conducting continuous security evaluations, and establishing swift patching mechanisms for discovered vulnerabilities. By coupling openness with accountability, the group aims to harness the benefits of community scrutiny and innovation without compromising overall security posture.
Conclusion: Toward a Collaborative, Resilient AI Security Future
The Open Secure AI Alliance represents a concerted effort to reshape how organizations defend AI‑driven systems. By marrying the strengths of open‑source transparency with the capabilities of proprietary technologies, the alliance seeks to give security teams the flexibility to choose, adapt, and audit their defenses. Realizing this vision will depend on clear governance, effective licensing, and sustained investment in shared security infrastructure—steps that, if achieved, could reduce vendor lock‑in, improve incident response capabilities, and foster a more resilient AI ecosystem.

