AI News

NVIDIA has brought together dozens of companies and open-source organizations to form the Open Secure AI Alliance, a group focused on developing openly available tools for AI safety and cybersecurity. The initiative is designed to help defenders inspect, adapt and operate security systems across their own infrastructure rather than relying exclusively on closed AI providers.

The alliance includes companies such as Amazon, Microsoft, IBM, Cisco, Google? No—Google is not listed—along with Hugging Face, Mistral, Red Hat, CrowdStrike, Palo Alto Networks, Salesforce, ServiceNow, Databricks, GitHub and the Linux Foundation. NVIDIA says the group will develop and share technologies for securing software and AI agents, including models, agent harnesses, identity systems, evaluation tools and secure model formats.

An alliance built around open defensive infrastructure

NVIDIA frames the initiative as an extension of open-source security work already associated with the Linux Foundation’s Akrites initiative and the Open Source Security Foundation, or OpenSSF. Its stated goal is to help remediate and disclose vulnerabilities using open technologies while giving more defenders access to systems they can examine and modify.

The central argument is that AI security cannot depend solely on a small number of opaque, closed systems. NVIDIA says open models and tools can provide local control, data protection and the ability to adapt security workflows to particular industries or jurisdictions. The company also argues that a multi-vendor ecosystem can reduce dependence on any single provider.

That position does not amount to a rejection of closed models. NVIDIA says defenders need both open and closed frontier systems, using each where it is most appropriate. The alliance’s emphasis is on ensuring that capable open alternatives remain available for security operations and research.

The announcement comes as enterprises move from experimenting with language models to deploying AI agents that can access files, call software tools and take actions. That shift broadens the security problem beyond model behavior. It also introduces risks involving identity, permissions, isolation, auditability and the software supply chain.

The proposed stack reaches beyond model weights

NVIDIA says its contribution will include open models, model weights, data and research into agent harnesses. It is also releasing the NVIDIA Labs Object-Oriented Agent, or NOOA, framework on GitHub. The company describes NOOA as a research framework intended to make agent behavior easier to test, trace, audit and govern by improving how harnesses integrate with models.

Other examples cited by NVIDIA show the alliance’s intended breadth. HPE contributes to SPIFFE/SPIRE, an identity framework designed to verify agents and services cryptographically before they communicate or access enterprise resources. Hugging Face has offered Safetensors, a model-weight format intended to prevent remote code execution, to the PyTorch Foundation.

IBM and Red Hat are associated with Lightwell, which extends digitally signed patches into the open-source supply chain. Microsoft is contributing MDASH, described as a multi-model scanning harness in which specialized agents search for, debate and establish whether software bugs are exploitable.

The collection of projects suggests that the alliance is treating an AI agent as a complete operational system rather than simply a model. In practice, that means security controls would need to cover the model, its tools, its permissions, its logs and the infrastructure running it. Open harnesses and common formats could make those controls easier for independent teams to inspect and evaluate.

What the evidence shows—and what remains unproven

The available evidence comes primarily from NVIDIA’s own announcement. StorageNewsletter lists the same alliance launch, but its full article text is unavailable in the supplied reporting material. As a result, the membership list, technical contributions and stated objectives should be treated as information published by NVIDIA rather than independently verified evidence of joint execution.

NVIDIA points to a recent Hugging Face security incident as an example of why defenders may need open, self-hosted AI systems. According to NVIDIA’s account, closed tools blocked parts of the forensic analysis because they could not distinguish defenders from attackers. Hugging Face then ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.

That account illustrates the operational case for local control, but the details are presented by NVIDIA and are not independently substantiated in the supplied sources. The announcement also does not provide a delivery timetable, governance model, funding structure, adoption figures or a description of how the participating organizations will coordinate releases and vulnerability response.

The safety debate is similarly unresolved. NVIDIA acknowledges that open models can be misused, including by weakening safeguards or repurposing capabilities for attacks. Its proposed answer is to combine openness with evaluation, red-teaming, usage rules and rapid remediation. Those are principles rather than demonstrated outcomes at this stage.

Why builders and enterprise buyers should care

For AI builders, the alliance could create more reusable components for securing agentic applications. Standardized identity, safer model formats and testable harnesses may reduce the need for every company to build separate controls around tool access, logging and model provenance. They could also make it easier to run security agents inside a company’s own environment when sensitive data cannot be sent to an external service.

Enterprise buyers should pay attention to how these projects mature, not simply to the size of the founding membership. Open components can improve portability and auditability, but they also create operational responsibilities. Organizations will still need to validate code, manage patching, monitor model behavior and decide which agents receive access to production systems.

The alliance may also sharpen competition between centralized AI platforms and more distributed security architectures. A strong open ecosystem could give security teams additional bargaining power and reduce dependence on one model provider. However, fragmented tools, inconsistent governance and unclear support arrangements could offset those benefits if the projects do not converge around practical standards.

For researchers and policy makers, the announcement reinforces a consequential question: whether open AI systems should be treated primarily as risks to restrict or as defensive infrastructure that security teams need to examine and control. NVIDIA is clearly advocating the latter view, while conceding that openness requires safeguards rather than unrestricted deployment.

What to watch next

The first signal will be whether the alliance publishes a concrete governance structure, shared roadmap or technical standards beyond the projects named in NVIDIA’s announcement. Buyers should also watch for production-ready releases from NOOA, MDASH, SPIFFE/SPIRE and related agent-security tools, along with documentation showing how they work across different models and cloud environments.

Independent evaluations will matter more than the partner list. Useful evidence would include reproducible testing of agent permissions, vulnerability detection, false positives, resistance to prompt injection and the security of model and tool supply chains. It will also be important to see whether participating companies disclose vulnerabilities through a common process and maintain the projects over time.

Creati.ai perspective

The Open Secure AI Alliance is significant because it defines AI security as an infrastructure and systems problem, not merely a question of choosing a safer model. Its most practical contribution could be a shared layer of identity, harnesses, formats and evaluation tools that lets organizations operate agents with more visibility and control.

But the announcement is still a starting point. NVIDIA has supplied a broad coalition and a set of vendor-reported examples, not proof that an interoperable defensive stack already exists. The alliance will earn credibility through open governance, independent testing and sustained maintenance—especially when its tools are used in high-pressure security incidents rather than demonstrations.

Featured

NVIDIA and Industry Leaders Form Open Secure AI Alliance for Defensive AI

NVIDIA and dozens of technology companies launch the Open Secure AI Alliance, sharing open tools and controls to strengthen AI cybersecurity.