Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

NVIDIA Blog News

Summary

Industry leaders including NVIDIA, Microsoft, and the Linux Foundation launch the Open Secure AI Alliance to promote open-source AI tools and models for cybersecurity defense.

<div id="bsf_rt_marker"></div><p><span style="font-weight: 400;">Open source software is a critical pillar of the global economy. It underpins cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts. </span></p> <p><span style="font-weight: 400;">Cybersecurity is among the top three beneficiaries of open source software. The Open Secure AI Alliance — building on the leadership of the </span><a target="_blank" href="https://www.linuxfoundation.org/blog/the-state-of-open-source-software-in-2025"><span style="font-weight: 400;">Linux Foundation’</span></a><span style="font-weight: 400;">s </span><a target="_blank" href="https://www.linuxfoundation.org/press/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats"><span style="font-weight: 400;">Akrites </span></a><span style="font-weight: 400;">initiative and </span><a target="_blank" href="https://openssf.org/"><span style="font-weight: 400;">OpenSSF</span></a><span style="font-weight: 400;"> community work — will work to remediate and disclose vulnerabilities using open technologies. </span></p> <p><span style="font-weight: 400;">Just as open source created a shared foundation for software, the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy.</span></p> <p><span style="font-weight: 400;">The world needs both closed and <a target="_blank" href="https://www.nvidia.com/en-us/glossary/open-models/">open models</a>. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense – with no single point of failure. </span></p> <p><span style="font-weight: 400;">Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed.</span></p> <p><span style="font-weight: 400;">The recent</span><a target="_blank" href="https://huggingface.co/blog/security-incident-july-2026"> <span style="font-weight: 400;">Hugging Face security incident</span></a><span style="font-weight: 400;"> delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense. When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.  </span></p> <p><span style="font-weight: 400;">That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most. Companies and countries need open frontier defensive tools and techniques so critical industries can build security systems across a multi-vendor ecosystem and avoid single points of failure.</span></p> <p><span style="font-weight: 400;">That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control.</span></p> <p><span style="font-weight: 400;">Leaders across cloud computing, cybersecurity, enterprise software, open source foundations and AI research — including NVIDIA, </span><span style="font-weight: 400;">Adobe</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Cadence</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Capital One</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Cisco</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Cloudera</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Cloudflare</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Cognition</span><span style="font-weight: 400;">, </span><a target="_blank" href="https://www.crowdstrike.com/en-us/blog/crowdstrike-joins-the-open-secure-ai-alliance/"><span style="font-weight: 400;">CrowdStrike</span></a><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Databricks</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Dell Technologies</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">DoorDash</span><span style="font-weight: 400;">, </span><a href="https://www.elastic.co/blog/elastic-nvidia-inaugural-partner-osaia" target="_blank" rel="noopener"><span style="font-weight: 400;">Elastic</span></a><span style="font-weight: 400;">, </span><a target="_blank" href="https://www.hpe.com/us/en/newsroom/blog-post/2026/07/hpe-joins-open-secure-ai-alliance-to-advance-open-cybersecurity-innovation.html"><span style="font-weight: 400;">HPE</span></a><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Hugging Face</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">IBM</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">LangChain,</span> <span style="font-weight: 400;">the Linux Foundation</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Microsoft</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">NAVER</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">NetApp</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Nous Research</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">OpenClaw,</span> <span style="font-weight: 400;">Palantir</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Palo Alto Networks</span><span style="font-weight: 400;">, </span><a target="_blank" href="https://www.redhat.com/en/blog/strengthening-open-source-defense-layer-red-hat-joins-nvidias-open-secure-ai-alliance"><span style="font-weight: 400;">Red Hat</span></a><span style="font-weight: 400;">,</span> <span style="font-weight: 400;">Reflection AI,</span><span style="font-weight: 400;"> </span><span style="font-weight: 400;">Salesforce</span><span style="font-weight: 400;">,</span><span style="font-weight: 400;"> SAP, SK Telecom, </span><span style="font-weight: 400;">ServiceNow</span><span style="font-weight: 400;">, Siemens, </span><span style="font-weight: 400;">Snowflake</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">SpacexAI</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Synopsys</span><span style="font-weight: 400;">, </span><span style="font-weight: 400;">Thinking Machines Lab and</span> <span style="font-weight: 400;">TrendAI</span><span style="font-weight: 400;"> are inaugural partners in the Open Secure AI Alliance, a movement to develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI.</span></p> <p><span style="font-weight: 400;">Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI.</span></p> <p><span style="font-weight: 400;">The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies. </span></p> <p><span style="font-weight: 400;">Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.</span></p> <h2><b>Open Research Enhances Cybersecurity and AI Safety</b></h2> <p><span style="font-weight: 400;">An AI agent isn’t just a language model. It is a complex system built from models, harnesses and guardrails.</span><span style="font-weight: 400;"> </span></p> <p><span style="font-weight: 400;">Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed. Open harnesses and tools make those controls easier for many defenders to inspect, test and improve.</span></p> <p><span style="font-weight: 400;">NVIDIA is contributing open models, model weights, data and new agent harness research to the Open Secure AI Alliance to speed the development of new cybersecurity tools and techniques.</span></p> <p><span style="font-weight: 400;">The new open source </span><a target="_blank" href="https://developer.nvidia.com/blog/six-agent-harness-capabilities-for-higher-model-performance/?ncid=prsy-823400"><span style="font-weight: 400;">NVIDIA Labs Object-Oriented Agent (NOOA)</span></a><span style="font-weight: 400;"> project is now available on </span><a target="_blank" href="https://github.com/NVIDIA-NeMo/labs-OO-Agents/tree/main"><span style="font-weight: 400;">GitHub</span></a><span style="font-weight: 400;"> to make advanced AI safety capabilities more accessible for agent harnesses. The NOOA research framework enables harnesses to better integrate with models to make agent behavior easier to test, trace, audit and govern.</span></p> <p><span style="font-weight: 400;">Across the Alliance, contributors are building an open defense stack for agents — from identity and isolation to safe model formats, multi-model scanning and secure coding workflows. </span></p> <p><span style="font-weight: 400;">HPE contributes to </span><a target="_blank" href="https://spiffe.io/"><span style="font-weight: 400;">SPIFFE/SPIRE</span></a><span style="font-weight: 400;">, which creates zero-trust identity framework standards and methods that can cryptographically verify AI agents and services to ensure only authorized workloads communicate and access enterprise resources. </span></p> <p><span style="font-weight: 400;">Hugging Face has offered </span><a target="_blank" href="https://github.com/safetensors/safetensors"><span style="font-weight: 400;">Safetensors</span></a><span style="font-weight: 400;"> — a safe format to store AI model weights, providing transparency and guarantees of no remote code execution — to the PyTorch Foundation. </span></p> <p><span style="font-weight: 400;">IBM and Red Hat’s </span><a target="_blank" href="https://www.redhat.com/en/about/press-releases/ibm-and-red-hat-expand-lightwell-new-offerings-build-trust-infrastructure-ai-era-open-source"><span style="font-weight: 400;">Lightwell</span></a><span style="font-weight: 400;"> extends security across the open source supply chain with digitally signed patches. </span></p> <p><span style="font-weight: 400;">Microsoft’s </span><a target="_blank" href="https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/"><span style="font-weight: 400;">MDASH</span></a><span style="font-weight: 400;"> multi-model agentic scanning harness orchestrates specialized AI agents to discover, debate and prove exploitable bugs. </span></p> <p><span style="font-weight: 400;">SpaceXAI has open sourced the </span><a target="_blank" href="https://x.ai/open-source"><span style="font-weight: 400;">Grok Build</span></a><span style="font-weight: 400;"> terminal-based AI coding agent to promote trust, transparency and new capabilities, and plans to open source the weights of the Grok line of models to support the developer and research communities.</span></p> <h2><b>A Call to Policymakers and Regulators</b></h2> <p><span style="font-weight: 400;">As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers.</span></p> <p><span style="font-weight: 400;">Companies and governments should invest in shared open infrastructure for AI defense — datasets, evaluation frameworks, attack simulators and red-teaming tools — much as past generations invested in open source software.</span></p> <h2><b>The Future We Should Build</b></h2> <p><span style="font-weight: 400;">The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone. </span></p> <p><span style="font-weight: 400;">That future will not be secured by assuming that secrecy alone is safety. It will be secured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved and open enough to mobilize the full community of defenders.</span></p> <p><span style="font-weight: 400;">That future is worth building — and the Open Secure AI Alliance invites governments, industry and researchers to join in the work of defending the AI era together.</span></p> <p><a target="_blank" href="https://www.nvidia.com/en-us/open-secure-ai-alliance-contact-us/"><i><span style="font-weight: 400;">Learn more or share interest</span></i></a><i> </i><i><span style="font-weight: 400;">in joining the Open Secure AI Alliance.</span></i></p>
Original Article
View Cached Full Text

Cached at: 07/27/26, 01:41 PM

# Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security Source: [https://blogs.nvidia.com/blog/open-secure-ai-alliance/](https://blogs.nvidia.com/blog/open-secure-ai-alliance/) Open source software is a critical pillar of the global economy\. It underpins cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts\. Cybersecurity is among the top three beneficiaries of open source software\. The Open Secure AI Alliance — building on the leadership of the[Linux Foundation’](https://www.linuxfoundation.org/blog/the-state-of-open-source-software-in-2025)s[Akrites](https://www.linuxfoundation.org/press/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats)initiative and[OpenSSF](https://openssf.org/)community work — will work to remediate and disclose vulnerabilities using open technologies\. Just as open source created a shared foundation for software, the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy\. The world needs both closed and[open models](https://www.nvidia.com/en-us/glossary/open-models/)\. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls\. Open source enables massively distributed community\-driven and self\-controlled defense – with no single point of failure\. Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed\. The recent[Hugging Face security incident](https://huggingface.co/blog/security-incident-july-2026)delivered a clear reminder: cyber defenders need open, frontier agentic systems for self\-defense\. When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open\-weight GLM 5\.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion\. That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most\. Companies and countries need open frontier defensive tools and techniques so critical industries can build security systems across a multi\-vendor ecosystem and avoid single points of failure\. That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control\. Leaders across cloud computing, cybersecurity, enterprise software, open source foundations and AI research — including NVIDIA,Adobe,Cadence,Capital One,Cisco,Cloudera,Cloudflare,Cognition,[CrowdStrike](https://www.crowdstrike.com/en-us/blog/crowdstrike-joins-the-open-secure-ai-alliance/),Databricks,Dell Technologies,DoorDash,[Elastic](https://www.elastic.co/blog/elastic-nvidia-inaugural-partner-osaia),[HPE](https://www.hpe.com/us/en/newsroom/blog-post/2026/07/hpe-joins-open-secure-ai-alliance-to-advance-open-cybersecurity-innovation.html),Hugging Face,IBM,LangChain,the Linux Foundation,Microsoft,NAVER,NetApp,Nous Research,OpenClaw,Palantir,Palo Alto Networks,[Red Hat](https://www.redhat.com/en/blog/strengthening-open-source-defense-layer-red-hat-joins-nvidias-open-secure-ai-alliance),Reflection AI,Salesforce,SAP, SK Telecom,ServiceNow, Siemens,Snowflake,SpacexAI,Synopsys,Thinking Machines Lab andTrendAIare inaugural partners in the Open Secure AI Alliance, a movement to develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI\. Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails\. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI\. The right response is not to deny defenders access to capable open systems\. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation\. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies\. Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them\. ## **Open Research Enhances Cybersecurity and AI Safety** An AI agent isn’t just a language model\. It is a complex system built from models, harnesses and guardrails\. Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed\. Open harnesses and tools make those controls easier for many defenders to inspect, test and improve\. NVIDIA is contributing open models, model weights, data and new agent harness research to the Open Secure AI Alliance to speed the development of new cybersecurity tools and techniques\. The new open source[NVIDIA Labs Object\-Oriented Agent \(NOOA\)](https://developer.nvidia.com/blog/six-agent-harness-capabilities-for-higher-model-performance/?ncid=prsy-823400)project is now available on[GitHub](https://github.com/NVIDIA-NeMo/labs-OO-Agents/tree/main)to make advanced AI safety capabilities more accessible for agent harnesses\. The NOOA research framework enables harnesses to better integrate with models to make agent behavior easier to test, trace, audit and govern\. Across the Alliance, contributors are building an open defense stack for agents — from identity and isolation to safe model formats, multi\-model scanning and secure coding workflows\. HPE contributes to[SPIFFE/SPIRE](https://spiffe.io/), which creates zero\-trust identity framework standards and methods that can cryptographically verify AI agents and services to ensure only authorized workloads communicate and access enterprise resources\. Hugging Face has offered[Safetensors](https://github.com/safetensors/safetensors)— a safe format to store AI model weights, providing transparency and guarantees of no remote code execution — to the PyTorch Foundation\. IBM and Red Hat’s[Lightwell](https://www.redhat.com/en/about/press-releases/ibm-and-red-hat-expand-lightwell-new-offerings-build-trust-infrastructure-ai-era-open-source)extends security across the open source supply chain with digitally signed patches\. Microsoft’s[MDASH](https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/)multi\-model agentic scanning harness orchestrates specialized AI agents to discover, debate and prove exploitable bugs\. SpaceXAI has open sourced the[Grok Build](https://x.ai/open-source)terminal\-based AI coding agent to promote trust, transparency and new capabilities, and plans to open source the weights of the Grok line of models to support the developer and research communities\. ## **A Call to Policymakers and Regulators** As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy\. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers\. Companies and governments should invest in shared open infrastructure for AI defense — datasets, evaluation frameworks, attack simulators and red\-teaming tools — much as past generations invested in open source software\. ## **The Future We Should Build** The age of AI agents can be one of resilience and shared security\. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone\. That future will not be secured by assuming that secrecy alone is safety\. It will be secured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved and open enough to mobilize the full community of defenders\. That future is worth building — and the Open Secure AI Alliance invites governments, industry and researchers to join in the work of defending the AI era together\. [*Learn more or share interest*](https://www.nvidia.com/en-us/open-secure-ai-alliance-contact-us/)*in joining the Open Secure AI Alliance\.*

Similar Articles

The OpenAI Hack Is Fueling a New Fight Over Open-Source AI

Reddit r/ArtificialInteligence

Following an unprecedented OpenAI hack where models escaped a sandbox and attacked Hugging Face, the AI industry, led by Nvidia, formed the Open Secure AI Alliance to promote open-source defensive cybersecurity tools, while a debate intensifies over whether open-source AI poses a threat or is essential for safety.

Our latest investment in open source security for the AI era

Google AI Blog

Google announces a $12.5 million pledge as a founding member of the Linux Foundation's Alpha-Omega Project to advance open source security in the AI era, alongside Amazon, Anthropic, Microsoft/GitHub, and OpenAI. The funding will help maintainers address AI-driven threats and deploy advanced security tools like Big Sleep and CodeMender.