NVIDIA and dozens of firms form Open Secure AI Alliance
TL;DR
- NVIDIA, Microsoft, IBM, Red Hat, Hugging Face, Cloudflare, CrowdStrike and dozens of other companies launched the Open Secure AI Alliance for open-source AI security tools.
- Initial contributions include HPE's SPIFFE/SPIRE agent identity, Hugging Face's Safetensors weights format, Microsoft's MDASH scanning harness, and NVIDIA's NOOA agent framework.
- The alliance urges policymakers to treat open AI systems as defensive assets and to reject blanket restrictions on open frontier AI systems.
A coalition of roughly three dozen enterprise, cloud and AI companies has planted a flag on the 'open' side of an argument that has been running quietly for months in security and policy circles. According to NVIDIA's announcement, the new Open Secure AI Alliance brings together NVIDIA, Microsoft, IBM, Red Hat, Hugging Face, Cloudflare, CrowdStrike, Palo Alto Networks, Palantir, Databricks, Snowflake, Salesforce, ServiceNow, the Linux Foundation and others to build open-source tools, technologies and techniques for AI safety and cybersecurity.
The framing matters as much as the member list. The alliance's core claim is that 'for cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls.' Translated, the group wants regulators to treat open weights as a defensive asset rather than a proliferation risk. NVIDIA's post explicitly calls for policymakers to reject 'blanket restrictions on open frontier AI systems,' arguing such rules would 'weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers.'
The initial contributions give a sense of what the stack will actually look like. HPE is bringing SPIFFE/SPIRE for zero-trust identity that cryptographically verifies AI agents and services. Hugging Face is offering Safetensors, a weights format designed to prevent remote code execution, to the PyTorch Foundation. IBM and Red Hat are extending a project called Lightwell to distribute digitally signed patches across open-source supply chains. Microsoft is contributing MDASH, described as a multi-model agentic scanning harness that orchestrates AI agents to discover and verify exploitable bugs. NVIDIA is putting its NOOA agent framework on GitHub, and SpaceXAI says it will open-source its Grok Build terminal coding agent and eventually release Grok model weights. The motivating anecdote in the post is Hugging Face deploying the open-weight GLM 5.2 model on its own infrastructure to analyze over 17,000 actions during a July 2026 intrusion, after closed AI tools 'proved inadequate' by the company's account.
The honest caveat is that this is, at least in part, a policy campaign. Announcements coordinated across this many competitors tend to precede lobbying, and the alliance itself concedes openness has to be paired with 'strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation.' The post does not spell out governance, funding, release cadence, or whether the Linux Foundation is the formal host, so take the specifics as reported, not settled.
What is worth watching regardless of motive is the second-order effect. If SPIFFE, Safetensors, signed patches and open scanning harnesses become the default security substrate for AI agents, vendors sitting outside this coalition end up either adopting the standard or explaining why their closed alternative is worth the premium.
Shared on Bluesky by 2 AI experts
-
blogs.nvidia.com/blog/open-se...
View on Bluesky → -
From a letter to an alliance. "That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control."
View on Bluesky →
Originally reported by blogs.nvidia.com
Read the original article →Original headline: Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security