Back to feed
News Story
NVIDIA AI Blog
1 sources

Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

Industry leaders have launched the Open Secure AI Alliance, building on the Linux Foundation's Akrites initiative and OpenSSF community work, to address AI safety and security through open source tools. The alliance aims to democratize defensive capabilities, increase transparency, and enable community-driven cyber defense, emphasizing the need for open models alongside closed ones. The initiative was motivated by incidents like the Hugging Face security breach, where open-weight models proved essential for forensic analysis.

SynthePulse Insight · AI deep reading

Open Secure AI Alliance Launches: Defenders Need Open 'Frontier Tools'

Version 1 · 1 source

The Linux Foundation, NVIDIA, and dozens of industry leaders jointly launch the Open Secure AI Alliance, aiming to empower defenders with open-source models, tools, and frameworks for AI security, avoiding reliance on a few closed systems.

  • The Open Secure AI Alliance, initiated by the Linux Foundation, OpenSSF, NVIDIA, and dozens of organizations, is dedicated to developing shared open-source AI security tools.
  • In the Hugging Face security incident, closed AI tools hindered forensic analysis, while the open-source GLM 5.2 model successfully analyzed over 17,000 action records and contained the intrusion.
  • The alliance emphasizes that open models are critical for cyber defense, avoiding single points of failure and allowing defenders to inspect, adapt, and deploy AI systems.
  • NVIDIA contributed the NOOA research framework to enhance testability, traceability, and auditability of AI agents.
  • Multiple members contributed specific technologies: HPE's zero-trust identity framework, Hugging Face's SafeTensors format, IBM's signed patches, Microsoft's multi-model scanning tool, etc.
  • The alliance calls on policymakers to view open models as defense assets, not risks, and avoid blanket restrictions on open frontier AI systems.
Open section navigationBackground and Mission of the Alliance

Background and Mission of the Alliance

On July 27, 2026, NVIDIA, together with the Linux Foundation, OpenSSF, and dozens of industry leaders, announced the formation of the Open Secure AI Alliance. The alliance aims to build and share open-source tools to promote responsible use and trust in AI. It believes that open-source software is a key pillar of the global economy, and cybersecurity is one of its greatest beneficiaries.

The alliance's mission is to ensure defenders have trusted and controllable open frontier tools. Its core argument is that in AI security, open models and tools are essential for democratizing defense capabilities, increasing transparency, protecting data, and avoiding single points of failure.

Key Event: Hugging Face Security Incident

The alliance's formation is partly driven by lessons from the recent Hugging Face security incident. In that incident, closed AI tools could not distinguish between attackers and defenders, hindering necessary forensic analysis. Ultimately, Hugging Face ran the open-source GLM 5.2 model on its own infrastructure, analyzing over 17,000 action records and successfully containing the intrusion.

This incident shows that when defenders cannot inspect, adapt, and run advanced AI on their own infrastructure, their response capabilities are limited at the moment when speed is most needed. Therefore, companies and countries need open frontier defense tools and technologies so that critical industries can build secure systems across multi-vendor ecosystems.

Balancing Open and Closed Systems

The alliance acknowledges that open models can be misused (e.g., to weaken security measures or for cyberattacks), but argues that these risks are not unique to open systems and exist in closed systems as well. The correct response is not to deny defenders access to open systems, but to combine openness with strong security measures, clear abuse rules, rigorous evaluation, and rapid fixes.

The alliance advocates that the world needs both closed and open models to work together, so defenders can choose the right system for the task and ensure transparency, adaptability, and sovereign control when security demands it.

Member Contributions and Technology Stack

NVIDIA contributed the new open-source NVIDIA Labs Object-Oriented Agent (NOOA) research framework, designed to make AI agent behavior easier to test, trace, audit, and govern. The framework is now available on GitHub.

Other member contributions include: HPE's SPIFFE/SPIRE zero-trust identity framework for cryptographically verifying AI agents and services; Hugging Face's SafeTensors secure tensor format providing transparency and no remote code execution guarantees; IBM and Red Hat's Lightwell extending open-source supply chain security with digitally signed patches; Microsoft's MDASH multi-model agent scanning tool coordinating specialized AI agents to discover and prove exploitable vulnerabilities; SpaceXAI open-sourcing the Grok Build terminal AI coding agent and planning to open-source Grok model weights.

Call to Policymakers

The alliance calls on policymakers and regulators to view open models, tools, and security tools as defense assets, not liabilities. Blanket restrictions on open frontier AI systems would weaken defense capabilities and could lead to power, dependency, and vulnerability concentrated in a few closed providers.

The alliance recommends that companies and governments invest in shared open AI defense infrastructure, including datasets, evaluation frameworks, attack simulators, and red-teaming tools, similar to past investments in open-source software.

Future Vision

The alliance believes that the era of AI agents can be an era of resilience and shared security. With the right choices, open secure AI systems can provide defenders with the tools they need, enhance competition, extend technological leadership, and ensure AI security is built in an open environment.

The alliance invites governments, industry, and researchers to join in building AI systems that can withstand scrutiny, be flexibly improved, and are open enough to mobilize the entire defender community.

Credibility boundary

This article's information primarily comes from a press release published on NVIDIA's official blog, a primary source. Details of the Hugging Face security incident (e.g., GLM 5.2 model analyzing 17,000 action records) are statements from the source and have not been independently verified by third parties. Technical details of other member contributions are also based on the press release statements.

Insight takeaway

The formation of the Open Secure AI Alliance marks a clear industry choice for the path of AI security defense: empowering defenders through open-source collaboration rather than relying on closed systems. The Hugging Face incident provides an empirical case, but risk management for open models still requires ongoing attention.

Primary report

NVIDIA AI Blog

Primary source