Nvidia and Tech Giants Launch AI Security Alliance
Nvidia and a coalition of tech giants have launched the Open Secure AI Alliance, an initiative focused on developing and sharing open-source tools and techniques to bolster the security of AI systems and agents. The alliance emphasizes that access to open AI models and tools is crucial for collective cyber defense, countering restrictions that could hinder forensic investigations and overall security efforts. The alliance highlights a recent incident involving OpenAI and Hugging Face, where open weights were used to investigate a breach.
Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced the launch of the Open Secure AI Alliance on Monday. The initiative aims to create and distribute open-source tools, models, and techniques to improve the security of AI systems and agents. The alliance is built upon existing work from the Linux Foundation’s Akrites initiative and the OpenSSF community.
Initial partners include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.
Nvidia’s contribution includes a newly released open-source project called NOOA, designed to help users trace, test, and audit agent behavior. HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for cryptographically verifying AI agents and services, while Hugging Face is donating its Safetensors model weight storage format to the PyTorch Foundation. IBM and Red Hat are extending open-source supply chain security through the Lightwell project, which is designed to deliver automated vulnerability remediation at scale. Microsoft is contributing MDASH, a multi-model agentic scanning harness that coordinates AI agents to find, debate, and validate exploitable software bugs. SpaceXAI is open-sourcing its Grok Build terminal-based AI coding agent, with plans to eventually open-source the weights of the Grok model line.
The alliance argues that open models and tools should be treated as defensive assets, not liabilities, and warns policymakers against broad restrictions on open frontier AI, which could weaken collective cyber defense. Nvidia cited a recent incident involving OpenAI and Hugging Face, where closed AI tools failed to differentiate between attackers and defenders, hindering forensic work, and Hugging Face used the open-weight GLM 5.2 model to review over 17,000 actions and contain the breach. “The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation,” Nvidia stated.