Nvidia and Industry Leaders Form Open Secure AI Alliance to Advance AI Security
Key Takeaways
- •The Open Secure AI Alliance is hosted by the Linux Foundation and builds on Akrites and OpenSSF community work.
- •The group includes participants from cloud computing, cybersecurity, enterprise software, open source development, and AI research.
- •A Hugging Face security incident showed that some hosted frontier models may be limited during defensive cyber investigations by safety guardrails.
- •Member contributions include Nvidia’s open models and NOOA framework, HPE’s SPIFFE/SPIRE identity work, Hugging Face’s Safetensors, and Microsoft’s MDASH scanner.
- •The alliance is urging policymakers to view open AI models, harnesses, and security tooling as defensive assets.

Nvidia Corp. and a coalition of industry leaders have launched the Open Secure AI Alliance, an initiative focused on developing open technologies to protect artificial intelligence systems and software from cyber threats.
The alliance is intended to support community-driven security tools for vulnerability remediation, secure model formats, and zero trust identity frameworks for AI agents. Its formation follows recent AI security incidents, including a July 2026 security issue at Hugging Face that highlighted constraints in some hosted frontier AI models during cyber incident response.
Open Secure AI Alliance Launches Under the Linux Foundation
On July 27, 2026, Nvidia and a broad group of participating organizations announced the formation of the Open Secure AI Alliance. The initiative is hosted under the Linux Foundation and builds on the Linux Foundation’s existing Akrites initiative, as well as community work led by the Open Source Security Foundation (OpenSSF).
The collaboration brings together organizations across cloud computing, cybersecurity, enterprise software, open source development, and AI research. Participants include Nvidia, Adobe, Cadence, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, NAVER, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, and TrendAI, among others.
The alliance aims to develop open tools and shared infrastructure that can help defenders secure AI systems as the technology becomes more deeply embedded in software, enterprise operations, and critical infrastructure. The effort reflects a growing security concern around agentic AI systems, which can connect to tools, data stores, and enterprise workflows, making identity controls, permissions, logging, and vulnerability management part of the AI security stack rather than separate software issues.
Hugging Face Incident Cited as Example of Security Need
The July 2026 Hugging Face security incident was cited as an example of why flexible AI-enabled cyber defense tools may be needed. During the forensic investigation, several hosted frontier AI models declined to analyze attack artifacts because their cybersecurity guardrails could not distinguish between a defender and an attacker.
Hugging Face instead ran the open-weight GLM 5.2 model on its own infrastructure. According to the source account, the model was used to analyze more than 17,000 actions and support the incident response.
The incident underscored a broader issue for AI security teams: whether defensive capabilities should remain concentrated in a small number of closed systems, or whether organizations should also rely on open models, harnesses, and tools that can be inspected, adapted, and deployed by defenders.
Open source software already supports major parts of cloud computing, financial services, manufacturing, telecommunications, government systems, and internet services by making technology accessible and observable to expert communities. As AI becomes more central to critical infrastructure, the alliance argues that security teams need access to self-hosted and open AI capabilities, particularly when commercial models are limited by safety guardrails during defensive investigations.
Alliance Members Outline Technical Contributions
The Open Secure AI Alliance says AI safety depends on the full agent stack, including identity, permissions, harnesses, guardrails, logs, and evaluation systems. Nvidia is contributing open models, model weights, data, and the Nvidia Labs Object Oriented Agent (NOOA) agent harness research framework.
HPE will help advance zero trust AI identity through SPIFFE/SPIRE, while Hugging Face will support secure model weights through Safetensors. IBM and Red Hat’s Lightwell will work to extend security across the open source supply chain using digitally signed patches.
Microsoft is developing MDASH for AI agent vulnerability scanning, and SpaceXAI has open-sourced Grok Build to promote transparent AI development.
The alliance also said AI policymakers and regulators should treat open models, harnesses, and security tooling as defensive assets in AI and cybersecurity policy. It warned that restrictions on open frontier AI systems could weaken defensive capacity and increase reliance on closed providers.
The Open Secure AI Alliance is calling for shared AI defense infrastructure, including datasets, evaluation frameworks, attack simulators, and red teaming tools, to support more resilient and secure AI systems. For security teams evaluating the initiative, the practical test will be whether these contributions become interoperable tools that can be adopted across different model providers, cloud environments, and enterprise AI deployments.