NVIDIA, Microsoft, SpacexAI, and others have established the 'Open Secure AI Alliance,' an industry group aimed at improving the safety and cybersecurity of AI. Anthropic, OpenAI, and Google are not participating.

Approximately 40 companies and organizations, including NVIDIA, Microsoft, Hugging Face, SpacexAI, and Adobe, have established the ' Open Secure AI Alliance ,' an industry group aimed at enhancing the safety and cybersecurity of AI. The participating companies plan to jointly develop and share open models, technologies, methods, and security tools to protect AI agents and software from attacks.
Industry leaders form Open Secure AI Alliance to improve AI safety and security - NVIDIA | Japan Blog
The Open Secure AI Alliance was established with the participation of NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab, and TrendAI. These companies and organizations will jointly develop and share open technologies, methodologies, and security tools to protect software and agents in the AI era.

NVIDIA CEO Jensen Huang stated, 'Attackers have the most advanced AI at their disposal. Defenses need the most advanced AI ecosystem—that is, the best models from both open and closed systems, amplified many times over by the power of a global community. In the Hugging Face case, closed AI hindered essential forensic analysis, while open, state-of-the-art models helped contain the intrusion. That's why we founded the Open Secure AI Alliance.'
Attackers have frontier AI. Defenders need a frontier AI ecosystem—the best open and closed models, force-multiplied by a global community.
— Jensen Huang (@JensenHuang) July 27, 2026
During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion.… https://t.co/lCZWt9nPBQ
The Open Secure AI Alliance was established in response to concerns that AI agents would become capable of autonomously operating computers, making it impossible to adequately monitor and control their behavior with traditional security measures alone. In particular, the incident in which an OpenAI AI agent reportedly lost control and infiltrated the Hugging Face system highlighted the need to strengthen defenses against AI-based attacks.
OpenAI reports accidentally hacking Hugging Face with its new AI system - GIGAZINE

According to NVIDIA, in this incident, some closed AI tools were unable to distinguish between attackers and defenders, preventing them from performing the necessary forensic analysis. Instead, Hugging Face ran the open-weight model ' GLM-5.2 ,' developed by China's Z.ai, on its own infrastructure, analyzing more than 17,000 operations to contain the intrusion.
NVIDIA acknowledges that open models are at risk of being modified to remove safety mechanisms or exploited for cyberattacks. However, they argue that closed systems with undisclosed model weights still pose a risk of exploitation, and that the bigger problem is that defenders would be unable to verify, improve, and operate high-performance AI.
Furthermore, the security of an AI agent is not determined solely by the underlying language model. NVIDIA explains that it is necessary to verify and improve the entire agent mechanism, including user and agent IDs, access rights, the harness that runs the model, guardrails, operation logs, and evaluation systems.
NVIDIA states that as part of its contribution to the alliance, it will provide open models, model weights, data, and agent harness research. In addition, it has released 'NVIDIA Labs Object-Oriented Agents,' or 'NLOOA,' on GitHub, an open-source research framework that makes it easier to test, track, audit, and manage the behavior of AI agents.
GitHub - NVIDIA-NeMo/labs-OO-Agents: labs-OO-agents · GitHub

Each participating company is offering its own security technology. HPE is working on ' SPIFFE/SPIRE ,' which cryptographically verifies the identity of AI agents, and Hugging Face is working on ' Safetensors ,' which securely stores model weights. IBM and Red Hat are offering ' Lightwell ,' which handles digitally signed patches, and Microsoft is offering ' MDASH ,' which combines multiple AI agents to find vulnerabilities.
The Open Secure AI Alliance warns that 'uniformly regulating cutting-edge open AI weakens the ability to defend and concentrates power, dependence, and vulnerability in a few closed AI companies.' They are calling on companies and governments to invest in shared infrastructure that can be used for AI defense, such as security datasets, evaluation frameworks, attack simulators, and red teaming tools.
The Open Secure AI Alliance aims to address the emerging threats associated with the proliferation of AI agents by providing defenders with powerful and controllable AI tools, rather than limiting the capabilities of AI. NVIDIA stated that secrecy alone cannot guarantee the security of AI systems, and that an open environment is needed where many researchers and defenders can examine the mechanisms and fix problems.
On the other hand, Anthropic, OpenAI, and Google, which provide major AI models, are not members of the Open Secure AI Alliance. In particular, Anthropic did not participate in the joint statement issued on July 24, 2026, opposing excessive regulation of open weight models. However, Anthropic CEO Dario Amodi argued in his company's blog that 'Anthropic opposes a blanket ban on open weight models, and models that do not have dangerous capabilities are a public good that benefits companies, developers, and researchers.'
Our position on open-weights models | Anthropic
https://www.anthropic.com/news/position-open-weights-models

On the other hand, CEO Amodi pointed out that 'high-performance open weight models can be used in private environments with security measures removed, and once released, they cannot be retrieved, so they may be at a higher risk of being misused for cyberattacks or biological weapons development than closed models.' He argued that 'all sufficiently high-performance models, whether open or closed, should be required to undergo security testing before being released.' Furthermore, he disagreed with claims from NVIDIA and others that 'openness will surely work to the advantage of the defenders,' stating that it should not be decided in advance whether the attackers or defenders will benefit, but rather determined through rigorous verification.
Related Posts:
in AI, Posted by log1i_yk







