- Nvidia and industry leaders have launched the Open Secure AI Alliance to build open tools for AI security.
- The alliance was formed to counter AI-enabled threats like the recent July 2026 Hugging Face security issue.
- The alliance could reshape AI security by promoting open models, shared tools, and stronger safeguards.
Nvidia Corp. and industry leaders have launched the Open Secure AI Alliance to develop open technologies that protect artificial intelligence (AI) systems and software from cyber threats. The alliance aims to create community-driven tools for vulnerability remediation, secure model formats, and zero trust AI agent identity frameworks after recent AI security incidents.
Nvidia and Industry Leaders Launch Open Secure AI Alliance
On July 27, 2026, Nvidia and a broad coalition of industry leaders announced the formation of the Open Secure AI Alliance, a new initiative hosted under the Linux Foundation. The alliance builds directly on the Linux Foundation’s existing Akrites initiative and the community efforts of the Open Source Security Foundation (OpenSSF). This collaborative effort unites cloud, cybersecurity, enterprise software, open source, and AI research organizations.
They include Nvidia, Adobe, Cadence, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, NAVER, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, and TrendAI, among others.
Hugging Face Incident Highlights Need for Open AI Security
The recent July 2026 Hugging Face security incident underscored the need for flexible AI-powered cyber defense. During the forensic investigation, several hosted frontier AI models declined to analyze attack artifacts because their cybersecurity guardrails could not distinguish a defender from an attacker. Hugging Face instead ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and support the incident response.
Open source software underpins cloud computing, financial services, manufacturing, telecommunications, government, and internet services by making technology accessible and observable to communities of experts. As AI becomes central to critical infrastructure, the focus has shifted to whether AI defenses should remain inside a few opaque systems or rely on open models, harnesses, and tools that defenders can study, adapt, and deploy. The Hugging Face incident reinforced the case that security teams need access to self-hosted, open AI capabilities when commercial models are constrained by safety guardrails.
What’s Next for the Open Secure AI Alliance?
AI safety depends on the full agent stack, including identity, permissions, harnesses, guardrails, logs, and evaluation. Nvidia is contributing open models, model weights, data and the Nvidia Labs Object Oriented Agent (NOOA) agent harness research framework. HPE will help advance zero trust AI identity through SPIFFE/SPIRE, and Hugging Face will support secure model weights with Safetensors.
IBM and Red Hat’s Lightwell will extend security across the open source supply chain with digitally signed patches, while Microsoft develops MDASH for AI agent vulnerability scanning, and SpaceXAI has open-sourced Grok Build to promote transparent AI development. AI policymakers and regulators should recognize open models, harnesses, and security tooling as defensive assets in AI and cybersecurity policy.
Furthermore, the Open Secure AI Alliance warns that restrictions on open frontier AI systems could weaken defensive capacity and increase dependence on closed providers. The alliance calls for shared AI defense infrastructure, including datasets, evaluation frameworks, attack simulators and red teaming tools, to build more resilient and secure AI systems.
Related: Researchers Warn AI Agents Must Be Treated as Untrusted Systems or Security Will Fail
Disclaimer: The information presented in this article is for informational and educational purposes only. The article does not constitute financial advice or advice of any kind. Coin Edition is not responsible for any losses incurred as a result of the utilization of content, products, or services mentioned. Readers are advised to exercise caution before taking any action related to the company.