Industry leaders including NVIDIA and Microsoft have launched the Open Secure AI Alliance to develop and share open technologies, techniques, and tools aimed at improving trust, safety, and security in the age of AI. The alliance unites companies, foundations, and research groups across cloud computing, cybersecurity, enterprise software, and open-source communities to promote defensive capabilities that are transparent and widely available.
Open source as a defensive pillar
Open-source software is a foundational element of modern infrastructure, supporting cloud computing, financial services, manufacturing, telecommunications, government services, and the internet. Cybersecurity is one of the principal beneficiaries of open source because open systems make technology more visible, adaptable, and easier for expert communities to inspect and improve.
Rationale and recent example
Defenders need open, frontier tools they can inspect, adapt, and run on their own infrastructure rather than relying solely on opaque closed systems. The announcement also highlights a recent Hugging Face security incident in which closed AI tools hindered forensic analysis while an open-weight GLM 5.2 model was run on-site to analyze more than 17,000 actions and help contain the intrusion, illustrating the operational need for open defensive capabilities.
Founding partners and contributions
Founding partners of the Open Secure AI Alliance include a broad cross-section of industry players such as NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI. The alliance plans to build an open defense stack for agents covering identity, isolation, safe model formats, multi-model scanning, and secure coding workflows.
Tools, standards, and research focus
Members of the Open Secure AI Alliance are contributing specific tools and standards to the effort: NVIDIA is donating open models, weights, data, and agent harness research, and has released the NVIDIA Labs Object-Oriented Agent (NOOA) project to make agent harness capabilities more testable and auditable. HPE is contributing SPIFFE/SPIRE for zero-trust identity verification, Hugging Face has offered Safetensors to the PyTorch Foundation as a safer model weight format, IBM and Red Hat’s Lightwell extends supply-chain security with digitally signed patches, Microsoft’s MDASH coordinates multi-model scanning to detect exploitable bugs, and SpaceXAI has open sourced the Grok Build coding agent and plans to open source Grok model weights.
Managing risks and policy guidance
The alliance acknowledges that open models can be misused or modified to remove guardrails, but contends those risks also exist in closed systems and that secrecy does not eliminate determined attackers. The group advocates pairing openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation, and rapid remediation. It also urges policymakers to recognize open models, harnesses, and security tooling as defensive assets rather than liabilities and warns that blanket restrictions on open frontier AI could weaken defensive capacity and concentrate risk in a few closed providers.
Vision for shared security
The alliance argues that real AI safety requires attention to the full agent stack which includes identity, permissions, harnesses, guardrails, logs, and evaluation, rather than focusing solely on whether model weights are open or closed.
Using open, scrutinizable systems and shared infrastructure such as datasets, evaluation frameworks, attack simulators, and red-teaming tools, the Open Secure AI Alliance envisions an AI era marked by resilience, competition, and collective defense.
Frequently Asked Questions (FAQ)
Q: What is the Open Secure AI Alliance?
A: It is a coalition of industry leaders formed to develop and share open technologies, techniques, and tools for AI safety and cybersecurity.
Q: Why do members of the Open Secure AI Alliance promote open models and harnesses?
A: They say open models and harnesses let defenders inspect, adapt, and run tools on their own infrastructure, improving transparency, flexibility, and local control.
Q: What real-world event highlighted the need for open tools?
A: A Hugging Face security incident was cited where running an open-weight GLM 5.2 model on-site helped analyze more than 17,000 actions and contain an intrusion when closed tools were insufficient.
Q: Which kinds of contributions are members of the Open Secure AI Alliance providing?
A: Contributions include open model weights and agent harness research (NVIDIA), zero-trust identity standards (HPE), safe weight formats (Hugging Face), digitally signed supply-chain patches (IBM/Red Hat), multi-model scanning harnesses (Microsoft), and open coding agents and weights (SpaceXAI).
Q: What does the Open Secure AI Alliance ask of policymakers?
A: It urges regulators to treat open AI security tools as defensive assets and to support investment in shared open infrastructure for AI defense.
Emman has been writing technical and feature articles since 2010. Prior to this, he became one of the instructors at Asia Pacific College in 2008, and eventually landed a job as Business Analyst and Technical Writer at Integrated Open Source Solutions for almost 3 years.
