NVIDIA and 36 partners form Open Secure AI Alliance for cyber defense
NVIDIA is among 37 organizations named as founding partners of the Open Secure AI Alliance
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance, a group that plans to develop and share open technologies for protecting software and AI agents against cyber threats.
The alliance brings together companies working across AI research, cloud computing, cybersecurity, enterprise software and open source development. Its founding partners include Adobe, Cisco, Cloudflare, CrowdStrike, Databricks, Hugging Face, IBM, the Linux Foundation, Microsoft, Palantir, Red Hat, Salesforce, SAP, ServiceNow, Siemens and Snowflake.
NVIDIA says the initiative will build on the Linux Foundation’s Akrites project and work by the Open Source Security Foundation, known as OpenSSF. Its stated objective is to give defenders security systems they can inspect, adapt and operate on their own infrastructure, alongside closed AI products.
The central argument is not that open models are automatically safer. NVIDIA acknowledges that they can be adapted for cyberattacks or modified to remove safeguards. Instead, it positions access to both open and closed frontier models as necessary for security teams to select and control the tools used in different situations.
“The world needs both closed and open models,” NVIDIA states. It argues that open models and agent harnesses can support transparency, local controls and cyber defense without requiring organizations to send sensitive data to an external provider.
Hugging Face incident shapes the case for open access
NVIDIA uses a recent security incident at Hugging Face to demonstrate the practical limitation it sees in relying exclusively on closed AI systems.
According to the company, closed AI tools blocked forensic work because they could not distinguish the actions of attackers from those of security professionals investigating the intrusion. Hugging Face then ran the open-weight GLM 5.2 model on its own infrastructure, where it analyzed more than 17,000 actions and helped contain the incident.
NVIDIA Founder and CEO Jensen Huang made the same case on LinkedIn. “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion,” he wrote.
The alliance argues that organizations and governments need access to frontier defensive systems that can operate across multiple vendors. In its view, concentrating cyber defenses within a small number of closed providers could create dependencies and single points of failure.
That remains the position of NVIDIA and the alliance rather than an established conclusion about the relative security of open and closed models.
Partners contribute components for an open defense stack
The alliance’s work will extend beyond model weights. NVIDIA describes an AI agent as a wider system incorporating models, identity controls, permissions, harnesses, guardrails, logs and evaluation tools.
NVIDIA is contributing open models, model weights, data and research into agent harnesses. Its new NVIDIA Labs Object-Oriented Agent project, known as NOOA, is an open source research framework designed to make AI agent behavior easier to test, trace, audit and govern.
Other founding partners are working on components covering identity, model storage, software supply chains, vulnerability scanning and coding agents.
HPE contributes to SPIFFE and SPIRE, which develop zero-trust identity standards intended to verify AI agents, services and authorized workloads. Hugging Face has offered Safetensors, its format for storing AI model weights without remote code execution, to the PyTorch Foundation.
IBM and Red Hat’s Lightwell applies digitally signed patches across the open source software supply chain. Microsoft’s MDASH harness coordinates multiple specialized AI agents to identify, assess and demonstrate exploitable software vulnerabilities.
These examples indicate that the alliance is intended to connect existing projects as well as produce new research. However, NVIDIA has not specified what every founding organization will contribute, how joint projects will be governed or which licenses will apply to future releases.
The complete group named in the announcement consists of NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, Synopsys, Thinking Machines Lab and TrendAI.
Alliance calls for open AI security infrastructure
Alongside its technical work, the alliance is making a policy case against blanket restrictions on open frontier AI. It argues that policymakers should treat open models, harnesses and security tools as defensive infrastructure rather than viewing openness itself as a security liability. NVIDIA calls on companies and governments to invest in shared datasets, evaluation frameworks, attack simulators and red-teaming tools.
The announcement accepts that access to powerful open models creates misuse risks, including attempts to remove protections or repurpose systems for attacks. Its proposed response combines open access with safeguards, evaluations, rules against malicious use and rapid vulnerability remediation.