CyberSecurity

Nvidia and Tech Giants Launch Open Secure AI Alliance to Arm Defenders

Published

on

A Coalition Takes Shape

On Monday, Nvidia and more than 30 technology, cybersecurity, and enterprise software heavyweights announced the formation of the Open Secure AI Alliance. The goal? Build and share open source tools, models, and techniques for securing AI systems and agents.

The alliance builds on earlier work from the Linux Foundation’s Akrites initiative and the OpenSSF community. It’s a recognition that AI security can’t stay locked inside proprietary labs.

Who’s In

The inaugural partner list reads like a who’s who of tech. Adobe, Cisco, Cloudflare, CrowdStrike, Databricks, Dell, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, Snowflake, and Hugging Face are all in. So are Capital One, Cloudera, Cognition, DoorDash, Elastic, HPE, LangChain, Naver, NetApp, Nous Research, OpenClaw, Palantir, Reflection AI, ServiceNow, Siemens, SK Telecom, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.

That’s a broad tent. Banks, cloud providers, chipmakers, security vendors, and AI startups — all agreeing on one thing: defenders need better tools.

What Each Giant Is Bringing

Nvidia’s contribution includes open models, weights, data, and agent harness research. The company also released a new open source project called NOOA, designed to help harnesses make agent behavior easier to trace, test, and audit.

HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for cryptographically verifying AI agents and services. Hugging Face is donating its Safetensors model weight storage format to the PyTorch Foundation.

IBM and Red Hat are extending open source supply chain security through the Lightwell project, which aims to deliver automated vulnerability remediation at scale. Microsoft is contributing MDASH, a multi-model agentic scanning harness that coordinates AI agents to find, debate, and validate exploitable software bugs. SpaceXAI is open-sourcing its Grok Build terminal-based AI coding agent, with plans to eventually open-source the weights of the Grok model line.

Why Openness Matters Now

The alliance’s core argument: open models, harnesses, and security tooling should be treated as defensive assets, not liabilities. The group warns policymakers and regulators that broad restrictions on open frontier AI could weaken collective cyber defense capacity.

Nvidia points to a recent security incident involving OpenAI and Hugging Face. When closed AI tools couldn’t differentiate between attackers and defenders and blocked forensic work, Hugging Face used the open-weight GLM 5.2 model on its own systems to review over 17,000 actions and contain the breach.

“The right response is not to deny defenders access to capable open systems,” Nvidia said. “It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.”

“Defenders need both frontier closed models and frontier open models, working together,” the company added, “so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.”

What This Means for Security Teams

For practitioners, the alliance could mean more options when it comes to AI security testing. Open harnesses like NOOA and MDASH give teams the ability to probe their own AI systems without waiting for a vendor’s patch cycle.

The zero-trust identity work from HPE on SPIFFE/SPIRE also matters. As AI agents become more autonomous, verifying who — or what — is making decisions becomes critical. Cryptographic identity for agents isn’t a nice-to-have anymore.

The supply chain angle is worth watching too. Lightwell’s automated vulnerability remediation could help close the gap between discovery and patching, a problem that’s only getting worse as AI-generated code accelerates development cycles.

The Bigger Picture

This launch lands amid a broader push on AI security. The White House recently launched an AI-driven vulnerability coordination initiative called ‘Gold Eagle.’ Meanwhile, researchers keep finding flaws in AI systems — from ChatGPT agent vulnerabilities to nuclear-sabotage malware benchmarks that trip up frontier models.

The AI security alliance is a bet that openness will win. It’s also a direct challenge to the idea that keeping powerful AI models locked away makes the world safer. The alliance’s answer: locked models leave defenders blind.

Whether that argument sways regulators remains to be seen. But for now, the tools are coming. Open source, auditable, and ready for defenders to use.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version