NVIDIA and more than 30 companies spanning cloud computing, cybersecurity, enterprise software and AI research launched the Open Secure AI Alliance on July 27, 2026. The group will develop and share open technologies, techniques and tools to help defenders secure software and AI agents. The move follows a high-profile Hugging Face security incident that showed why defenders need open, inspectable AI systems they can run on their own infrastructure.
Founding members include Adobe, Capital One, Cisco, CrowdStrike, Databricks, Dell Technologies, Hugging Face, IBM, the Linux Foundation, Microsoft, Palantir, Palo Alto Networks, Red Hat, SAP, ServiceNow, Snowflake, SpaceXAI and others. The alliance builds on existing work by the Linux Foundation's Akrites initiative and the OpenSSF community to remediate and disclose vulnerabilities using open technologies.
Why open models matter for cyber defense
When a security incident hit Hugging Face, closed AI tools blocked essential forensic analysis because they could not distinguish attackers from defenders. The company ran the open-weight GLM 5.2 model on its own infrastructure, analyzed more than 17,000 actions and contained the intrusion. "When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most," the alliance said.
Open models and open harnesses give defenders the ability to test, verify and strengthen the systems they rely on. They also avoid single points of failure and allow organizations to customize controls for local requirements. The alliance argues that both closed and open frontier models are needed, but in cybersecurity, openness is essential for transparency and distributed defense.
New tools and research contributions
NVIDIA is contributing open models, model weights, data and a new agent harness research project called NOOA (NVIDIA Labs Object-Oriented Agent). Available on GitHub, NOOA helps harnesses integrate with models so agent behavior is easier to test, trace, audit and govern. Other members are building components of an open defense stack: HPE contributes to SPIFFE/SPIRE for zero-trust identity frameworks that cryptographically verify AI agents; Hugging Face offered Safetensors, a safe model format with no remote code execution, to the PyTorch Foundation; IBM and Red Hat's Lightwell secures the open source supply chain with digitally signed patches; Microsoft's MDASH orchestrates specialized AI agents to find and prove exploitable bugs; and SpaceXAI open-sourced the Grok Build coding agent and plans to release Grok model weights.
A call to policymakers
The alliance warns that blanket restrictions on open frontier AI systems would weaken defensive capacity and concentrate risk in a few closed providers. Instead, it urges governments to treat open models, harnesses and security tooling as defensive assets. For professionals in government and public-sector IT, understanding the role of open AI in national resilience is becoming a core competency-AI for Government training resources can help teams evaluate and adopt these technologies responsibly. The group also calls for investment in shared open infrastructure: datasets, evaluation frameworks, attack simulators and red-teaming tools.
Why this matters for IT, development and government professionals
The alliance reshapes the AI security conversation by putting open, inspectable tools into the hands of defenders rather than restricting them. For cybersecurity teams and developers, this means new open frameworks and models will soon be available to build custom defenses without vendor lock-in. The NOOA harness, Safetensors format and multi-model scanning tools directly affect how agents are secured in enterprise environments. Building skills in these open defensive systems will be critical-AI Learning Path for Cybersecurity Analysts offers a structured way to get started. Policymakers and public-sector IT leaders should track the alliance's output closely, as it will influence procurement, compliance and national security guidance for AI systems.
Your membership also unlocks: