What the Open Secure AI Alliance Actually Does

Nvidia and more than 30 other companies have banded together to form the Open Secure AI Alliance, a coalition built around one core idea: open-source AI tools make for stronger cyber defense than locked-down, proprietary ones. The group's stated mission is to develop and share open technologies that harden AI safety and security practices across the industry, rather than leaving that work siloed inside individual companies.

Building on Existing Open-Source Groundwork

The alliance isn't starting from zero. It grows out of work already underway through the Linux Foundation's Akrites initiative and the OpenSSF community, giving it a foundation of established open-source security practices to build on rather than reinventing processes from scratch.

Who's Involved and Why the Roster Matters

A Cross-Industry Founding Lineup

The list of inaugural partners spans nearly every corner of enterprise tech: Adobe, Cisco, CrowdStrike, Cloudflare, Dell Technologies, Elastic, HPE, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake, SK Telecom, and Synopsys are all founding members, among others. That breadth — cloud providers sitting alongside cybersecurity firms, enterprise software makers, and AI research labs — signals this isn't a narrow technical experiment. It's an attempt to get the biggest names in tech rowing in the same direction on AI security.

The Case for Openness Over Lock-In

Nvidia's own framing of the alliance argues that open models and tools do something closed systems can't: they spread defensive capability more widely and give defenders more visibility into how the tools protecting them actually work. Rather than depending on a single vendor's black box, security teams get systems they can inspect and adapt themselves, with no single point of failure controlling the outcome for everyone.

The Incident That Made the Case for the Alliance

When a Closed Tool Couldn't Tell Friend From Foe

The push behind this alliance isn't purely theoretical. Nvidia pointed to a recent security breach at Hugging Face as a real-world example of where closed AI tools fall short. During that incident, the closed systems in use couldn't tell attackers apart from the defenders trying to stop them, which got in the way of forensic investigation. Hugging Face's workaround was to bring in an open-weight model on its own infrastructure, using it to sift through more than 17,000 logged actions and ultimately contain the intrusion.

Nvidia's point in citing the incident is straightforward: when security teams can't examine, adjust, and run advanced AI tools on infrastructure they control, their ability to respond gets boxed in right at the moment when speed is everything.

Why the Harness Around the Model Matters as Much as the Model Itself

CrowdStrike, explaining its decision to join, added a data point that reinforces the same argument from a different angle. The company found that running the same frontier AI model through different "harnesses" — the surrounding tooling and configuration that shapes how a model gets applied — produced dramatically different results in vulnerability research. A generic, off-the-shelf setup returned false positives close to 80 percent of the time. Swap in a harness purpose-built for security work, and that false-positive rate dropped to around 20 percent. The model didn't change; the tooling wrapped around it did, and that alone reshaped the outcome.

What the Alliance Is Actually Building

Nvidia's Contribution: NOOA

Nvidia is putting its own open-source research framework into the alliance's toolkit: NOOA, short for NVIDIA Labs Object-Oriented Agent, now live on GitHub. The idea behind NOOA is to make AI agent behavior easier to test, trace, audit, and govern, giving teams a clearer window into what an autonomous agent is actually doing rather than treating it as an opaque process.

Zero-Trust Identity and Signed Patches

Other founding members are bringing their own pieces to the table. HPE is contributing work on SPIFFE and SPIRE, open standards for zero-trust identity verification. IBM and Red Hat are behind Lightwell, a project focused on digitally signed patches. Microsoft is adding MDASH, a multi-model scanning harness. Each piece targets a different layer of the security stack, but all of them are aimed at the same goal: making AI systems easier to verify and harder to quietly compromise.

The Bigger Policy Fight Behind the Launch

Jensen Huang's Open Letter and the Push Against New Restrictions

The alliance didn't launch in isolation. It follows shortly after Nvidia CEO Jensen Huang shared a separate open letter, "Open Weights and American AI Leadership," signed by 25 companies including Microsoft, Meta, and Palantir. That letter urged policymakers to hold off on premature restrictions targeting open-weight AI models.

The Open Secure AI Alliance picks up that same thread and points it specifically at cybersecurity policy. Its warning: broad restrictions on open frontier AI systems wouldn't just slow innovation — they'd weaken collective defensive capacity and risk concentrating power, dependence, and vulnerability into the hands of a small number of closed providers. The companies behind this alliance are essentially arguing that keeping AI security tools open isn't a nice-to-have. It's a safeguard against putting too much of the internet's defense in too few hands.