NVIDIA and a broad group of technology companies and open-source organizations have announced the formation of the Open Secure AI Alliance, with the goal of developing and sharing open technologies and tools that help defenders protect software and intelligent agents as the use of artificial intelligence expands. The alliance builds on Linux Foundation community initiatives, including the Akrites initiative and OpenSSF’s work, with a focus on addressing and disclosing vulnerabilities using open technologies.
The alliance includes founding partners from the cloud computing, cybersecurity, enterprise software and AI research sectors, including NVIDIA, Adobe, Akamai, Amazon, Atlassian, Cisco, Cloudflare, CrowdStrike, Dell Technologies, Docker, GitHub and Google?
Openness as a Defensive Tool
The alliance believes that cyber defense requires open models and open operational tools because they allow defenders to inspect and adapt systems and run them on their own infrastructure, while protecting data and reducing dependence on a single provider. According to the article, these tools can complement advanced closed models by providing customizable controls suited to local environments.
NVIDIA acknowledges that open models, like any powerful technology, may be misused by weakening safeguards or repurposing them for cyberattacks. However, the article argues that these risks are not limited to open systems, and that keeping model weights closed does not prevent determined attackers from attempting to access or exploit advanced capabilities.
The article cites a recent security incident affecting Hugging Face, saying that the company used the open-weight GLM 5.2 model on its infrastructure to analyze more than 17,000 actions and contain the breach, after closed AI tools hindered forensic analysis because they could not distinguish between attackers and defenders. NVIDIA uses this incident to illustrate the importance of giving defenders access to advanced systems that can be inspected, modified and operated internally.
NVIDIA’s Contributions and Security Components
NVIDIA said it is contributing open models, model weights, data and new research on agent runtime frameworks to the alliance. It has also made the NVIDIA Labs Object-Oriented Agent (NOOA) project open source on GitHub. This research framework aims to help agent runtime frameworks integrate more effectively with models, making agent behavior easier to test, trace, audit and govern.
Participants are working to build an open defense ecosystem for agents that includes identity and isolation, secure model formats, multi-model scanning and secure coding workflows. Examples cited in the article include HPE’s contribution to SPIFFE/SPIRE for cryptographic verification of agent and service identities, and Hugging Face making the Safetensors format available to the PyTorch Foundation. The format stores model weights with safeguards against remote code execution.
A Call for Shared Infrastructure
NVIDIA called on governments, companies and researchers to invest in open infrastructure for AI-based defense, such as datasets, evaluation frameworks, attack simulators and offensive testing tools. It also urged policymakers and regulators to treat open models, runtime frameworks and security tools as defensive assets, warning that sweeping restrictions on open AI systems could weaken defensive capabilities and increase dependence on a limited number of closed providers.