New Delhi: Open source is getting a security upgrade. Chip giant NVIDIA has unveiled the Open Secure AI Alliance, bringing together some of the world’s biggest technology companies to develop open tools and frameworks aimed at making artificial intelligence safer, more transparent and more resilient against cyber threats.
The alliance, announced on 27 July, builds on the work of the Linux Foundation and the OpenSSF. It seeks to create an open ecosystem for AI security by developing technologies that enable organisations to inspect, test and strengthen AI systems rather than relying solely on proprietary platforms.
More than 40 organisations have joined as founding members, including Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Dell Technologies, Hewlett Packard Enterprise, Hugging Face, Adobe, Databricks, Palantir Technologies, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Snowflake and Capital One.
The coalition argues that while both open and closed AI models have a role to play, open technologies are particularly important for cybersecurity because they allow defenders to examine systems, customise safeguards and deploy protections without depending on a single vendor.
NVIDIA said the initiative was prompted in part by a recent cyberattack on Hugging Face, where open AI models reportedly enabled engineers to analyse more than 17,000 actions and investigate the breach after access to some closed AI tools proved limited. According to the company, the incident highlighted the need for organisations to run advanced AI security tools on their own infrastructure during cyber emergencies.
Rather than focusing solely on AI models, the alliance plans to secure the entire AI agent stack, including identity management, permissions, guardrails, logging, evaluation and governance. Members argue that AI safety depends as much on these surrounding systems as on the models themselves.
As part of its contribution, NVIDIA has open sourced its new NVIDIA Labs Object-Oriented Agent (NOOA) framework on GitHub. The research project is designed to improve the transparency, traceability and governance of AI agents by making their behaviour easier to audit and evaluate.
Other alliance members are contributing complementary technologies. HPE is advancing zero-trust identity standards through SPIFFE and SPIRE, Hugging Face has contributed its Safetensors model format to improve AI model security, IBM and Red Hat are extending digitally signed software patches across the open source supply chain, while Microsoft is contributing its MDASH multi-model AI scanning framework to help identify exploitable software vulnerabilities.
The alliance also welcomed efforts by SpaceXAI to open source its Grok Build AI coding agent and plans to release the weights of future Grok models to support developers and researchers.
Beyond technical development, the alliance is calling on governments and regulators to recognise open AI systems as critical defensive infrastructure rather than security risks. It argues that blanket restrictions on open frontier AI models could reduce cybersecurity resilience by concentrating AI capabilities among a handful of proprietary providers.
Instead, the group is urging policymakers to support shared AI defence infrastructure, including open datasets, evaluation frameworks, red-teaming tools and attack simulators, mirroring the collaborative approach that helped establish open source software as the backbone of today’s digital economy.
With AI rapidly becoming embedded across governments, businesses and critical infrastructure, the Open Secure AI Alliance aims to ensure that the next generation of AI security is built collaboratively, giving defenders around the world access to transparent, adaptable and trustworthy tools to protect increasingly complex digital systems.