NVIDIA and ~40 Companies Launch Open Secure AI Alliance Focused on Open Source AI Security Tools

NVIDIA and ~40 Companies Launch Open Secure AI Alliance Focused on Open Source AI Security Tools
NVIDIA, together with approximately 40 companies including Microsoft, IBM, Cisco, and others, has established the Open Secure AI Alliance, aiming to develop and share open models, agent harnesses, and security tools for cybersecurity in the AI era.

NVIDIA, together with approximately 40 companies, has formed the Open Secure AI Alliance, with members including Microsoft, IBM, Cisco, CrowdStrike, Hugging Face, Palantir, Databricks, Dell Technologies, HPE, Red Hat, Salesforce, SAP, and others, aiming to develop and share open models, agent harnesses, and security tools for cybersecurity in the AI era.

Fact Restoration

In July 2026, NVIDIA launched the alliance alongside more than 35 partners, building on the Linux Foundation's Akrites initiative and existing vulnerability remediation efforts within the OpenSSF community. The alliance cited the July 2026 Hugging Face security incident as a case study, where the open-weight GLM 5.2 model helped analyze over 17,000 actions and control intrusions, whereas closed tools failed to distinguish attackers from defenders.

Mechanism Breakdown

The alliance's operations rely on the shared foundation of open source software, focusing on specific contributions such as NVIDIA's open-source NVIDIA Labs Object-Oriented Agents framework, HPE's SPIFFE/SPIRE identity standards, Hugging Face's donated Safetensors format, IBM and Red Hat's Lightwell supply chain signing tool, and Microsoft's MDASH agent security scanner. These tools target vulnerabilities in open models, autonomous agents, and their interactions with data, applications, and infrastructure.

Industry Impact

In terms of competitive landscape, Anthropic and OpenAI are not participating in the alliance, creating a clear divide between open and closed camps. Upstream and downstream developers can gain inspectable and adaptable defense capabilities through open tools, avoiding single-vendor dependency. Enterprise users can build security systems within a multi-vendor ecosystem, reducing the risk of single points of failure, but must manage the potential for misuse of open models on their own.

Comparisons and Precedents

This initiative echoes an open letter published by Jensen Huang on July 24, signed by approximately 25 companies, arguing that open-weight models are critical to US AI leadership. The Linux Foundation and OpenSSF had previously worked in the vulnerability disclosure space, and the alliance extends this effort to AI agent security.

Strategic Assessment

Based on existing participants and technical contributions, the alliance is most likely to release the first integrated tool prototypes in the coming months. Signals for validation include actual deployment cases from member companies and public records of vulnerability remediation. This is an analytical inference based on material facts, not a deterministic prediction.