NVIDIA assembles 37 companies behind open AI security as OpenAI, Anthropic and Google stay out
NVIDIA and 36 other organisations launched the Open Secure AI Alliance on Monday, a coalition committed to developing and sharing open technologies, techniques, and tools to secure software and AI agents. Its stated scope covers the full agent stack, including identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows. Jensen Huang, Founder and Chief Executive Officer of NVIDIA, set out the reasoning in a post published to both LinkedIn and X. “Attackers have frontier AI. Defenders need a frontier AI ecosystem, the best open and closed models, force-multiplied by a global community,” Huang said. NVIDIA shares rose roughly 1% in pre-market trading on Monday.
The inaugural partner list spans cloud, cybersecurity, enterprise software and AI research. Alongside NVIDIA, it includes Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Red Hat, Palantir, Databricks, Snowflake, Salesforce, SAP, ServiceNow, Siemens, HPE, Dell Technologies, Adobe, Capital One, Cadence, Cloudera, Cognition, DoorDash, Elastic, Hugging Face, LangChain, NAVER, NetApp, Nous Research, OpenClaw, Reflection AI, SK Telecom, SpaceXAI, Synopsys, Thinking Machines Lab, TrendAI and the Linux Foundation. OpenAI, Anthropic and Google are absent from the roster.
Meta endorsed the policy and has not joined the coalition
The alliance follows a three-page policy letter published on 24 July, titled Open Weights and American AI Leadership, which 25 companies signed in opposition to premature restrictions on open-weight models. Huang joined X last month and used his first post to share it, stating that open models “strengthen safety and cybersecurity, accelerate innovation and diffusion, and enable sovereignty.” Satya Nadella, Chairman and Chief Executive Officer of Microsoft, amplified the same message that day. OpenAI, Anthropic and Google declined to sign, and as Tom’s Hardware observed, none of the 25 signatories sells access to a closed frontier model. Sam Altman, Chief Executive Officer of OpenAI, said publicly that he was glad to see the support and wanted the United States to win with open-weight and proprietary models alike.
Three days later, the coalition that formed around that position looks materially different from the group that signed the letter. Meta, the largest publisher of open weights in the industry, signed the letter and does not appear among the alliance’s inaugural partners. Mistral, Mozilla, Andreessen Horowitz, Y Combinator, Perplexity and Replit are similarly absent. Cisco, Cloudflare, Red Hat, Snowflake, Siemens, SAP, SpacexAI and Thinking Machines Lab have joined the alliance without having signed the letter. Endorsing a policy position and committing engineering resources to a shared codebase are separate decisions, and the public materials do not say whether membership discussions with the missing names are under way or what a member is required to contribute.
A July breach supplied the case behind the coalition
Hugging Face disclosed on 16 July that an AI agent had broken into its systems and stolen an access key that was then used to reach deeper into its network. OpenAI subsequently confirmed that two of its experimental models had escaped a restricted testing environment and reached Hugging Face’s production infrastructure while attempting to cheat on a cybersecurity benchmark, characterising the episode as an unprecedented cyber incident. Closed AI tools proved unable to distinguish attackers from defenders during the response and blocked essential forensic analysis, according to NVIDIA’s account, after which Hugging Face ran the open-weight GLM 5.2 model from Chinese developer Z.ai on its own infrastructure to analyse more than 17,000 actions and contain the intrusion.
NVIDIA has built the announcement on that sequence of events, citing it as the reason the alliance exists at all. “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion. That’s why we created the Open Secure AI Alliance,” Huang said. The company made the same case in its own text, stating that cyber defenders need open, frontier agentic systems for self-defence, and that when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at precisely the moment speed matters most. Clem Delangue, Co-founder and Chief Executive Officer of Hugging Face, said in a statement published by OpenAI that AI safety “will be solved in the open, collaboratively, with broad access to AI for every defender, everywhere.” A breach caused by one company’s closed models was contained using another company’s open weights, and the vendor selling the compute underneath all of it has now organised 36 partners around the lesson.
The stated aim reaches beyond tooling into regulation
The alliance has set itself the task of remediating and disclosing vulnerabilities using open technologies, building on the Linux Foundation’s Akrites initiative and the work of the Open Source Security Foundation. NVIDIA described the objective as ensuring that defenders everywhere have open, frontier tools they can trust and control, and argued that the choice facing the United States and its partners is whether the defences protecting critical infrastructure sit inside a few opaque systems or rest on models, harnesses and tools that any defender can study, adapt and deploy. Real security depends on the full agent stack, the company said, and the single question of whether model weights are published settles very little on its own.
A section of the announcement addresses regulators directly, calling for open models, harnesses and security tooling to be recognised as defensive assets in AI and cybersecurity policy. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers, NVIDIA said. It also called on companies and governments to invest in shared open infrastructure for AI defence, including datasets, evaluation frameworks, attack simulators and red-teaming tools. NVIDIA published that call while two regulatory arguments were already running. Policymakers have responded to the Hugging Face incident with calls for an AI kill switch that would allow the Department of Homeland Security to order the throttling or shutdown of advanced models, and the letter three days before the launch surfaced amid a wider dispute in Washington over Chinese open-weight models. NVIDIA acknowledged the risks in its own text, stating that open models can be misused through attempts to weaken safeguards or repurpose capabilities, and that openness has to be paired with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. “The world needs both closed and open models,” the company said.
The mechanics amount to one new release and a pool of existing projects
NVIDIA is contributing open models, model weights, data and agent harness research, including the NVIDIA Labs Object-Oriented Agent project, released on GitHub under an Apache 2.0 licence. NOOA represents the harness, the software layer that renders context, executes actions and manages state around a model, as a Python class, so that fields store state, methods expose capabilities, docstrings act as prompts and type annotations define the contracts the model must follow. The practical effect is that non-deterministic agent behaviour becomes testable and version-controllable using ordinary software engineering workflows.
Everything else on the table already existed. HPE is contributing to SPIFFE/SPIRE, the zero-trust identity standard used to cryptographically verify that only authorised workloads communicate with enterprise resources. Hugging Face has offered its Safetensors weight storage format to the PyTorch Foundation. IBM and Red Hat are extending Lightwell, which distributes digitally signed patches across the open source supply chain. Microsoft is contributing MDASH, its multi-model agentic scanning harness that orchestrates specialised agents to discover, debate and prove exploitable bugs. SpacexAI has open sourced its Grok Build terminal coding agent and stated that it plans to open the weights of the Grok model line. CrowdStrike said it is developing techniques that use open models to detect attacks against AI systems and agents, while Elastic said it will contribute research, tools and architectural knowledge across security, search, observability and AI-powered detection. Jim Zemlin, Chief Executive Officer of the Linux Foundation, said that “open source became the backbone of modern computing because it let everyone see, improve, and secure the technology they rely on”, adding that AI deserves the same foundation.
What enterprise security teams should watch
The Linux Foundation has positioned itself as the neutral ground on which competing organisations can collaborate, and it praised NVIDIA for contributing working code to the effort. It stopped short of stating that the alliance is formally hosted or governed as a Linux Foundation project, which leaves the question of stewardship open. Governance structures, published workstreams, named maintainers and jointly owned release processes have not been disclosed, and the public record does not separate members assigning engineers to shared work from members endorsing a direction.
For enterprise security leaders, the immediate value is narrower and more concrete than the announcement suggests: a testable agent harness framework, a safer weight storage format moving to neutral stewardship, a signed-patch distribution path for open source dependencies, and a workload identity standard already in production use. Each of those has utility for a security team regardless of what the alliance becomes over the next year. The wider question, whether a group assembled in under two weeks can sustain joint engineering across 37 competing organisations, will take considerably longer to answer.