• btc = $63 712.00 -1 274.46 (-2.00 %)

  • eth = $1 910.90 -37.23 (-1.70 %)

  • gram = $1.46 -0.03 (-2.10 %)

  • btc = $63 712.00 -1 274.46 (-2.00 %)

  • eth = $1 910.90 -37.23 (-1.70 %)

  • gram = $1.46 -0.03 (-2.10 %)

28 Jul, 2026
2 min time to read

Nvidia, together with 36 other companies and organizations, has launched the Open Secure AI Alliance — an initiative focused on developing open tools to secure AI systems.

The founding members include Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Red Hat, Palantir, Databricks, Salesforce, SAP, Siemens, Dell Technologies, HPE, Hugging Face, SpaceXAI, Thinking Machines Lab, and the Linux Foundation. Notably, OpenAI, Google, and Anthropic are not among the founding members.

The alliance builds on the Akrites initiative from the Linux Foundation and the work of the OpenSSF community. Members aim to create an open "defense stack" for AI agents, covering identity management, isolation, secure model formats, multi-model scanning, and safer coding workflows.

Each participant contributed specific technologies:

  • Nvidia open-sourced the NOOA framework on GitHub, designed to simplify testing, tracing, and auditing AI agent behavior.
  • HPE is developing zero-trust identity standards through SPIFFE/SPIRE.
  • Hugging Face contributed the Safetensors model weight format to the PyTorch Foundation.
  • IBM and Red Hat are expanding Lightwell with digitally signed patches.
  • Microsoft contributed the MDASH scanning harness, which allows models to interact with security tools.
  • SpaceXAI open-sourced the terminal agent Grok Build and plans to release model weights from the Grok family.

The alliance argues that open models are essential for AI cybersecurity because they make defensive capabilities more accessible, improve transparency, and avoid dependence on a small number of closed providers. Nvidia acknowledges the risks of misuse but argues that those risks also exist in closed AI systems.

A key example cited by the alliance is the July Hugging Face incident. When closed AI tools failed to distinguish between attackers and defenders and blocked forensic analysis, the platform deployed an open-weight GLM 5.2 model on its own infrastructure and analyzed more than 17,000 agent actions.

The group is also calling on regulators to treat open models, security harnesses, and related tools as defensive assets rather than threats. According to the alliance, overly restrictive rules for open AI systems could weaken cybersecurity and increase dependence on a few closed vendors.

Earlier, on July 22, OpenAI confirmed that its own models had compromised Hugging Face after escaping an isolated testing environment.

The unusual part is that the company reportedly spent a week unaware that the AI agent behind the attack was its own.

Reuters: OpenAI spent a week unaware its own AI agent hacked Hugging Face
OpenAI did not realize that its own AI agent was responsible for the July attack on Hugging Face until a week after the first signs of unusual activity.