AI

NVIDIA, Microsoft and IBM Launch Open Secure AI Alliance

NVIDIA, Microsoft and IBM Launch Open Secure AI Alliance

Open Secure AI Alliance member company logos arranged on a press-kit graphic

A who’s-who of the technology industry lined up behind a single argument on July 27: that the defenses protecting critical infrastructure in the AI era should be built in the open, not locked inside a handful of proprietary systems. The vehicle for that argument is the Open Secure AI Alliance, announced by NVIDIA with an inaugural partner list that spans NVIDIA, Microsoft, IBM, Hugging Face, Cisco, Cloudflare, CrowdStrike, Databricks, Dell Technologies, HPE, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake, the Linux Foundation and more than a dozen others.

The alliance’s stated mission is to develop and share open technologies, techniques and tools to safeguard software and AI agents — building on the Linux Foundation’s Akrites initiative and the OpenSSF community’s existing work on open-source security. The pitch is framed as a direct answer to a policy question: should AI-powered cyber defense depend on a few opaque closed systems, or on open models, harnesses and tooling that any defender can inspect, adapt and run on their own infrastructure?

The Hugging Face incident as Exhibit A

The announcement leans hard on one recent, concrete story. During the recent Hugging Face security incident, NVIDIA’s post says, closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis mid-response. Hugging Face instead ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.

That episode is the alliance’s core exhibit: when defenders cannot inspect, adapt and run advanced AI on infrastructure they control, their response capacity is constrained at precisely the moment speed matters most. The counterargument — that open weights can be stripped of guardrails and repurposed by attackers — gets acknowledged rather than dodged. The alliance’s position is that those risks exist in closed systems too, and the answer is pairing openness with safeguards, evaluation and rapid remediation rather than denying defenders capable tools.

What the members are actually contributing

This is not a statement-of-principles alliance; the launch comes with a stack of named contributions:

NVIDIA is contributing open models, weights, data and its new NVIDIA Labs Object-Oriented Agent (NOOA) project, an open-source research framework on GitHub designed to make agent behavior easier to test, trace, audit and govern. Microsoft brings MDASH, its multi-model agentic scanning harness that orchestrates specialized AI agents to discover, debate and prove exploitable bugs. IBM and Red Hat’s Lightwell extends supply-chain security with digitally signed patches, and Red Hat’s announcement frames the alliance as an open-source “defense layer” play.

HPE contributes to SPIFFE/SPIRE, the zero-trust identity standards that can cryptographically verify AI agents so only authorized workloads touch enterprise resources. Hugging Face has offered Safetensors — its no-remote-code-execution model weight format — to the PyTorch Foundation. SpaceXAI has open-sourced its Grok Build terminal coding agent and says it plans to open-source the weights of the Grok model line. Security vendors are on board too: CrowdStrike announced its own membership the same day, alongside Palo Alto Networks and Elastic on the partner roster.

The framing throughout is that an AI agent is not just a model — it is a system of identity, permissions, harnesses, guardrails, logs and evaluation, and real security depends on that whole stack being inspectable.

The policy subtext

The announcement closes with an explicit message to regulators: treat open models, harnesses and security tooling as defensive assets, not liabilities. Blanket restrictions on open frontier AI systems, the alliance argues, would concentrate defensive capability — and therefore dependence and vulnerability — in a few closed providers.

That is a live policy fight, and this alliance is best read as one side of it organizing. The membership list is the message: cloud vendors, chipmakers, security firms, enterprise software giants and open-source foundations jointly asserting that openness and security are complements, not opposites. Whether governments buy that framing will shape how the next round of AI safety rules treats open weights — which makes this less a product announcement than an opening brief.

Editorially independent: we accept no payment for coverage and currently use no affiliate links. Read our Editorial Standards and Corrections Policy. Published: Jul 28, 2026.
Jinultimate

Editor of ZBrandCo and the person accountable for what we publish — setting our sourcing standards, fact-checking claims against primary sources, and issuing corrections promptly across AI, open source, and gaming. Reach the desk at editorial@zbrandco.com.