NVIDIA and a coalition of industry leaders have formed the Open Secure AI Alliance, addressing a critical juncture in artificial intelligence security. The alliance frames the current choice as binary: AI defenses will either reside within a few opaque systems or be built on open models and tools accessible to all defenders. Cybersecurity is specifically identified as one of the top three areas to benefit from this open approach, promising a direct boost to existing security infrastructure. Building on the work of the Linux Foundation’s Akrites initiative and OpenSSF community, the group intends to share open technologies to remediate vulnerabilities and foster trust in AI. “The world needs both closed and open models,” the alliance asserts, emphasizing that open models are essential for democratizing defensive capabilities and avoiding single points of failure.
Open Secure AI Alliance: Collaborative Cybersecurity Foundation
The emergence of the Open Secure AI Alliance signals a fundamental shift in how the industry approaches artificial intelligence security, with cybersecurity explicitly positioned as one of the top three areas to benefit from this collaborative effort. This builds upon established frameworks instead of attempting to reinvent them, accelerating the development and deployment of crucial defenses. This effort focuses on ensuring that defensive capabilities are democratized, increasing transparency for those tasked with protecting critical infrastructure.
Contributing partners, including NVIDIA, Adobe, and Microsoft, are contributing to an encompassing identity, permissions, and secure coding workflows. HPE is contributing to SPIFFE/SPIRE, creating zero-trust identity frameworks, while Hugging Face has offered Safetensors, a secure format for storing AI model weights, to the PyTorch Foundation. NVIDIA is also contributing open models and research through the NOOA project, designed to make AI safety capabilities more accessible for agent harnesses. The alliance asserts that combining openness with robust safeguards and rapid remediation will ultimately prioritize shared security over secrecy.
The current landscape of artificial intelligence security increasingly relies on layered systems, encompassing not just model weights but the complete “agent stack”, identity protocols, permissions, harnesses, and evaluation tools. Industry leaders agree that real progress in AI safety depends on securing this entire system, not solely on restricting access to model weights. This emphasis on holistic security is driving new research initiatives like NVIDIA’s NOOA project, designed to enhance the accessibility of AI safety capabilities for agent harnesses. NVIDIA is actively contributing open models, weights, and data to the Open Secure AI Alliance, aiming to accelerate the development of novel cybersecurity tools and techniques. The newly available NOOA research framework, hosted on GitHub, intends to improve how harnesses integrate with models, making agent behavior more easily tested, traced, audited, and governed. This is a collaborative effort for agents, addressing elements from identity and isolation to secure coding workflows.
Hugging Face Incident Highlights Need for Open Systems
The recent security breach experienced by Hugging Face underscores a growing imperative for transparency in artificial intelligence systems, prompting industry leaders to prioritize open-source solutions for enhanced cybersecurity. While closed AI models offer a degree of control, the incident revealed critical limitations when defenders lack the ability to independently analyze and respond to threats. Facing an intrusion, Hugging Face leveraged the open-weight GLM 5.2 model on its own infrastructure to dissect over 17,000 actions and contain the attack, highlighting the value of accessible AI for self-defense.
This is not simply about sharing code; it’s about fostering a distributed, community-driven defense system, mitigating the risks associated with reliance on a few opaque systems. The alliance recognizes that open models, while potentially susceptible to misuse, present a more resilient approach than solely relying on closed systems, asserting that “the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.” The Open Secure AI Alliance invites governments, industry, and researchers to join in defending the AI era together.
The escalating need for robust AI security is now being addressed through collaborative open-source initiatives, shifting the focus from proprietary defenses to community-driven resilience. This framing underscores a growing concern that concentrated control over AI security creates inherent vulnerabilities. The security incident at Hugging Face served as a stark reminder of the need for open systems. The alliance’s goal is to ensure that defenders everywhere have open, frontier tools they can trust and control, fostering a distributed, community-driven defense system against emerging threats.
See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
