AI Models

NVIDIA and Tech Giants Launch Open Secure AI Alliance

NVIDIA and dozens of industry leaders, including Adobe, Cisco, Cloudflare, CrowdStrike, IBM, Microsoft, and Red Hat, have formed the Open Secure AI Alliance. The group aims to develop and share open tools, models, and techniques to improve cybersecurity and AI safety, building on the Linux Foundation's Akrites initiative and OpenSSF community work.

Neura News

Neura News

Neura Market Editorial

July 27, 20265 min read
NVIDIA and Tech Giants Launch Open Secure AI Alliance

{ "title": "Tech Giants Unite Behind Open Secure AI Alliance to Fortify AI Defenses", "body": "A coalition of more than 50 technology companies and organizations, including NVIDIA, Microsoft, IBM, and SpaceXAI, has launched the Open Secure AI Alliance, an open-source initiative aimed at developing shared cybersecurity tools and techniques for AI systems. The Alliance builds on the Linux Foundation's Akrites initiative and the OpenSSF community's work, with a focus on remediating and disclosing vulnerabilities through open technologies. The founding partners represent a broad cross-section of the tech industry, from cloud providers and cybersecurity firms to AI startups and enterprise software companies.\n\n## Why Open Source Is Critical for AI Security\n\nOpen source software serves as a foundational element of the global economy, supporting cloud computing, financial services, manufacturing, telecommunications, government, and internet services. Cybersecurity ranks among the top three beneficiaries of open source software. The Alliance contends that open models and open harnesses are essential for cybersecurity because they democratize defensive capabilities, increase transparency, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls.\n\nOpen source facilitates massively distributed, community-driven, and self-controlled defense without a single point of failure. While open models can be misused—for example, by weakening safeguards or repurposing them for cyber attacks—those risks are not exclusive to open systems. Some argue that open models are inherently less safe due to potential misuse for cyberattacks or removal of guardrails, but the risks of open models do not disappear in closed systems. Simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI.\n\nThe appropriate response, according to the Alliance, is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation, and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify, and strengthen systems. Defenders need both frontier closed models and frontier open models working together. The Alliance emphasizes that open source security tools allow organizations to inspect code, audit dependencies, and customize defenses to their specific infrastructure, which is critical in a multi-vendor environment where no single provider can address all threats.\n\n## The Hugging Face Incident Highlights the Need for Open Tools\n\nA recent security incident at Hugging Face demonstrated the limitations of closed AI tools. During the incident, closed AI tools blocked essential forensic analysis. Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.\n\n"When defenders cannot inspect, adapt, and run advanced AI on their own infrastructure, their ability to respond is constrained at the moment speed matters most," the Alliance stated. Companies and countries need open frontier defensive tools and techniques to build security systems across a multi-vendor ecosystem and avoid single points of failure. The incident underscored that proprietary AI tools, while powerful, can become bottlenecks during active security incidents when rapid customization and local deployment are required. The Alliance argues that open-weight models give defenders the flexibility to run analysis on-premises or in private clouds, keeping sensitive data within their control.\n\n## Contributions from Founding Partners\n\nThe Alliance's inaugural partners include NVIDIA, Adobe, Box, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Crusoe, Databricks, Dell Technologies, DoorDash, Elastic, F5, Factory AI, Fortinet, G42, GitHub, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, Mistral, NAVER, NetApp, Nokia, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Perplexity, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, TrendAI, Uber, Upwind, vLLM, World Wide Technology, and Zscaler. This diverse group spans industries including cloud computing, enterprise software, telecommunications, financial services, and cybersecurity.\n\nNVIDIA is contributing open models, model weights, data, and new agent harness research to the Alliance. The NVIDIA Labs Object-Oriented Agent (NOOA) project is now available on GitHub. NOOA is a research framework that enables harnesses to better integrate with models to make agent behavior easier to test, trace, audit, and govern. The framework is designed to help developers build AI agents that are more transparent and accountable, addressing a key challenge in deploying autonomous systems.\n\nHPE contributes to the SPIFFE/SPIRE zero-trust identity framework standards for cryptographically verifying AI agents and services. Hugging Face offered Safetensors, a safe format for storing AI model weights, to the PyTorch Foundation. Safetensors provides transparency and no remote code execution guarantees, meaning that loading model weights cannot trigger arbitrary code, a common attack vector in machine learning pipelines.\n\nIBM and Red Hat's Lightwell extends security across the open source supply chain with digitally signed patches. This ensures that updates to open source components are verified and tamper-proof, reducing the risk of supply chain attacks. Microsoft's MDASH multi-model agentic scanning harness orchestrates specialized AI agents to discover, debate, and prove exploitable bugs. The harness uses multiple AI models that collaborate to identify vulnerabilities, cross-checking each other's findings for higher accuracy.\n\nSpaceXAI open-sourced Grok Build, a terminal-based AI coding agent, to promote trust, transparency, and new capabilities. The company also plans to open-source weights of the Grok line of models. This move allows the broader developer community to inspect, modify, and improve the models, fostering innovation in AI-assisted coding.\n\nAcross the Alliance, contributors are building an open defense stack for agents that includes identity, isolation, safe model formats, multi-model scanning, and secure coding workflows. The stack is designed to be modular, allowing organizations to adopt components that fit their existing security infrastructure while maintaining interoperability.\n\n## The Full Agent Stack: Beyond Model Weights\n\nAn AI agent is a complex system built from models, harnesses, and guardrails. Real AI safety and security depend on the full agent stack—identity, permissions, harnesses, guardrails, logs, evaluation—not just whether model weights are open or closed. The Alliance argues that focusing solely on model weights misses the broader security picture. For example, even a closed model can be vulnerable if its harness or identity system is compromised, while an open model with strong guardrails and monitoring can be more secure in practice.\n\nThe Alliance argues that policymakers and regulators should recognize open models, harnesses, and security tooling as defensive assets, not liabilities. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence, and vulnerability in a few closed providers. The Alliance points out that closed systems can create monocultures where a single vulnerability affects all users, whereas open systems allow for diverse implementations and faster patching.\n\nCompanies and governments should invest in shared open infrastructure for AI defense, including datasets, evaluation frameworks, attack simulators, and red-teaming tools. The age of AI agents can be one of resilience and shared security with open secure AI systems. The Alliance calls for collaboration between public and private sectors to fund and maintain these shared resources, noting that no single organization can keep pace with evolving AI threats alone.\n\nThe future will be secured by building systems strong enough to withstand scrutiny, flexible enough to be improved, and open enough to mobilize the full community of defenders. The Open Secure AI Alliance invites governments, industry, and researchers to join. The Alliance plans to release regular updates on its projects and welcomes contributions from new members who share its vision of open, secure AI.\n\n## Related on Neura Market\n- AI & Machine Learning Sector\n- Cybersecurity & Defense\n- Open Source Software" }

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

More from Neura News

AI Models

42 Mathematicians Urge Royal Society to Warn Government and Media About AI Existential Risk

Forty-two mathematical fellows, including Fields Medal winners Martin Hairer, Peter Scholze, and Wendelin Werner, have signed an open letter urging the Royal Society to warn the UK government and media about existential risks from advanced AI. The letter follows recent breakthroughs in which leading models solved open research problems, including a Millennium Problem. None of the signatories are affiliated with AI companies. The group warns that AI labs' estimates of existential risk above ten percent must not be dismissed as hype, and that by the time the situation becomes obvious to the public, it may be too late to act.

Sep 18·2 min read
Developer

Steve Yegge Shuts Down Gas Town After Failing to Build Anything Else With It

Steve Yegge shut down Gas Town, his ultra-vibed coding agent orchestrator, after admitting he never built anything else with it despite heavy subscription spend. Databricks reported a 60% coding spend increase after rolling out GPT-6 Astra to 3,500 engineers, OpenAI published a misalignment disclosure framework with six case reports, and Xiaomi ran MiMo-V2.6 RL training in public with live telemetry.

Sep 18·21 min read