A coalition of technology companies, cybersecurity vendors, and open source organisations, has launched the Open Secure AI Alliance, an industry initiative aimed at developing open AI models, agent frameworks and security tools for cyber defence.
According to a NVIDIA blog the founding members include NVIDIA, Adobe, Cisco, Cloudflare, CrowdStrike, Databricks, Dell Technologies, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NetApp, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake and several AI research organisations.
The launch comes amid growing debate over whether advanced AI models used for cybersecurity should be open or proprietary based on a recent security incident when OpenAI and Hugging Face partnered to address a cybersecurity incident in which an advanced AI model accidently escaped its containment environment and hacked Hugging Face servers.
Hugging Face used the open-weight GLM 5.2 model on its own infrastructure to analyse more than 17,000 actions that successfully contained the unauthorized intrusion. Since closed AI tools are unable to distinguish attackers from defenders during essential forensic analysis, it exposed how closed AI tools are restricted when cyberattacks occur. The incident illustrated the importance of being able to inspect, modify and run advanced AI tools locally during security investigations.
Nvidia said in a statement on CNBC, “The Open Secure AI Alliance will work to remediate and disclose vulnerabilities using open technologies, the recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense.”
The alliance builds on the Linux Foundation’s Akrites project and work by the Open Source Security Foundation (OpenSSF). Its goal is to develop open technologies for vulnerability remediation, disclosure and AI-powered security while enabling organisations to deploy and customise AI systems within their own infrastructure.
The alliance argues that open models and agent frameworks give defenders greater transparency, flexibility and operational control, while acknowledging that both open and closed frontier AI systems have roles in cybersecurity. It also argues that the security risks associated with open AI models, including their potential misuse for cyberattacks, are not unique to open systems. Governments and regulators are obligated to recognise open AI models, agent frameworks and security tooling as defensive infrastructure.
Several founding members announced contributions to the initiative. NVIDIA released the open source NVIDIA Labs Object-Oriented Agent (NOOA) framework for testing and governing AI agents.
HPE is contributing work on SPIFFE/SPIRE identity standards, Hugging Face is contributing the Safetensors model format to the PyTorch Foundation, IBM and Red Hat are extending software supply chain security through Lightwell. Microsoft is contributing its MDASH multi-model agentic scanning framework, and SpaceXAI has open sourced its Grok Build coding agent and plans to release the weights for its Grok model family.
The initiative reflects a broader effort within the technology industry to establish open standards and shared infrastructure for securing AI systems as enterprises deploy increasingly autonomous AI agents. These broad restrictions on open frontier AI systems could reduce defensive capabilities and increase dependence on a small number of proprietary AI providers.

