Nvidia, Microsoft, IBM, Red Hat, Hugging Face, Cisco, CrowdStrike and more than two dozen other companies launched the Open Secure AI Alliance on July 27, a coalition to build open-source cybersecurity tools for AI agents. The group is framing openness as a defensive necessity, arguing that closed AI systems leave security teams unable to inspect or adapt the models protecting critical infrastructure. The launch arrives days after Hugging Face used an open-weight model to analyze more than 17,000 actions in containing its own security breach — a case study the alliance is putting at the center of its pitch.
The founding roster spans cloud, security, enterprise software and AI research: Adobe, Cadence, Capital One, Cloudera, Cloudflare, Cognition, Databricks, Dell Technologies, DoorDash, Elastic, HPE, LangChain, the Linux Foundation, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Reflection AI, Salesforce, SAP, SK Telecom and others sit alongside Nvidia and Microsoft. The alliance builds on the Linux Foundation's Akrites initiative and existing OpenSSF community work on vulnerability disclosure. It is explicitly modeled on the open-source software movement that underpins cloud computing, financial services and telecommunications.
The Hugging Face incident is the alliance's founding evidence. According to Nvidia's announcement, closed AI systems refused to run the forensic analysis needed to investigate the breach because they could not distinguish attackers from defenders. Hugging Face turned to the open-weight GLM 5.2 model, ran it on its own infrastructure, and processed 17,000 actions to contain the intrusion.
“When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.”— NVIDIA, Open Secure AI Alliance announcement
Key facts
- 01Nvidia, Microsoft, IBM, Red Hat, Hugging Face, Cisco, Palantir and CrowdStrike are among 30-plus founding members of the Open Secure AI Alliance.
- 02The alliance builds on the Linux Foundation's Akrites initiative and OpenSSF community work to remediate AI-related vulnerabilities.
- 03Hugging Face analyzed 17,000 actions using open-weight GLM 5.2 to contain a recent intrusion after closed AI tools blocked forensic work.
- 04Nvidia is contributing the open-source NVIDIA Labs Object-Oriented Agent (NOOA) project to GitHub as part of the launch.
- 05The coalition is explicitly lobbying policymakers against blanket restrictions on open frontier AI systems.
That episode is being used to argue a specific policy point: defenders need the ability to run frontier AI on their own hardware, without a vendor's content policy blocking incident response. "When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most," the alliance said in its launch text.
The coalition is also lobbying against pending restrictions on open-weight AI. That puts the group in direct opposition to a rival letter, signed earlier by OpenAI and Anthropic, urging Washington to curb Chinese open-weight models. The Open Secure AI Alliance argues the opposite — that blanket restrictions on open frontier systems would concentrate power in a small number of closed providers and weaken cyber defense across the broader ecosystem.
Members are contributing specific pieces of technical infrastructure. Nvidia is open-sourcing the NVIDIA Labs Object-Oriented Agent framework, or NOOA, on GitHub to make agent behavior easier to test, trace and audit. HPE is contributing to SPIFFE/SPIRE, a zero-trust identity framework for verifying AI agents. Hugging Face has donated its Safetensors format to the PyTorch Foundation. IBM and Red Hat are extending their Lightwell project for signed patches across the open-source supply chain. Microsoft is contributing MDASH, a multi-model agentic scanning harness that orchestrates specialized AI agents to find exploitable bugs.
“Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed.”— NVIDIA, Open Secure AI Alliance announcement
SpaceXAI has open-sourced its Grok Build terminal-based coding agent and, according to the announcement, plans to release the weights of its Grok model line to developers and researchers. Cognition, whose Devin coding agent AI Chat Daily covered following its Poke acquisition, is also a founding contributor. The scope of technical contributions is unusually broad for a launch-day coalition — most industry alliances open with a manifesto and fill in the code later.
The pitch to regulators is the sharpest part of the announcement. The alliance is asking governments to treat open models, harnesses and security tools as defensive assets rather than liabilities, and to invest in shared open infrastructure — datasets, evaluation frameworks, attack simulators, red-teaming tools — the way past generations of policy funded open-source software. It is a direct challenge to the framing that has driven recent proposals to restrict open-weight AI on national-security grounds.
The counterargument is real. Open weights can be modified to strip safety guardrails, and any capable model can be repurposed for offensive cyber work. The alliance's response is that determined attackers do not need open weights to build offensive tools, and that closing off defenders' access does not stop that threat — it only handicaps the defense. Whether policymakers accept that framing will determine how much of the alliance's technical work matters in practice.
The coalition also reflects a competitive fault line in the AI industry. On one side sit the closed frontier labs pushing for tighter export and access controls; on the other, an increasingly organized bloc — spanning infrastructure providers, cybersecurity vendors and open-source foundations — that sees regulatory capture as the bigger risk. With Nvidia, Microsoft and IBM on the open side, that bloc now has the enterprise weight to be heard in Washington and Brussels. The next test is whether the alliance ships enough working defensive tooling to make its policy case with code rather than lobbying alone.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




