NVIDIA, Microsoft, CrowdStrike, and more than 30 industry leaders have launched the Open Secure AI Alliance, a coalition dedicated to building and sharing open source tools that strengthen AI safety and security.
The initiative, announced July 27, 2026, builds on the Linux Foundation’s Akrites initiative and OpenSSF community work, aiming to remediate and disclose vulnerabilities using transparent, community-driven technologies.
The Alliance frames its mission around a core tension in AI security: whether critical infrastructure defenses will rely on opaque, closed systems or on open models and harnesses that any defender can inspect, adapt, and deploy.
NVIDIA, Microsoft and CrowdStrike Launch AI Security Tools
Proponents argue that open source cybersecurity tools democratize defensive capabilities, increase transparency, and eliminate single points of failure across a multi-vendor ecosystem.
A recent incident at Hugging Face underscored this argument. During a security breach in July 2026, closed AI tools reportedly failed to distinguish attackers from defenders, blocking essential forensic analysis.
Hugging Face’s security team pivoted to the open-weight GLM 5.2 model running on its own infrastructure, analyzing over 17,000 actions to contain the intrusion, demonstrating the operational value of self-hosted, inspectable AI during active incident response.
The Alliance’s founding members span cloud computing, cybersecurity, enterprise software, and AI research, including Adobe, Cisco, Cloudflare, Databricks, Dell, Elastic, HPE, IBM, Palo Alto Networks, Red Hat, Salesforce, SAP, and Snowflake, among others.
Key technical contributions include:
- NVIDIA’s NOOA framework — the NVIDIA Labs Object-Oriented Agent project, now on GitHub, designed to make agent behavior easier to trace, audit, and govern within harness architectures.
- HPE’s SPIFFE/SPIRE work — zero-trust identity standards that cryptographically verify AI agents and services.
- Hugging Face’s Safetensors — a secure model weight storage format, now contributed to the PyTorch Foundation, that prevents remote code execution risks.
- IBM and Red Hat’s Lightwell — supply chain security via digitally signed patches.
- Microsoft’s MDASH — a multi-model agentic scanning harness that orchestrates specialized AI agents to discover and prove exploitable vulnerabilities.
- SpaceXAI’s Grok Build — an open-source terminal-based AI coding agent, with plans to open source Grok model weights.
NVIDIA stated that AI safety depends on more than model weights alone. Real security requires attention to the entire agent stack: identity, permissions, harnesses, guardrails, logging, and evaluation.
Open harnesses make these control layers easier for defenders to test and strengthen collectively. The coalition is also directing a message at regulators: open models and security tooling should be treated as defensive assets rather than liabilities.
Blanket restrictions on open frontier AI, the group warns, could concentrate power and vulnerability among a handful of closed providers rather than distributing defensive capacity broadly.
The Alliance is inviting governments, enterprises, and researchers to contribute to shared infrastructure, including datasets, evaluation frameworks, and red-teaming tools, positioning open collaboration as the foundation for AI-era cyber resilience.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.