Open Secure AI Alliance: Nvidia and Partners Bet on Open Models for Cybersecurity
Amid ongoing debates over open-weight AI models, Nvidia on Monday announced the launch of the Open Secure AI Alliance, a coalition of more than 35 technology companies that will develop and share tools for AI safety and cybersecurity. The announcement follows a recent security incident on Hugging Face involving OpenAI-linked AI agents, which heightened concerns about the risks of autonomous AI systems.
The alliance includes Nvidia, Microsoft, IBM, Cisco, Dell Technologies, Adobe, CrowdStrike, Palo Alto Networks, Salesforce, SAP, the Linux Foundation, Hugging Face, and other organizations spanning AI, cybersecurity, enterprise software, cloud computing, and open-source technologies. Nvidia was also among 25 technology companies that recently signed an open letter urging the US administration to reconsider its stance on open-weight AI models.
The coalition's core argument is that cyber defenders need AI systems whose inner workings can be inspected, rather than opaque black-box models. Closed models, no matter how advanced, cannot always distinguish between an attacker and a defender investigating their own systems—an ambiguity that hampers speed during critical incidents.
The recent Hugging Face security incident served as a catalyst: when closed AI tools prevented investigation of a breach, Hugging Face used an open-weight model on its own systems to analyze over 17,000 actions and contain the situation. For the alliance's founders, this demonstrated that open, inspectable AI is an operational necessity when defenders need to move fast and trust their tools.
The alliance builds on existing open-source security work, including the Linux Foundation's efforts and the OpenSSF community. Instead of pitting open versus closed AI, the alliance frames them as complementary: closed frontier models still have a role, but open models and tools allow a wider circle of defenders to test, adapt, and deploy protections without depending on a handful of opaque providers.
In practice, the alliance shares not just AI models but also the surrounding safety machinery—systems that verify user identity, control permissions, and record actions. Early contributions include Nvidia's research on safer AI harnesses, HPE's identity verification tools, Hugging Face's secure model storage, IBM and Red Hat's tamper-proof software update verification, Microsoft's multi-agent bug-hunting tool, and SpaceXAI's open-sourced coding tool (with plans to open-source Grok models).
The alliance urges policymakers not to treat open AI systems as inherently riskier than closed counterparts. Blanket restrictions on open frontier models, the group argues, would empower a small number of closed providers and shrink the pool of defenders able to protect critical systems. Instead, the alliance calls for public and private investment in shared defensive infrastructure such as datasets, evaluation frameworks, attack simulators, and red-teaming tools.