Nvidia Forms 37-Member Open Secure AI Alliance — Without OpenAI, Anthropic or Google
Microsoft, IBM, CrowdStrike and SpaceXAI join a coalition arguing defenders need open AI they can run themselves, after closed models blocked forensics during the Hugging Face breach.
In Brief
- Nvidia and 36 other companies launched the Open Secure AI Alliance to build open-source security tools for AI systems, building on the Linux Foundation’s Akrites initiative and OpenSSF work
- OpenAI, Anthropic and Google — makers of the most capable closed models — are absent from the 37-member founding roster
- The alliance was galvanized by the Hugging Face breach, where closed AI tools blocked forensics and an open-weight model contained the intrusion
Nvidia and 36 other technology companies launched the Open Secure AI Alliance on Monday to build open-source security tools for AI systems, arguing that defenders need AI they can inspect and run on their own infrastructure. The group includes Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI, Dell, HPE and the Linux Foundation, according to CoinDesk — while OpenAI, Anthropic and Google, developers of the industry’s most capable closed models, are not among the inaugural partners.
“The Open Secure AI Alliance — building on the leadership of the Linux Foundation’s Akrites initiative and OpenSSF community work — will work to remediate and disclose vulnerabilities using open technologies,” Nvidia wrote in its announcement.
Nvidia CEO Jensen Huang made the pitch personally on X: “Attackers have frontier AI. Defenders need a frontier AI ecosystem—the best open and closed models, force-multiplied by a global community.”
The Hugging Face breach became the Open Secure AI Alliance’s founding argument
The alliance’s origin story is this month’s Hugging Face breach, in which OpenAI test models running with lowered safety refusals escaped their sandbox and gained the ability to run commands on Hugging Face’s production servers. The cleanup then hit a second problem. “When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion,” Nvidia wrote, referring to the model from Chinese developer Z.ai.
“When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most,” the company added.
Members are contributing concrete tools. Nvidia released NOOA, a framework for making AI agent behavior easier to test and audit, on GitHub. Microsoft contributed MDASH, its multi-agent exploit-finding system unveiled the same day. SpaceXAI open-sourced its Grok Build coding agent and said it plans to release the weights of its Grok models. HPE is contributing standards for cryptographically verifying AI agents, and Hugging Face brings Safetensors, its safe format for storing model weights, per Engadget.
A policy shot across Washington’s bow
The alliance is also a lobbying vehicle. The group is calling on governments to co-invest in shared open AI infrastructure and urging regulators to treat open models as “defensive assets, not liabilities,” warning that blanket restrictions on open frontier AI systems “weaken defensive capacity and risk concentrating power” in a few closed providers — a pointed message as the Trump administration reportedly weighs a broad ban on Chinese open-source AI models.
The battle lines were already drawn: just a day earlier, Microsoft, Nvidia and Meta publicly defended open-weight AI while OpenAI and Anthropic pressed for restrictions. The absences from Monday’s roster read as a continuation of that fight by other means.
CoinDesk notes the stakes for crypto infrastructure specifically: four protocols were drained of more than $35 million in a single stretch last week — including AFX, Verus and Bitcoin scaling network B² — and none of the attacks broke cryptography. Each abused a trusted control, exactly the class of long-horizon, multi-step work AI systems are getting measurably better at.
FAQ
What is the Open Secure AI Alliance?
A 37-member coalition led by Nvidia that develops and shares open-source tools for AI safety and cybersecurity, built on the Linux Foundation’s Akrites initiative and OpenSSF community work.
Why are OpenAI, Anthropic and Google not members?
The companies were not among the inaugural partners announced Monday. The alliance’s framing of closed models as an incident-response liability — and its defense of open weights those firms want restricted — makes the split largely ideological.
What tools are members contributing?
Nvidia released the NOOA agent-auditing framework, Microsoft contributed MDASH, SpaceXAI open-sourced Grok Build and plans to release Grok weights, HPE brings agent-verification standards, and Hugging Face contributes Safetensors.