Nvidia Leads 40-Company Coalition to Build Open Security Tools for AI Systems
The Open Secure AI Alliance wants shared, openly inspectable tools to become the standard defence against attacks on artificial intelligence systems, and it is warning regulators that locking down open AI could leave defenders blind.

Key points
- Nvidia and more than 35 companies launched the Open Secure AI Alliance on Monday to develop free, open-source security tools for artificial intelligence systems.
- Inaugural partners include Microsoft, IBM, Cloudflare, CrowdStrike, Salesforce, Hugging Face, Palo Alto Networks, and Capital One, among others.
- Nvidia cited a real breach at OpenAI and Hugging Face where a closed AI tool blocked forensic investigators, while an open-weight AI model reviewed over 17,000 actions to help contain the damage.
- The alliance is urging policymakers not to restrict open AI models, arguing that restrictions would weaken collective cyber defence.
- Several concrete technical contributions were announced at launch, covering everything from software vulnerability scanning to secure identity verification for AI systems.
More than three dozen of the world's largest technology companies announced Monday that they are forming a new body called the Open Secure AI Alliance. The group's goal is straightforward: build and share free, openly inspectable security tools specifically designed to protect AI systems from attack.
Nvidia is leading the effort. The founding membership, first reported by SecurityWeek, reads like a who's-who of enterprise technology: Adobe, Capital One, Cisco, Cloudflare, CrowdStrike, Dell, Hugging Face, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, Siemens, and around twenty others have all signed on.
Why does this matter to ordinary people?
AI systems now help run hospital booking systems, bank fraud detection, and customer service platforms. Attacks on those systems can expose personal data or cause services to fail. This alliance is an attempt to make those systems harder to break into before something goes wrong.
The alliance is building on groundwork already laid by the Linux Foundation's Akrites initiative and the OpenSSF community, both of which are existing groups that produce free security tools for software developers.
What is each company actually contributing?
Each founding member is bringing something concrete to the table.
| Company | Contribution | What it does |
|---|---|---|
| Nvidia | NOOA open-source project | Makes AI agent behaviour easier to trace and audit |
| HPE | SPIFFE/SPIRE framework | Cryptographically verifies the identity of AI services (think of it as a digital ID check) |
| Hugging Face | Safetensors format | A safer way to store AI model files, donated to the PyTorch Foundation |
| IBM and Red Hat | Lightwell project | Automatically finds and patches security flaws in software supply chains |
| Microsoft | MDASH scanning harness | Uses multiple AI agents working together to find and validate exploitable software bugs |
| SpaceXAI | Grok Build agent | An open-source AI coding assistant, with plans to open-source the underlying model weights |
The alliance's central argument is that open models and openly inspectable security tools are a defence, not a danger. Keeping AI tools closed and proprietary, the group says, can actually help attackers.
Nvidia pointed to a recent security incident involving OpenAI and Hugging Face as evidence. When investigators tried to work out what had happened, a closed AI tool could not tell attackers from defenders and blocked the forensic work. Hugging Face stepped in and used an open-weight model called GLM 5.2 to review more than 17,000 system actions and help contain the breach.
"The right response is not to deny defenders access to capable open systems," Nvidia said in a statement. "It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation."
Should regulators be worried?
The alliance is sending a direct message to governments: broad restrictions on open AI frontier models would weaken cyber defence, not strengthen it. That is a pointed intervention at a moment when several jurisdictions are debating exactly how tightly to regulate advanced AI.
The practical argument is simple. When security researchers can inspect an AI model's inner workings, they can test it, find its weaknesses, and fix them. Closed systems do not allow that. In cybersecurity, the ability to examine and verify a tool is not a luxury; it is the job.



