Skip to content

Open Secure AI Alliance Pushes Open-Source AI Defense

The Open Secure AI Alliance aims to strengthen AI security with open-source tools. Can open defense outpace AI threats?

In a bid to build open defensive tools for agentic AI and to lead an AI policy push to build open tools for AI agents, Nvidia and more than 30 other tech companies launched the Open Secure AI Alliance. Industry reaction to the alliance has been largely positive but mixed on how the efforts will likely impact how enterprises secure their agentic AI efforts in the future.

The news of the alliance landed days after OpenAI confirmed that two of its models, GPT‑5.6 Sol and a pre-release model being tested in a sandboxed environment, managed to hack into machine-learning sharing platform Hugging Face's production systems to find and extract the solution artifacts tied to the evaluation stored in Hugging Face's systems that could help the models to complete the test.

The first part of this story:

OpenAI, Hugging Face, and the Real AI Security Problem
OpenAI and Hugging Face exposed AI’s biggest security risk: enterprises automating broken processes, weak governance, and excess access.

The Hugging Face breach

According to OpenAI's explanation, using the benchmarking suite ExploitGym, its models were being evaluated for security capabilities. With that, they remained focused on solving the security benchmark testing, escaped the sandbox, targeted Hugging Face and found a zero-day in the package registry cache proxy to gain Internet access, and then chained stolen credentials and additional vulnerabilities to reach Hugging Face's production database. The models then obtained what they concluded they needed to solve the benchmark efficiently.

From its vantage, Hugging Face described the intrusion as malicious code execution in its data-processing pipeline, privilege escalation, credential harvesting, and lateral movement across internal systems by an autonomous agent. In Hugging Face's attempt to defend its systems, Hugging Face said it initially tried to use frontier AI models accessed through commercial APIs. Still, those systems' guardrails blocked the forensic work because they could not distinguish an incident responder from an attacker. The company then turned to GLM 5.2, an open-weight model running on its own infrastructure, to analyze the attack logs.

"The lesson driving this coalition is a practical one, and it should reshape incident-response planning: a defender locked out of commercial models by the very safety guardrails meant to stop attackers is fighting with one hand tied," wrote Eric Parizo, founder and chief analyst at Cernivera Research. 

That's essentially the alliance's pitch: if defenders need to inspect, adapt, and locally deploy AI security systems, they need open infrastructure and to deploy without relying on a handful of closed systems to succeed. 

Those tools would come in the form of a common defensive stack for AI security. They would reduce dependence on proprietary protections that are not fully transparent to the customer through closed models, hidden detection logic, or security controls that can't be audited or modified easily. If the alliance is successful, it could make AI defense more portable, more transparent, and less vulnerable to single-vendor failures.

What the Open Secure AI Alliance Aims to Achieve

To avoid security lockouts like that experienced by Hugging Face, Cernivera recommends every security team vet and stage a capable model it can run on its own infrastructure before an incident, both to avoid guardrail lockout and to keep attacker data and credentials inside the environment. 

The alliance announcement wants to ensure that can be done with open models and tools as well as proprietary systems. "Just as open source created a shared foundation for software, the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy," Nvidia said in its announcement post.

"For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense – with no single point of failure," the post continued.

The alliance's founding group, which includes Adobe, Cisco, CrowdStrike, Dell Technologies, HPE, Hugging Face, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, the Linux Foundation, and others acknowledged open models can be misused, just as any technology, "but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed," the post said.

What the Open Secure AI Alliance has committed

Nvidia is contributing open models, weights, data, and new agent-harness research, including the open-source NOOA (NVIDIA Labs Object-Oriented Agents) project, which is designed to make agent behavior easier to test, trace, audit, and govern. Nvidia argues that defenders need both open and closed systems, with open tools available for inspection and control.

Open Secure AI Alliance members are contributing security tools that manage identity, model-format safety, supply-chain protection, and vulnerability scanning. Reported contributions include HPE's cryptographic identity work based on SPIFFE and SPIRE, Hugging Face's Safetensors format for safer model-weight storage, IBM and Red Hat's Lightwheel work on digitally signed open-source patches, and Microsoft's MDASH multi-model vulnerability scanning framework. 

In total, those components add up to an initial plausible "open defense stack" for AI agents: workload identity, secure model formats, scanning, logging, and remediation workflows. Current AI security is often fragmented, with point products that address a single aspect of defense. 

 Sachin Jade, chief product officer at threat intelligence and security operations platform provider Cyware, said some elements will need more time to mature and prove themselves, such as NVIDIA's NOOA agent-harness framework and the MDASH multi-model vulnerability discovery harness, which need more testing. "As such, essentially, the pieces exist at very different maturity levels and don't seem to have ever been assembled end-to-end by anyone," Jade said.

 "Elements such as the shared evaluation frameworks, the attack simulators, and the red-teaming commons are in their infancy in a collaborative sense but the right ones to be invested in," he added.

 Kristin Lowery, field CISO at cybersecurity consultancy Optiv, said that there are aspects of what's been released this week by the alliance that are practical because they connect to security work companies already understand: knowing what AI tools are being used, who or what is allowed to access them, how activity is logged, and how issues are reported and fixed. "The most useful near-term controls are the ones that help organizations put identity, permissions, monitoring, and accountability around AI systems," she said.

 However, it will take time for everything needed in that AI security stack to come together. "The more aspirational part is the idea of a complete open defensive stack for AI agents. That is directionally important, but most enterprises will still need clear implementation guidance, support models, and proof that these tools can operate safely in production before treating it as a mature platform," Lowery said.

Policy and lobbying goals

The alliance also wants to shape legislative and regulatory policy. The alliance is urging policymakers to recognize open models, harnesses, and tooling as defensive assets, and to avoid blanket restrictions that could concentrate power in a few closed providers. 

Effectively, the alliance is asking governments to preserve the ability of defenders to use open AI systems for red-teaming, vulnerability discovery, and secure development while also supporting shared infrastructure investments and security research. The message: restricting open models could weaken cyber defense capacity, especially for organizations that need customizable, locally controlled tools.

Lowery said the alliance's efforts may help shape the policy debate, though regulators are unlikely to treat openness as automatically safe. "The strongest argument is that open models and tools can help defenders see how systems work, test them, and respond faster when something goes wrong. That transparency matters. However, regulators will still ask whether the tools can be misused, who is accountable, and how access is controlled. This is where identity becomes central: openness is easier to defend when organizations can prove who or what accessed a system, what permissions were granted, and what safeguards were in place," she said.

 The likely outcome is a more nuanced line between governed openness that supports defense and uncontrolled openness that creates new risk, Lowery concluded.

 Cyware's Jade said in the short and near term, the impact on lawmakers will probably be a mixed bag. "The regulatory line right now is being drawn primarily around compute thresholds, capability evaluations, and export controls posture rather than a binary open-vs-closed one. NVIDIA and its co-signers are pushing on a partly open door. This hopefully gives regulators political cover not to impose blanket open-weight restrictions. By naming Adobe, Capital One, Cisco, Palantir, Microsoft, IBM, Red Hat, and CrowdStrike in one press release, it makes it politically expensive to treat open weights as presumptively dangerous. This appears to be the alliance's most durable near-term achievement, probably.

Industry reaction

Early industry reaction to the effort appears broadly positive, especially among open-source and infrastructure providers. The Linux Foundation backed the effort and supported open models and open tooling as foundational to secure AI. At the same time, the alliance and security are being framed as a serious attempt to create a shared defensive infrastructure.

However, the alliance has its membership gaps: OpenAI, Anthropic, and Google (the biggest providers of closed frontier models) were not among the founding members, despite the alliance's stated ambition to speak for the broader AI security ecosystem.

Cernivera's Parizo said that the alliance also sharpens the open-weight debate by reframing open models as defensive assets rather than liabilities. Parizo said he is also concerned about OpenAI's recent lack of openness. "Cybersecurity leaders know that full disclosure is a guiding principle, not based on legal advice. Delangue's [Hugging Face CEO Clément Delangue's] demand for radical transparency "is the right instinct, and how OpenAI answers should serve as a signal to enterprises on how seriously it takes its disclosure obligations."

When it comes to near-term outcomes for enterprises, Optiv's Lowery explained there should be measurable outcomes, such as stronger identity and permission controls for AI agents. "Enterprises need a clear answer to a fundamental question: who or what is acting on their behalf," she said.

"Once that foundation is in place, organizations can better control what an AI agent can access, limit the actions it can take, monitor its behavior, and investigate issues when they occur. Better vulnerability discovery and faster disclosure are important outcomes, but they depend first on trustworthy identity, accountability, and governance. The most immediate enterprise advantage is confidence that AI-driven activity is governed, traceable, and restricted to approved actions," Lowery said.

If the alliance succeeds, the Open Secure AI Alliance could make AI defense more transparent and portable; if it stalls, it may end up as an influential statement rather than an operational standard.

HOU.SEC.CON CTA

Latest