StorageReview.com

NVIDIA’s Open Secure AI Alliance Launches With 35+ Members and Three Notable Absences

AI  ◇  Enterprise

NVIDIA and more than 35 founding partners have launched the Open Secure AI Alliance, an initiative focused on developing open-source tools, models, agent frameworks, and security technologies for AI systems. The membership is notable as much for who is absent as who signed on: Microsoft, IBM, Cisco, Palantir, Dell Technologies, and HPE are in, while OpenAI, Google, and Anthropic, the three labs most identified with frontier closed models, are not.

The alliance is being established with support from the Linux Foundation’s Akrites initiative and the Open Source Security Foundation, or OpenSSF. Its stated objective is to give security teams inspectable and adaptable technologies for securing AI models, agents, and the software supply chain around them.

Founding participants span cloud infrastructure, cybersecurity, enterprise software, AI research, and open-source communities. The member list includes Adobe, Box, Capital One, Cisco, Cloudflare, CrowdStrike, Databricks, Dell Technologies, Elastic, Fortinet, GitHub, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, Mistral, NAVER, NetApp, Nokia, Palantir, Palo Alto Networks, Perplexity, Red Hat, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Uber, vLLM, and Zscaler.

Focus Shifts Beyond Model Weights

The alliance argues that AI security should be evaluated at the full agent-stack level rather than solely through the availability of model weights. In this view, an AI agent includes the model, orchestration layer, tools, identity controls, permissions, isolation mechanisms, guardrails, logging, and evaluation processes.Open Secure AI Alliance

Open models can create misuse risks, including removal of safeguards or adaptation for offensive cyber activity. However, the alliance contends that closed models do not eliminate these risks and can limit a defender’s ability to inspect behavior, validate controls, or operate AI capabilities within its own infrastructure.

The initiative will promote a model that allows organizations to use both closed and open AI models. Closed models may remain appropriate for certain frontier capabilities, while open models and harnesses can offer transparency, local control, and customization for defensive workloads.

This is particularly relevant in regulated sectors and sovereign environments, where organizations may need to retain direct operational control over sensitive data, model behavior, security logs, and incident-response workflows.

Open Agent Harness Research

NVIDIA plans to contribute open models, model weights, data, and research on agent harnesses to the alliance. One early contribution is the NVIDIA Labs Object-Oriented Agent (NOOA) project, available on GitHub.

NOOA is a research framework designed to improve the safety and auditability of AI agent harnesses. The project is intended to make it easier to test, trace, govern, and evaluate agent behavior as models interact with tools, external data, code repositories, and enterprise systems.

The broader alliance work is expected to include tooling for agent identity, workload isolation, secure model formats, model scanning, and secure AI-assisted software development.

Member Contributions Target Identity, Model Security, and Scanning

Several founding members outlined technologies that could form components of an open AI defense stack.

HPE is supporting SPIFFE/SPIRE, an open framework for zero-trust workload identity. The technology uses cryptographic identity verification to authenticate services and AI agents, helping ensure that only authorized workloads can access enterprise resources and communicate across distributed environments.

Hugging Face has contributed Safetensors to the PyTorch Foundation. Safetensors is a model-weight format designed to avoid arbitrary code execution risks associated with some serialized model-file formats. It is intended to make the distribution and inspection of AI models safer across open-source environments.

IBM and Red Hat have highlighted Lightwell, which uses digitally signed patches to improve integrity across the open-source software supply chain. Microsoft contributed MDASH, a multi-model agentic scanning harness that coordinates specialized AI agents to identify, assess, and demonstrate potentially exploitable software vulnerabilities.

SpaceXAI has open-sourced Grok Build, a terminal-based AI coding agent, and signaled an intent to release model weights for Grok models. These contributions reflect the alliance’s broader emphasis on enabling independent inspection, testing, and adaptation of AI tools used in security operations.

Policy Implications for Open AI Security

The Open Secure AI Alliance is also advocating for policy approaches that treat open AI tools as part of cybersecurity infrastructure rather than categorically as a risk factor. Its position is that broad restrictions on frontier open models could increase reliance on a limited number of proprietary providers while reducing the ability of enterprise and government defenders to test and harden their own systems.

The alliance is calling for shared investment in open datasets, evaluation frameworks, attack simulators, red-teaming tools, secure model distribution, and agent security controls. For enterprise infrastructure teams, the effort underscores the growing need to secure AI deployments as interconnected systems that combine models, applications, identities, storage, networking, observability, and automated decision-making.

Engage with StorageReview

Newsletter | YouTube | Podcast iTunes/Spotify | Instagram | Twitter | TikTok | RSS Feed

Harold Fritts

I have been in the tech industry since IBM created Selectric. My background, though, is writing. So I decided to get out of the pre-sales biz and return to my roots, doing a bit of writing but still being involved in technology.