NVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance.
This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).
Its goal is to enhance vulnerability disclosure, remediation, and community-driven cyber defense as AI agents become integrated into enterprise and critical infrastructure environments.
NVIDIA, Microsoft, and CrowdStrike Launch AI Security
Nvidia initiative emphasizes that open-source software is foundational to various sectors, including cloud services, finance, manufacturing, telecommunications, government systems, and internet infrastructure.
Proponents of the alliance argue that open AI models and harnesses offer similar defensive capabilities by enabling security teams to inspect system behavior, customize controls, deploy capabilities locally, and maintain control over sensitive data.
Rather than replacing proprietary cutting-edge models, the alliance positions open systems as complementary tools that can reduce dependence on single vendors and provide organizations with greater flexibility during incident response.
A recent security incident involving Hugging Face highlighted the operational need for this initiative. During the incident, closed AI services reportedly struggled to distinguish legitimate forensic activity from malicious behavior, which limited their effectiveness for responders.
In contrast, Hugging Face deployed the open-weight GLM 5.25.25.2 model on its own infrastructure, allowing it to analyze over 17,000 actions and support containment efforts.
This example underscores the need for defenders to be able to run, inspect, and fine-tune advanced models within their own environments, especially during time-sensitive investigations involving confidential telemetry or restricted network access.
Inaugural participants in the alliance include major companies and organizations such as NVIDIA, Microsoft, CrowdStrike, Adobe, Cisco, Cloudflare, Databricks, Dell Technologies, Elastic, HPE, IBM, the Linux Foundation, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Snowflake, and TrendAI, among others.
The group will collaborate on a shared defensive stack that encompasses agent identity, isolation, safe model distribution, multi-model vulnerability scanning, secure development workflows, evaluation frameworks, and red-team tooling.
NVIDIA is contributing open models, weights, datasets, and research related to AI agent harnesses. Its newly released NVIDIA Labs Object-Oriented Agent (NOOA) framework is now available on GitHub.
This framework aims to make agent behavior more testable, traceable, auditable, and governable. The project emphasizes that AI security must extend beyond model weights to include permissions, identities, logs, guardrails, orchestration layers, and continuous evaluation.
Other member contributions reflect this comprehensive approach. HPE is supporting SPIFFE/SPIRE zero-trust identity standards for cryptographically verifying AI agents and services.
Hugging Face has contributed Safetensors, a model-weight format designed to avoid risks associated with remote code execution. IBM and Red Hat are advancing Lightwell, which facilitates digitally signed open-source patches.
At the same time, Microsoft’s MDASH harness coordinates specialized AI agents to identify, debate, and validate exploitable vulnerabilities.
The alliance acknowledges that open models can be misused or modified to bypass safeguards. However, it argues that similar risks exist in closed ecosystems.
It should be managed through robust evaluations, misuse policies, rapid remediation, identity controls, and transparent security testing, not by denying defenders access to effective tools.
The Open Secure AI Alliance is also urging policymakers to treat open AI security infrastructure as a valuable defensive asset and to support investment in common datasets, attack simulators, benchmarks, and red-teaming platforms.
ALERT: 20+ government sites delivered malware to businesses and citizens. See full attack research to check your own exposure.

