TLDRocket
Sign in

Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security

NVIDIA NVIDIA Covered by 75 sources

Nvidia, Microsoft, IBM and dozens more just launched an open AI security alliance. Closed AI blocked a hack response, so Hugging Face used an open model instead.

Based on reporting by NVIDIA, NVIDIA — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

A long list of tech heavyweights just put their names on something called the Open Secure AI Alliance, and the pitch is simpler than the roster suggests: cybersecurity needs open AI tools, not just polished closed ones locked behind a handful of vendors. Nvidia, Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks, Cloudflare, Red Hat, Hugging Face and dozens of others are inaugural partners, building on work already underway at the Linux Foundation's Akrites initiative and the OpenSSF community. The goal is to find, disclose and fix vulnerabilities using shared, inspectable technology rather than proprietary black boxes.

The case for this got a real-world stress test recently. During a security incident at Hugging Face, closed AI tools couldn't tell the difference between attackers and defenders, so they blocked the forensic analysis the security team actually needed. Hugging Face turned to the open-weight GLM 5.2 model running on its own infrastructure, used it to comb through more than 17,000 actions, and contained the intrusion. That's the argument in a nutshell: when defenders can't inspect, tweak and run a model themselves, they lose precious time exactly when speed matters most.

None of this is an anti-closed-model crusade. The alliance's framing is that the world needs both open and closed systems working side by side, and that open models carry their own misuse risks — jailbreaking, guardrail removal, repurposing for attacks — that are real but not unique to open systems. The fix, as the group sees it, isn't hiding weights from everyone; it's pairing openness with strong safeguards, clear rules against misuse, and fast remediation when something goes wrong.

What's actually landing on GitHub and elsewhere gives some shape to the ambition. Nvidia is contributing open models, weights, data and a new project called NOOA — the NVIDIA Labs Object-Oriented Agent framework — meant to make agent behavior easier to test, trace and audit. HPE is bringing SPIFFE/SPIRE identity standards for verifying which AI agents get to talk to what. Hugging Face has handed its Safetensors format, which avoids remote code execution risks in model weights, over to the PyTorch Foundation. IBM and Red Hat's Lightwell adds digitally signed patches across the open source supply chain, Microsoft's MDASH orchestrates AI agents to hunt for and prove exploitable bugs, and SpaceXAI has open sourced its Grok Build coding agent while planning to open the weights of its Grok models too.

The alliance is also aiming its message squarely at regulators, arguing that blanket restrictions on open frontier AI would concentrate power and risk in a few closed providers rather than making anyone safer. Whether policymakers buy that framing is another matter entirely, but the underlying claim — that security built in the open, where more people can poke at it, tends to hold up better than security built on secrecy — is at least consistent with how open source software has generally played out elsewhere in tech.

My take — AI-written commentary, not fact-checked reporting

The Hugging Face story is the whole argument in miniature: a closed AI tool couldn't tell friend from foe and got in the way of the actual fix, while an open model did the job. That's a pointed rebuttal to the instinct that locking everything down automatically means safer, and it's the kind of evidence regulators leaning toward blanket restrictions on open models should sit with before writing rules that hand even more leverage to a small set of closed providers.

Read more about this at: NVIDIA

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.