A new group of major firms, the Open Secure AI Alliance, are setting out to build open-source AI tools for security defences.

Nvidia, Adobe, Cisco, Cloudflare, CrowdStrike, IBM, Microsoft, Palo Alto Networks, Red Hat, Salesforce, SAP, and ServiceNow sit alongside cloud and infrastructure providers such as Dell Technologies, HPE, NetApp, and Snowflake. The roster also includes AI labs including Hugging Face, Cognition, Nous Research, and Thinking Machines Lab. The Linux Foundation, which already runs the OpenSSF community work referenced in the group’s founding materials, supplies the governance structure behind it.

What forced the question wasn’t a policy paper but a certain alarming incident at Hugging Face that made global headlines.

The breach that forced an open-model fix

Hugging Face suffered a security incident that its own closed AI tooling couldn’t help contain. The closed systems used for forensic work couldn’t distinguish attacker activity from legitimate defender action, and ended up blocking the analysis Hugging Face’s team needed to run.

The company switched to GLM 5.2, an open-weight model it could run without restriction on its own infrastructure, and used it to analyse more than 17,000 actions taken during the intrusion. That analysis is what let the company contain the breach.

Nvidia and the Alliance are using that episode as the case for the entire initiative. When a closed model’s safety filters can’t tell an incident responder from an intruder, a defender locked into that one vendor has few options left; they either wait for a fix or lose visibility during the window when speed matters most. 

Hugging Face had an alternative it controlled directly, but not every enterprise runs a research lab with spare model weights on hand. Closing that gap is the argument members are making for treating open frontier models as infrastructure rather than a niche option for hobbyist developers.

None of that resolves the case against open models outright. Weights any defender can inspect are also weights an attacker can inspect, strip of safeguards, or fine-tune for misuse, and the Alliance doesn’t dispute that.

The position of the Open Secure AI Alliance is that closed weights don’t remove the risk either, they just put it behind a vendor’s access controls. The group argues that pairing openness with evaluation, monitoring, and quick patching gives defenders more capacity than restricting access does.

Governance below the model layer

An AI agent used for security work is a stack, not a single model. Identity checks, permission scopes, a harness that constrains what the model can call, logging, and evaluation all sit around whatever weights run the reasoning. Members are contributing pieces of that stack rather than competing on a single open-versus-closed model release.

Nvidia’s contribution is the NVIDIA Labs Object-Oriented Agent (NOOA) project, released on GitHub as open-source research code. NOOA targets the harness layer specifically, the software sitting between a model and the actions it’s permitted to take, and it’s built to make agent behaviour easier to trace, test, audit, and govern rather than to improve raw model reasoning. After all, a model can be technically-capable and still produce agents nobody can audit if the harness around it doesn’t log or constrain what it does.

Other members are filling adjacent gaps. HPE is contributing to SPIFFE/SPIRE, an identity framework that issues cryptographic identities to workloads so systems can verify an AI agent is what it claims to be before granting access to enterprise resources.

Hugging Face has handed Safetensors, its format for storing model weights without embedded executable code, to the PyTorch Foundation, addressing a known route for remote code execution in older model file formats.

IBM and Red Hat’s Lightwell project applies digitally-signed patches across the open-source supply chain. Microsoft is contributing MDASH, a scanning harness that runs multiple specialised agents against code to find and prove exploitable bugs rather than simply flag suspicious patterns. xAI has open-sourced its Grok Build coding agent and says it plans to release the weights of its Grok model line to outside researchers.

What regulators do with this claim

The Alliance’s public argument is aimed at policymakers currently drafting AI safety rules: treat open weights, harnesses, and security tooling as assets defenders rely on, not a category to restrict by default. 

A blanket rule against open frontier models, the group argues, would concentrate AI defence capacity inside a small number of closed vendors and remove the option Hugging Face used during its own incident.

Whether that argument holds will depend on cases beyond this one. The Alliance’s founding document leans on a single documented incident and a set of contributions, several released only this week without a track record in hostile production environments. NOOA remains a research framework on GitHub rather than a supported product with a maintenance contract behind it.

Members will need more recovery stories like Hugging Face’s before open agent stacks are treated as the default choice rather than a backup option.

See also: Codeberg members vote to reject LLM training and vibe coding

Banner for Cyber Security Expo by TechEx events.

Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

Developer is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.



Share.
Leave A Reply

Exit mobile version