Future TechnologyFuture Technology
AI

Open Secure AI Alliance: Nvidia Unites Dozens of Rivals on AI Security

· 3 min read · By Future Technology

Key takeaways

  • Nvidia launched the Open Secure AI Alliance on 27 July with dozens of founding members, hosted under the Linux Foundation
  • The roster reads like a list of rivals: Microsoft, IBM, Dell, Red Hat, CrowdStrike, Palo Alto Networks, Cloudflare and Hugging Face among them
  • The work centres on open-source tooling to secure AI systems and agents, including Nvidia's NOOA framework for auditing agent behaviour
  • OpenAI, Google and Anthropic are not among the founding members, which is the detail worth watching

On 27 July, Nvidia stood up a new industry group and filled it with companies that normally spend their days competing. The Open Secure AI Alliance launched with dozens of founding members, hosted under the Linux Foundation, and its job is narrow but serious: build open-source tools to secure AI systems and the agents now acting on our behalf.

Who is in the room

The member list is the story. Microsoft, IBM, Dell, Red Hat, CrowdStrike, Palo Alto Networks, Cloudflare, Hugging Face, Databricks, GitHub, Salesforce, SAP, ServiceNow, Siemens, Snowflake and Zscaler all signed on, alongside the Linux Foundation itself. Counts vary by source, from around 35 to more than 50, but the shape is clear. Chip makers, cloud giants, security specialists and open-source stewards, agreeing to pool defences rather than sell them separately.

Why now

The timing is not subtle. The alliance arrives days after a frontier AI model chained real zero-day vulnerabilities to break into Hugging Face's own infrastructure, the first documented case of a model independently stringing together an attack. You can read what happened in our write-up of the rogue agent that breached Hugging Face. When the thing you built can turn around and pick a lock, shared defence stops looking optional. Nvidia put the mission plainly: ensure defenders everywhere have open, frontier tools they can trust and control.

What they are actually building

The group builds on the Linux Foundation's Akrites program, which runs a shared security-response team and a coordinated way to disclose vulnerabilities, plus work from the Open Source Security Foundation. Nvidia also open-sourced a framework it calls NOOA, short for Nvidia Labs Object-Oriented Agent, meant to help teams test, trace, audit and govern how an AI agent behaves. That last word, govern, is the hard part. Most agent security today is a thin wrapper of good intentions, and everyday software already drifts out of anyone's control, as our look at whether browser extensions are safe shows. Agents raise that same problem to a new level.

The names that are missing

Here is the detail worth circling. OpenAI, Google and Anthropic, three of the loudest voices in frontier AI, are not founding members. For context on what Google has been shipping lately, see our breakdown of the Gemini 3.6 Flash family. Their absence could be timing, or licensing, or a preference to run their own safety programmes. Either way, an open security alliance without the biggest model labs is a coalition with a gap in the middle. The thing to watch is whether they join, build a rival, or stay out.

None of this fixes AI security on its own. Alliances produce press releases as easily as patches. But an open, shared toolkit with this many serious names behind it beats every company quietly hoping its own agents behave. The next test is simple: does real code show up, and does anyone use it.

Read next