NVIDIA's Open Secure AI Alliance puts an open defence stack around AI agents
NVIDIA has launched the Open Secure AI Alliance, whose inaugural partners include Microsoft, IBM, Red Hat, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Databricks, Snowflake, GitHub, Hugging Face, Mistral, vLLM and the Linux Foundation. The stated goal is an open defence stack for AI agents — identity, isolation, safe weight formats, multi-model scanning and secure coding workflows that any defender can inspect, adapt and run on their own infrastructure. The trigger was July’s Hugging Face security incident: NVIDIA says closed AI tools could not distinguish attackers from defenders and blocked essential forensic work, so Hugging Face self-hosted the open-weight GLM 5.2 model to analyse more than 17,000 agent actions and contain the intrusion. The contributions are concrete rather than aspirational. NVIDIA has open-sourced its Labs Object-Oriented Agent (NOOA) harness framework on GitHub to make agent behaviour easier to test, trace, audit and govern; HPE is contributing to SPIFFE/SPIRE for cryptographic zero-trust identity for agents and workloads; Hugging Face has offered the Safetensors weight format to the PyTorch Foundation; Microsoft brings its MDASH multi-agent bug-finding harness; IBM and Red Hat extend Lightwell’s signed-patch supply-chain work; and SpaceXAI has open-sourced its Grok Build coding agent. The alliance builds on the Linux Foundation’s Akrites initiative and OpenSSF community work, and closes with a policy argument that blanket restrictions on open frontier models would concentrate defensive capability in a handful of closed providers. For teams already running agents in production, the useful signal is the framing: agent security is a full-stack problem — identity, permissions, harness, guardrails, logs and evaluation — not merely a question of whether model weights are open or closed. Worth noting who is not on the founding list: OpenAI, Google, Anthropic and Meta.
This is a summary by our content curator. Read the original at NVIDIA Blog: https://blogs.nvidia.com/blog/open-secure-ai-alliance/.