NVIDIA and 90+ industry leaders have launched the Open Secure AI Alliance to develop open source AI tools and models for
Open source software is fundamental to the global economy, underpinning cloud computing, financial services, manufacturing, telecommunications, government and internet services. Cybersecurity ranks among the top three beneficiaries of open source, and the newly formed Open Secure AI Alliance, built on the Linux Foundation's Akrites initiative and OpenSSF community work, will remediate and disclose vulnerabilities using open technologies.
As open source created a shared foundation for software, the United States and its partners now face a choice about AI security: whether defensive systems will be contained in a few opaque solutions or built on open models, harnesses and tools that any defender can study, adapt and deploy. Both closed and open models are needed globally, but for cybersecurity specifically, open models and harnesses are essential. They democratize defensive capabilities, increase transparency, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed, community-driven and self-controlled defense with no single point of failure.
Open models can be misused, including through attempts to weaken safeguards or repurpose capabilities for cyberattacks, but these risks are not unique to open systems and must be managed wherever advanced AI is deployed. The recent Hugging Face security incident demonstrated this reality: when closed AI tools were unable to distinguish attackers from defenders and blocked forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than seventeen thousand actions and contain the intrusion. This showed that when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their response capability is constrained precisely when speed matters most. Companies and countries need open frontier defensive tools so critical industries can build security systems across a multi-vendor ecosystem and avoid single points of failure.
The Open Secure AI Alliance has ninety-one inaugural partners including NVIDIA, Adobe, Box, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Crusoe, Databricks, Dell Technologies, DoorDash, Elastic, F5, Factory AI, Fortinet, G42, GitHub, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, Mistral, NAVER, NetApp, Nokia, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Perplexity, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, TrendMicro, Uber, Upwind, vLLM, WWT and Zscaler.
Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. These risks are real but do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI. The right response is not to deny defenders access to capable open systems but to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen systems on which society relies. Defenders need both frontier closed and frontier open models working together so they can choose the right system for the job and ensure transparency, adaptation and sovereign control wherever security demands them.
An AI agent is not just a language model but a complex system built from models, harnesses and guardrails. Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed. Open harnesses and tools make those controls easier for defenders to inspect, test and improve.
Alliance members are contributing specific technologies. NVIDIA is contributing open models, weights, data and new agent harness research, including the NOOA project, an open source Object-Oriented Agent framework available on GitHub that makes advanced AI safety capabilities more accessible for agent harnesses and enables better integration of harnesses with models to make agent behavior easier to test, trace, audit and govern. HPE contributes to SPIFFE and SPIRE, which create zero-trust identity framework standards to cryptographically verify AI agents and services. Hugging Face has offered Safetensors, a safe format to store AI model weights providing transparency and guarantees of no remote code execution, to the PyTorch Foundation. IBM and Red Hat's Lightwell extends security across the open source supply chain with digitally signed patches. Microsoft's MDASH is a multi-model agentic scanning harness that orchestrates specialized AI agents to discover, debate and prove exploitable bugs. SpaceXAI has open sourced the Grok Build terminal-based AI coding agent to promote trust and transparency, and plans to open source the weights of the Grok line of models.
As policymakers and regulators grapple with AI safety, they must recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers. Companies and governments should invest in shared open infrastructure for AI defense — datasets, evaluation frameworks, attack simulators and red-teaming tools — much as past generations invested in open source software.
The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that safety and security are built in the open for everyone. That future will not be secured by assuming secrecy alone is safety but by building systems strong enough to withstand scrutiny, flexible enough to be improved and open enough to mobilize the full community of defenders.