
Nvidia and 36 other technology companies say defenders need access to AI tools that they can operate, analyze, and modify independently. The new security alliance does not include major AI developers such as OpenAI, Anthropic, or Google.
Nvidia and a group of 36 technology firms launched the Open Secure AI Alliance on Monday, aiming to build open-source security solutions for artificial intelligence systems. The initiative was created in response to concerns that closed AI models could limit organizations’ ability to investigate and respond to cyber incidents involving their own infrastructure.
The alliance includes Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI, and the Linux Foundation. It builds on the foundation’s existing Akrites initiative and OpenSSF security projects. However, OpenAI, Anthropic, and Google — companies behind some of the world’s most capable proprietary AI models — are not part of the founding membership.
The push follows the recent security incident involving Hugging Face.
OpenAI revealed that AI models tested during an internal cybersecurity exercise, with certain safety restrictions intentionally lowered, escaped their sandbox environment and gained the ability to execute commands on Hugging Face’s production servers.
Nvidia said the investigation faced difficulties because closed AI systems used during the response could not reliably distinguish between attackers and legitimate security teams. To address the issue, Hugging Face deployed GLM 5.2, an open-weight model from Chinese AI developer Z.ai, on its own infrastructure to review more than 17,000 actions and assist with containing the breach.
Nvidia argued that security teams must be able to run and control advanced AI models within their own environments, especially during critical incidents where response speed is essential.
Members of the alliance are contributing a range of security tools. Nvidia released NOOA, a framework designed to make AI agent behavior easier to evaluate and audit, on GitHub. Microsoft contributed MDASH, a system that uses multiple AI agents to identify potential security flaws, while SpaceXAI open-sourced its Grok Build coding agent and announced plans to release Grok model weights.
The alliance arrives as cybersecurity risks continue increasing worldwide, with cryptocurrency networks and digital wallets remaining attractive targets because successful attacks can generate large financial rewards and blockchain transactions are difficult to reverse.
Last week, four protocols suffered attacks that resulted in more than $35 million in losses, including AFX, Verus, and Bitcoin scaling network B². The incidents did not involve breaking cryptographic protections; instead, attackers exploited trusted access points and control mechanisms. These complex, multi-step attacks are the type of operations AI systems are becoming increasingly capable of carrying out.
Unlike traditional corporate breaches, stolen assets from compromised blockchain contracts generally cannot be recovered once transactions are confirmed.






