Security 3 min read

Open Secure AI Alliance Targets Secure AI Agents 

The Linux Foundation, NVIDIA, Microsoft, IBM, Cisco, CrowdStrike, Palo Alto Networks, Hugging Face, Red Hat and dozens of other technology companies and research organizations launched the Open Secure AI Alliance (OSAA)to develop open technologies, tools and frameworks for securing AI systems and defending critical digital infrastructure. The initiative builds on work from the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF), promoting an ecosystem where organizations can inspect, adapt and deploy AI security technologies on their own infrastructure.

The alliance argues that cybersecurity increasingly depends on open AI models, agent frameworks and evaluation tools that defenders can inspect and modify rather than relying exclusively on proprietary services. While acknowledging that both open and closed AI models can be misused, the group contends that transparency, community review and rapid remediation improve defensive capabilities. The announcement cites a recent Hugging Face security incident, where the company reportedly used an open-weight GLM 5.2 model running on its own infrastructure to analyze more than 17,000 actions during incident response after access to certain closed AI services proved unavailable for forensic analysis.

Beyond advocating for open models, the alliance focuses on the broader AI agent stack—including identity, permissions, guardrails, harnesses, logging and evaluation. Initial technical contributions include NVIDIA’s new open-source NVIDIA Labs Object-Oriented Agent (NOOA) framework for agent harnesses, Microsoft’s MDASH multi-agent vulnerability scanning framework, HPE’s SPIFFE/SPIRE-based identity technologies, Hugging Face’s Safetensors model format, IBM and Red Hat’s Lightwell signed software supply chain capabilities, and open-source contributions from SpaceXAI around its Grok Build coding agent. The alliance also calls on policymakers to recognize open AI security tooling as a strategic defensive asset and to support shared investments in evaluation frameworks, datasets, red-teaming platforms and attack simulation environments.

“The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone.”

• Open Secure AI Alliance launched by more than 40 organizations spanning AI, cloud, cybersecurity and enterprise software.
• Builds on Linux Foundation Akrites and OpenSSF security initiatives.
• Focuses on open AI models, agent harnesses, evaluation tools and secure AI infrastructure.
• NVIDIA released the open-source NVIDIA Labs Object-Oriented Agent (NOOA) research framework on GitHub.
• Microsoft contributes the MDASH multi-agent vulnerability scanning framework.
• HPE contributes SPIFFE/SPIRE-based zero-trust identity technology for AI agents.
• Hugging Face contributes the Safetensors secure model format.
• IBM and Red Hat contribute the Lightwell digitally signed software supply chain framework.
• Alliance encourages governments to treat open AI security technologies as strategic defensive infrastructure.

🌐 Analysis

The membership spans much of the modern AI infrastructure stack, including semiconductor vendors, cloud providers, cybersecurity firms, enterprise software companies and open-source organizations. Rather than proposing a new model architecture, the alliance seeks to establish interoperable security technologies that can operate across both open and proprietary AI models, potentially influencing future standards for enterprise AI security and governance.

Share this article

Help others discover this reporting.

From the Graveyard

You just read about Security. A name from the archive that helped shape it:

IronPort Systems built Email security appliances, anti-spam intelligence and web security. What became of it?

From the Technology Graveyard

You just read about Security. A technology from the archive that helped get us here:

WEP (Wired Equivalent Privacy) served 1999–2004. What ultimately replaced it?

On this day

July 27

From 25 years of the Converge Digest archive.