NVIDIA and more than 35 companies, including Microsoft, IBM, Cisco, CrowdStrike, Salesforce, SAP, ServiceNow, Palantir, Databricks, Snowflake, Dell Technologies, HPE, Red Hat, Hugging Face and the Linux Foundation, formed the Open Secure AI Alliance on July 27, 2026 (NVIDIA, 2026). The coalition is dedicated to developing and sharing open models, agent harnesses, and security tooling to help defenders counter AI-enabled cyber threats.
The Alliance builds on the Linux Foundation's Akrites initiative and OpenSSF's existing vulnerability-remediation work. It cites Hugging Face's use of the open-weight GLM 5.2 model to contain a recent security incident as the case for why defenders need frontier tools they can run and inspect on their own infrastructure. The launch follows Jensen Huang's July 24 open letter, signed by roughly 25 companies arguing that open-weight AI models are essential to preserving US AI leadership.
What is the Open Secure AI Alliance building?
Three things. First, open models and model weights for cybersecurity defense. NVIDIA is contributing open models, model weights, data, and new agent harness research. Second, the NVIDIA Labs Object-Oriented Agent (NOOA) project, now available on GitHub, which enables the development of advanced AI safety capabilities for agentic control systems. Third, shared security tooling: HPE's zero-trust identity framework SPIFFE/SPIRE, Hugging Face's Safetensors format for storing model weights, Microsoft's MDASH multi-model agentic security scanner, and SpaceXAI's open-sourced Grok Build coding agent (NVIDIA, 2026).
- NVIDIA NOOA: open-source agent-harness framework for testing and auditing agent behavior
- HPE SPIFFE/SPIRE: zero-trust identity framework for AI systems
- Hugging Face Safetensors: safe format for storing and sharing model weights
- Microsoft MDASH: multi-model agentic security scanner
- SpaceXAI Grok Build: open-sourced terminal-based AI coding agent
Why did NVIDIA launch this now?
The Hugging Face security incident in July 2026 is the founding case study. When closed AI tools blocked essential forensic work because they could not tell attackers apart from defenders, Hugging Face fell back on the open-weight GLM 5.2 model running on its own hardware. The episode showed that defenders need open, frontier agentic systems for self-defense. NVIDIA's argument is explicit: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most (NVIDIA, 2026).
The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense.
— NVIDIA
Who is not in the Alliance?
Anthropic and OpenAI. The two most prominent frontier labs still committed to closed-weight models are absent from both the Alliance and Huang's letter. That is significant, given that the Alliance's central claim is that closed systems cannot be fully trusted for defensive work because defenders cannot inspect or adapt them. Their absence could reflect a genuine disagreement with the open-security thesis, a reluctance to lend credibility to a coalition built around a rival's platform, or simply that neither was asked to join a group NVIDIA is using to advance its own ecosystem (Futurum Group, 2026).
What does this mean for the open vs closed AI debate?
The Alliance is the clearest sign yet that NVIDIA sees open source not just as a market to compete in, but as a security argument it wants to own. The coalition brings together more than 35 companies around a shared commitment to building open models, agent harnesses, and vulnerability-remediation tools for AI-era cyber defense. It arrives at a moment when Washington is actively weighing restrictions on open-weight AI, including Chinese models like Kimi K3. NVIDIA's letter explicitly defends distillation as a normal part of AI development rather than misappropriation, and its cybersecurity coalition reinforces the same underlying message: do not restrict open models, because defenders need them (Futurum Group, 2026).
What happens next?
Three tests. First, will tools like Microsoft's MDASH, NVIDIA's NOOA, and IBM and Red Hat's Lightwell achieve broader adoption within independent security frameworks? Second, will regulatory discussions in Washington recognize the narrative that open models are defensive assets as an established truth? Third, will Anthropic and OpenAI respond publicly to the Alliance's framing, join later, or continue to sit outside it. The Alliance faces a clear choice: converge on shared technical standards or remain a loose coalition of separately branded member contributions.
Sources and further reading
- NVIDIA — Open Secure AI Alliance
- Linux Foundation — Open Models and Open Weights Are Foundational to Secure AI
- Futurum Group — NVIDIA's Open Secure AI Alliance Bets Open Models Beat Closed Ones on Defense
- CNBC — Nvidia launches AI initiative as OpenAI cyber attack fallout continues
- US Weighs Ban on Chinese Open-Weight AI Models
- Kimi K3: China's Open-Weight Model Overtakes the US
- The Best AI Models of 2026, Ranked
Bottom line
Three tests. First, will tools like Microsoft's MDASH, NVIDIA's NOOA, and IBM and Red Hat's Lightwell achieve broader adoption within independent security frameworks? Second, will regulatory discussions in Washington recognize the narrative that open models are defensive assets as an established truth? Third, will Anthropic and OpenAI respond publicly to the Alliance's framing, join later, or continue to sit outside it. The Alliance faces a clear choice: converge on shared technical standards or remain a loose coalition of separately branded member contributions.
What we still don't know
This is a fast-moving story. We update the post as new facts land — and we'll flag it when we do.
Enjoyed this? Pay it forward
Five people forward this newsletter before they finish their coffee. Make it six.



