Breaking News
NVIDIA, Microsoft, IBM join Open Secure AI Alliance to advance open-source AI cybersecurity
2026-07-29
A broad coalition of technology companies, cybersecurity vendors and open-source organisations has launched the Open Secure AI Alliance (OSAA) to develop open technologies, tools and frameworks aimed at improving AI security and strengthening cyber defence.
The alliance brings together more than 60 founding partners, including NVIDIA, Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Fortinet, Red Hat, Hugging Face, Salesforce, SAP, Dell Technologies, HPE, GitHub, Nokia, ServiceNow and the Linux Foundation, among others.
Building on the Linux Foundation's Akrites initiative and the Open Source Security Foundation (OpenSSF), the alliance aims to accelerate the development of open AI models, agent frameworks, security tools and vulnerability remediation technologies that organisations can inspect, adapt and deploy within their own environments.
The launch comes amid growing debate over whether advanced AI security capabilities should remain confined to proprietary platforms or be developed through open ecosystems that allow enterprises and governments greater transparency and control.
The alliance brings together more than 60 founding partners, including NVIDIA, Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Fortinet, Red Hat, Hugging Face, Salesforce, SAP, Dell Technologies, HPE, GitHub, Nokia, ServiceNow and the Linux Foundation, among others.
Building on the Linux Foundation's Akrites initiative and the Open Source Security Foundation (OpenSSF), the alliance aims to accelerate the development of open AI models, agent frameworks, security tools and vulnerability remediation technologies that organisations can inspect, adapt and deploy within their own environments.
The launch comes amid growing debate over whether advanced AI security capabilities should remain confined to proprietary platforms or be developed through open ecosystems that allow enterprises and governments greater transparency and control.

The alliance argues that while both proprietary and open AI models have a role to play, open technologies are essential for cybersecurity because they enable defenders to inspect models, customise security controls and avoid dependence on a single AI provider.
The announcement also follows the recent Hugging Face security incident, in which the company used an open-weight AI model running on its own infrastructure to analyse more than 17,000 actions during an investigation after proprietary AI tools were unable to support key forensic analysis. According to the alliance, the incident highlighted the importance of giving defenders access to AI models that can be deployed and audited within enterprise environments.
Among the first open-source contributions announced, NVIDIA has released the NVIDIA Labs Object-Oriented Agent (NOOA) research framework on GitHub to help developers build AI agent harnesses that are easier to test, audit and govern.
Other founding members are contributing technologies across different layers of the AI security stack. HPE is advancing zero-trust identity standards through the SPIFFE/SPIRE framework, Hugging Face is contributing its Safetensors model format to improve AI model security, IBM and Red Hat are extending software supply-chain protection with digitally signed patches, while Microsoft has contributed its MDASH multi-agent vulnerability scanning framework for identifying exploitable software flaws.
The alliance said contributors will collaborate on an open defence stack covering AI agent identity, model isolation, secure model formats, vulnerability scanning, secure coding workflows and evaluation frameworks to improve the security of AI systems.
The group also called on governments and regulators to recognise open AI models and security tooling as defensive assets rather than liabilities. It warned that broad restrictions on open frontier AI systems could weaken cybersecurity by concentrating critical capabilities within a small number of proprietary providers.
As enterprises accelerate the adoption of AI agents and autonomous systems, the Open Secure AI Alliance aims to establish a shared ecosystem of open technologies that enables organisations to secure AI deployments while promoting transparency, interoperability and collaborative innovation across the cybersecurity community.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




