The Open Secure AI Alliance launches: NVIDIA and 37 organizations declare open models a cyber defense asset
NVIDIA and 36 other companies and institutions announced the Open Secure AI Alliance on July 27, 2026. The inaugural partner list includes NAVER, SK Telecom, Microsoft, IBM, Hugging Face and the Linux Foundation. The alliance is a movement to develop and share open technologies, techniques and tools that safeguard software and agents in the age of AI, and it builds on the Linux Foundation's Akrites initiative and OpenSSF community work. ASAP works from NVIDIA's official blog and the Linux Foundation press release as primary sources to lay out what was announced and what remains unanswered.
The starting point was the Hugging Face breach
The single piece of evidence NVIDIA's announcement offers for why this alliance is needed is the recent Hugging Face security incident. According to the post, closed AI tools were unable to distinguish attackers from defenders and blocked essential forensic analysis, so Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.
NVIDIA draws one practical conclusion from that incident. When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most. The post does not ask anyone to choose between open and closed. It states that the world needs both closed and open models, and argues that for cybersecurity specifically, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency, enable defense while protecting data, and add customizable, localized controls.
The 37 named partners, and the names that are missing
The inaugural roster cuts across cloud computing, cybersecurity, enterprise software, open source foundations and AI research. The announcement names NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab and TrendAI.
The character of that list becomes clearer alongside the names it omits. OpenAI, Anthropic, Google and Amazon Web Services do not appear among the 37 organizations named in this announcement. Yet Akrites, the Linux Foundation initiative this alliance says it builds on, launched on June 25, 2026 with 19 founding members that included Amazon Web Services, Anthropic, Google and OpenAI. The two efforts sit under the same foundation's umbrella with different participation. The announcement introduces its roster with "including," so whether the list is exhaustive is not established, and later additions cannot be confirmed from the post either.
The difference in kind between the two initiatives matters as much as the membership. Akrites is closer to an operating body, with a shared Security Incident Response Team and a single standardized Coordinated Vulnerability Disclosure process, and the Linux Foundation grounded its launch in a specific figure: of the thousands of validated open source vulnerabilities surfaced in recent months, fewer than 5% have been patched. The Open Secure AI Alliance, by contrast, describes itself in the announcement as a movement. The first is a procedure; the second reads as a declaration.
Six contributed technologies and the defense points they cover
NVIDIA is contributing open models, model weights, data and new agent harness research. The headline item is the NVIDIA Labs Object-Oriented Agent (NOOA) project, now open source on GitHub, a research framework that helps harnesses integrate with models so agent behavior is easier to test, trace, audit and govern.
The other five cover distinct defense points. HPE contributes to SPIFFE/SPIRE, zero-trust identity framework standards that cryptographically verify AI agents and services so only authorized workloads communicate and access enterprise resources. Hugging Face has offered Safetensors, a safe format for storing model weights with guarantees of no remote code execution, to the PyTorch Foundation. IBM and Red Hat's Lightwell extends security across the open source supply chain with digitally signed patches. Microsoft's MDASH, a multi-model agentic scanning harness, orchestrates specialized AI agents to discover, debate and prove exploitable bugs. SpacexAI has open sourced Grok Build, a terminal-based AI coding agent, and plans to open source the weights of the Grok line of models for the developer and research communities.
The argument moved from model weights to the agent stack
The most consequential line in this announcement is a definition rather than a roster. The post states that an AI agent is not just a language model but a complex system built from models, harnesses and guardrails, and that real safety and security depend on the full agent stack of identity, permissions, harnesses, guardrails, logs and evaluation rather than on whether model weights are open or closed.
Why that reframing matters shows up in the contribution list itself. Only two of the six contributions concern model weights; the rest are identity verification, a storage format, patch signing, scanning orchestration and a coding agent. For two years the open-versus-closed debate has largely run on the single axis of whether weights are published, and this roster embeds an observation that the axis explains very little of the actual attack surface. If you cannot verify what an agent accessed and under which permissions, incident response stalls at the same point whether the model is open or closed.
For teams evaluating deployments, the practical consequence is a change in the first question. It shifts from which model to adopt toward what will verify agent identity, logs and permission boundaries. That mature standards like Safetensors and SPIFFE/SPIRE were named as the alliance's first building blocks points in the same direction.
What NAVER and SK Telecom joining signals
Two Korean companies appearing on an inaugural roster of this kind is worth recording on its own. NAVER and SK Telecom are the two Korean names in the list, and both sit at the center of the domestic sovereign AI conversation. The announcement does not state what any individual partner contributes, so their specific roles are not established.
The direction of the participation is still legible. The concepts the post returns to are localized and sovereign control, and avoiding single points of failure across a multi-vendor ecosystem. For a telecom operator and a platform company that must handle domestic data on domestic infrastructure, that requirement is a regulatory condition rather than an abstract principle. Korean operators engaging international AI governance on the axis of defensive tooling rather than frontier model competition also fits the structure of a domestic industry stronger in infrastructure and applications than in model development.
The policy ask targets how regulation gets written
The final two sections of NVIDIA's announcement are addressed to policymakers and regulators rather than to engineers. NVIDIA asks policymakers and regulators to recognize open models, harnesses and security tooling as defensive assets rather than liabilities, and argues that blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers. The post also proposes that companies and governments invest in shared open infrastructure for AI defense, including datasets, evaluation frameworks, attack simulators and red-teaming tools.
That ask reads more accurately alongside the interests behind it. Lighter regulation of open models directly benefits vendors that ship open weights and the hardware suppliers whose customers want to run those models on their own infrastructure. The soundness of an argument and the interests of the party making it are separate questions, and both can hold at once: the Hugging Face incident is concrete support for the argument, and the argument also favors a particular business structure.
What the announcement does not contain: governance, deliverables, dates
As much goes unstated in this launch as is stated. NVIDIA's post contains no description of the alliance's decision-making structure, membership requirements, planned specifications or benchmarks, or any schedule for delivering them. That contrasts with Akrites, which launched with a concrete operating apparatus in the form of a SIRT and a CVD process.
The division of labor is an open question as well. The post says only that the alliance will remediate and disclose vulnerabilities using open technologies while building on Akrites leadership and OpenSSF community work, without explaining how that differs from what Akrites already does with its disclosure process. Of the six contributed technologies, NOOA is roughly the only one arriving with this announcement; SPIFFE/SPIRE, Safetensors and Lightwell are existing projects repositioned under a new umbrella.
Two tests, rather than partner count, will likely determine how this launch is judged. The first is whether joint deliverables appear, meaning a specification or evaluation tool built by multiple members rather than a list of each company's existing projects. The second is whether the frontier labs absent from the roster join. An alliance claiming to set standards for cyber defense that stays limited to the open-weights camp and hardware suppliers reads less as an industry standard than as one camp's position paper. The next checkpoint is the first joint deliverable, not the next partner announcement.
Source: NVIDIA official blog, "Industry Leaders Unite in Open Secure AI Alliance for AI Safety and Security" (July 27, 2026), and Linux Foundation press release, "Linux Foundation and Industry Leaders Launch Akrites" (June 25, 2026), compiled by ASAP.

AI & tech,
read in depth
Beyond the headlines — into the context and the structure
AGI Soon As Possible · asapai.co.kr