Nvidia has brought Microsoft, Hugging Face, IBM, Cisco, CrowdStrike and more than 30 other organisations into the Open Secure AI Alliance, a new industry initiative focused on openly developed tools for securing AI agents, software and critical digital infrastructure.
The alliance arrives after Hugging Face disclosed an autonomous, AI-driven intrusion into part of its production environment. The incident became a practical example of Nvidia’s argument that cyber defenders require adaptable models and security tools they can inspect, run locally and control.
TL;DR
- Nvidia launched the Open Secure AI Alliance with 36 other inaugural partners.
- Members will develop and share open AI security models, harnesses, data and defensive tools.
- The initiative follows an AI-driven breach at Hugging Face involving more than 17,000 recorded actions.
- OpenAI, Google and Anthropic were not named as inaugural alliance members.
What Will The Open Secure AI Alliance Build?
The alliance includes companies spanning chips, cloud computing, cybersecurity, enterprise software and open-source development. Its 37 inaugural partners include Nvidia, Microsoft, Adobe, Cisco, Cloudflare, CrowdStrike, Dell Technologies, HPE, Hugging Face, IBM, the Linux Foundation, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens and Snowflake.
Nvidia said the coalition will create an open defence stack for AI agents, covering identity, isolation, safe model formats, multi-model scanning and secure coding workflows. Nvidia is contributing open models, model weights, data and research into agent harnesses, which are the systems connecting models with tools, permissions, guardrails and logs.
The company also released Nvidia Labs Object-Oriented Agent, or NOOA, as an open-source research framework. Nvidia said NOOA is designed to make agent behaviour easier to test, trace, audit and govern.
Other members are contributing existing security projects. Microsoft’s MDASH system coordinates specialised AI agents to discover and validate exploitable software flaws. HPE is supporting zero-trust identity standards for agents, while Hugging Face has offered its Safetensors model-storage format to the PyTorch Foundation.
“Open development produces stronger defense,” said Justin Boitano, Nvidia’s Vice President of Enterprise AI. Nvidia’s announcement also argued that the world needs both closed and open models, rather than treating the two approaches as mutually exclusive.
Topics For More Insights
Why Did The Hugging Face Incident Matter?
Hugging Face said an autonomous agent framework carried out thousands of actions across short-lived sandboxes after exploiting two code-execution paths in its dataset-processing pipeline. The attacker gained node-level access, harvested credentials and moved across several internal clusters.
The company analysed more than 17,000 recorded events to reconstruct the intrusion. However, it said commercial frontier models initially blocked the forensic requests because their safety systems could not distinguish defensive analysis from malicious hacking activity.
Hugging Face then ran Z.ai’s open-weight GLM 5.2 model on its own infrastructure. It said this helped complete work in hours that would normally take days, while keeping attack data and credentials inside its environment.
The alliance is using that experience to argue against blanket restrictions on open frontier systems. Nvidia acknowledged that open models can be misused, but said similar risks exist wherever powerful AI is deployed and should be addressed through safeguards, evaluation and rapid remediation.
OpenAI, Google and Anthropic were not listed among the alliance’s inaugural partners. Their absence highlights the continuing debate over whether access to advanced model weights strengthens independent security research or creates risks that cannot be reversed after release.




















