Chipmaker Nvidia and dozens of major tech firms form a new coalition to develop and share open models, tooling and research to safeguard AI software and agents.
Picture a locksmith’s convention where everyone agrees to publish their master keys — not to help burglars, but because they believe the best way to build a safer lock is to let every expert examine it. That, roughly, is the logic behind a sweeping new industry coalition announced in late July 2026.
Nvidia has launched the Open Secure AI Alliance (OSAA), a broad industry initiative built around a single conviction: that AI security gets better when companies build their defences in the open, together, rather than locking tools away inside proprietary platforms. The founding membership spans nearly 40 organisations — reports vary between 37 and around 44 — drawn from cybersecurity, cloud infrastructure, enterprise software, semiconductor design and open source foundations.
What Is the Open Secure AI Alliance?
The alliance’s stated mission is to ensure that defenders everywhere have open, frontier tools they can trust, inspect, modify and deploy on their own infrastructure. That last point matters. Rather than routing security through a handful of closed commercial platforms, OSAA wants organisations to be able to pull the tools apart, look inside them and run them on kit they control.
At the same time, the scope is deliberately broad. OSAA covers the full AI agent stack — identity, permissions, isolation, guardrails, logging, model formats, multi-model scanning and secure coding workflows. In plain terms: every layer of an AI system, from the moment a user sends a request to the moment a model produces an output, is within scope.
Jensen Huang, Nvidia’s chief executive, said: “AI is transforming cyber security, and the best way to defend against AI-enabled threats is with AI — open, inspectable, and built by the community.”
Who Has Signed Up — and Who Hasn’t
The founding members read like a who’s who of enterprise technology. On the cybersecurity side there’s CrowdStrike, Palo Alto Networks and Cloudflare. Cloud and infrastructure is covered by Microsoft, Cisco, Dell Technologies and Hewlett Packard Enterprise. Enterprise software brings in Salesforce, SAP, Adobe, IBM and ServiceNow. AI tooling firms including Hugging Face, Databricks and LangChain are also aboard, alongside semiconductor companies Synopsys and Nvidia itself. The Linux Foundation and its OpenSSF community — which has years of experience in open source software security — provide the organisational backbone.
Each member is contributing something concrete. Nvidia is putting in open models, model weights, data and a new agent harness research framework called NOOA, designed to make AI agents easier to test, trace, audit and govern. Hugging Face is contributing its Safetensors format, which makes the storage of model weights more transparent. Microsoft is bringing MDASH, its multi-model scanning system for vulnerability detection. Other partners are adding zero-trust identity solutions, software supply-chain security tools and secure coding technologies.
But there are conspicuous absences. OpenAI, Google and Anthropic — the three companies behind the most widely used frontier AI models — are not listed among the founding members. That gap has not gone unnoticed. Critics have asked how far OSAA’s standards and tooling can spread if the developers of the most powerful AI systems aren’t in the room.
The Open Versus Closed Debate
This is where the politics get interesting. Some regulators and policy makers have treated powerful, openly available AI models primarily as proliferation risks — tools that bad actors could study and exploit. OSAA’s members take the opposite view: that open, inspectable models are defensive assets, not liabilities, because they allow security teams to find and fix flaws before attackers do.
It’s a debate the software world has had before. Open source operating systems, for example, were once dismissed as security risks. Many are now the backbone of critical infrastructure precisely because thousands of eyes can examine the code.
And the timing is pointed. The alliance was announced against a backdrop of growing concern about AI-enabled cyber attacks and software supply-chain vulnerabilities, following high-profile incidents in which AI systems have been compromised or manipulated. The pressure to act collectively is real.
Yet critics raise a fair counter-point. Publishing detailed model artefacts and open defensive tools could, in theory, give attackers a clearer map of how AI systems work and where their weaknesses lie. How OSAA governs access to its most sensitive contributions will be watched closely.
What the Alliance Is Building
Beyond the politics, there’s practical work under way. OSAA’s technical agenda includes shared open models, scanning frameworks, identity systems, datasets and secure development practices — all tailored specifically to AI agents and the infrastructure they run on. The NOOA agent harness framework from Nvidia is designed to make it easier to test and audit AI agents before they’re deployed in production environments.
Hugging Face’s Safetensors format addresses a specific, unglamorous but important problem: ensuring that the files containing a model’s learned parameters can’t be used to smuggle malicious code. Microsoft’s MDASH system scans across multiple models simultaneously, looking for vulnerabilities that might not show up when you examine each model in isolation.
Short version: this is less about grand announcements and more about building plumbing.
What This Means for Kent Residents
Most Kent residents won’t interact with OSAA directly, but many already rely on software from alliance members — Microsoft 365, Salesforce, Adobe and Cisco products are widely used across Kent’s public sector, NHS services and local businesses. As OSAA’s open security tools are integrated into those commercial platforms over time, the AI-powered services people use day to day could become harder to compromise. For Kent organisations that use AI tools and are subject to UK government guidance on cyber security and responsible AI, the alliance’s emphasis on auditable, open models may also make it easier to demonstrate compliance — though no formal UK endorsement of OSAA has been announced at this stage.
Source: @nvidia
Nvidia Leads Open Secure AI Alliance Backed by Nearly 40 Major Tech Firms Quiz
5 questions