Insider Spotlight
NVIDIA and more than 40 organizations have formed the Open Secure AI Alliance, an industry initiative that aims to develop and share open technologies, techniques and tools for AI safety and cybersecurity.
The alliance builds on the Linux Foundation's Akrites initiative and OpenSSF community efforts to improve vulnerability remediation and disclosure through open technologies.
Why it matters
Open source software already underpins industries ranging from finance and manufacturing to telecommunications and cloud computing.
Alliance members argue that applying the same collaborative approach to AI security can help organizations inspect, adapt and deploy defensive tools while avoiding dependence on a single vendor.
The initiative follows a recent cybersecurity incident involving Hugging Face, where the company said it relied on the open-weight GLM 5.2 model running on its own infrastructure to analyze more than 17,000 actions after closed AI tools were unable to support forensic analysis.
The alliance said the incident demonstrated the importance of giving defenders access to AI systems they can inspect and control during cyber emergencies.
The big picture
The alliance maintains that both closed and open AI models have roles in cybersecurity. While acknowledging that open models can be misused, members argue those risks also exist with proprietary systems and should instead be managed through safeguards, rigorous testing and rapid vulnerability remediation.
NVIDIA is contributing open models, model weights, datasets and agent harness research to the initiative. It also introduced the open source NVIDIA Labs Object-Oriented Agent (NOOA) project on GitHub, a research framework designed to make AI agent behavior easier to test, trace, audit and govern.
By the numbers
Alliance members are also contributing technologies across the AI security stack. HPE is supporting zero-trust identity standards through SPIFFE/SPIRE, Hugging Face is advancing its Safetensors model format, IBM and Red Hat are extending digitally signed software patches through Lightwell, while Microsoft is contributing its MDASH multi-model agentic scanning harness.
SpaceXAI also plans to open source the weights of its Grok AI model family to support developers and researchers. —Vanessa Hidalgo| Ed: Corrie S. Narisma