Skip to main content
The Quantum Dispatch
Back to Home
Cover illustration for Open Secure AI Alliance Unites 40+ Firms on Defense

Open Secure AI Alliance Unites 40+ Firms on Defense

NVIDIA, Microsoft, IBM and 40+ others launched the Open Secure AI Alliance on July 27, pooling five open-source projects to defend AI agents.

Kai Aegis
Kai AegisJul 28, 20265 min read

Forty Companies Decided Defensive AI Should Be Inspectable

On July 27, 2026, NVIDIA and the Linux Foundation announced the Open Secure AI Alliance — a coalition of more than 40 organizations committing to build the security layer for AI agents in the open. Red Hat, IBM, Microsoft, Hugging Face, Cloudflare, Cisco, CrowdStrike, HPE, Salesforce, SAP, Adobe, Dell Technologies, Elastic, Palo Alto Networks, Siemens and Snowflake are among the founding participants. The organizing idea is refreshingly plain: the models and tooling that defend software should not live behind a vendor's closed door, because defenders need to audit what they deploy.

  • The Open Secure AI Alliance launched July 27, 2026 with 40+ member organizations
  • It builds on the Linux Foundation's Akrites project and the OpenSSF community
  • Five founding technologies are being contributed, including NVIDIA's NOOA agent framework and Hugging Face's Safetensors format
  • HPE is contributing SPIFFE and SPIRE extensions for cryptographic workload identity

What Is the Open Secure AI Alliance Actually Building?

Rather than starting a new standards body from scratch, the alliance is anchoring itself on work that already exists. It builds on the Linux Foundation's Akrites project, which we covered when it launched in June, and on the long-running OpenSSF community. Akrites contributes the coordination machinery — a shared Security Incident Response Team and a coordinated disclosure framework — while the alliance layers a much wider industry membership on top of it.

The practical output is a set of donated components rather than a white paper. NVIDIA is open-sourcing NOOA (the NVIDIA Labs Object-Oriented Agent), a research framework designed to make the seam between a model and its agent harness easier to test, trace, audit and govern. Hugging Face is contributing Safetensors, the model-weight storage format that removes arbitrary code execution from the loading path. HPE is bringing SPIFFE and SPIRE extensions, which give workloads and services cryptographically verifiable identities. Microsoft is contributing its MDASH scanning harness, and IBM and Red Hat are contributing the Lightwell supply-chain security project.

Why Does Open Defensive AI Matter Right Now?

Because the asymmetry has shifted. A capable model can now read a codebase and surface exploitable weaknesses in minutes — work that used to take a skilled researcher weeks. That capability cuts both ways, and the alliance's argument is that the defensive half of it cannot be a black box. If a security team cannot inspect the model that triages its incidents, it cannot explain its own decisions, tune its own false-positive rate, or run the tool in an air-gapped environment.

There is an operational argument too. Open weights can be run locally, which matters enormously during an active incident when a responder needs a model that will not refuse, rate-limit, or phone home. Members have pointed to exactly that scenario — a response team switching to a locally-run open-weight model to work through an intrusion — as the concrete reason transparency belongs in the incident-response toolchain.

How This Fits the Broader Agentic Security Push

The alliance arrives in a year when agent security has gone from a research topic to a procurement checklist item. We have tracked the same trend through Google's agentic AI threat intelligence work and through the practical lessons on agent sandbox design that came out of recent research. What the Open Secure AI Alliance adds is scale and a shared home for the code, so that identity, provenance, scanning and disclosure stop being reimplemented separately inside each vendor's stack.

What to Watch Next

The interesting signals over the next few months are governance and throughput: how the alliance handles technical decisions across 40+ members, how quickly the five founding projects land under common governance, and whether additional model labs contribute defensive weights. For teams building on agents today, the immediate value is simpler — NOOA, Safetensors, SPIFFE/SPIRE, MDASH and Lightwell are components you can evaluate now, and they are converging under one roof. More on this beat in our AI security coverage.

Sources: NVIDIA Blog — July 27, 2026; Cyber Press — July 27, 2026; Linuxiac — July 27, 2026; Phoronix — July 27, 2026.

More Ai Security Stories

AI Security

Druva AI Resilience Adds Backup for Claude Code Work

Druva launched AI Resilience on July 21, adding backup, rollback, and governance for Claude Code projects and Microsoft Copilot activity logs.

Kai Aegis
Kai AegisJul 28, 20266 min read
AI Security

Snowpick Open-Source Scanner Checks ServiceNow Exposure

Bishop Fox released Snowpick, a free Go tool that tests your own ServiceNow portal for unauthenticated data exposure across 26 table checks.

Kai Aegis
Kai AegisJul 27, 20265 min read
AI Security

Google Threat Intelligence Ships Agentic AI Defense

Google Threat Intelligence moved its agentic AI to general availability, automating threat hunting, triage, and malware analysis with cited results.

Kai Aegis
Kai AegisJul 26, 20264 min read