Nvidia and more than 30 technology, cybersecurity and enterprise software companies launched the Open Secure AI Alliance on Monday, a coalition built around sharing open-source AI models and security tooling among defenders.
The stated mission is to “promote responsible use of and trust in AI”, according to Nvidia.
Founding partners include CrowdStrike, Adobe, Cisco, Nvidia, Microsoft, Palo Alto Networks, IBM, Red Hat, Salesforce, SAP, Databricks, Cloudflare, Hugging Face, Palantir and roughly two dozen others.
The move is also seen as a lobbying effort to head off open-weight AI regulations. Currently, the White House’s June executive order asks AI companies to voluntarily submit frontier models for a pre-release cybersecurity review, and the Commerce Department has already used export controls to restrict access to Anthropic’s most powerful models, the kind of gatekeeping the alliance’s members are explicitly warning against.
Nvidia warned that blanket restrictions on open frontier AI models would leave defenders weaker, not safer, by concentrating dependence on a small number of closed providers.
“As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy,” Nvidia wrote. “Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers.”
Vendor contribution rainbow
Each contributor is bringing a specific technical piece.
Examples include Nvidia’s NOOA, which makes it easier to audit what an AI agent is actually doing. Microsoft’s MDASH has several AI agents cross-check each other’s bug findings. HPE’s SPIFFE/SPIRE work cryptographically verifies that an AI agent is who it claims to be before it’s allowed near enterprise systems.
Hugging Face is donating its Safetensors model-weight format to the PyTorch Foundation. IBM and Red Hat are extending the Lightwell project for automated open-source vulnerability remediation.
Bartley Richardson, CrowdStrike’s chief AI and autonomous systems officer, wrote Monday that the alliance reflects CrowdStrike’s own vulnerability-research work.
CrowdStrike contributions include in-progress techniques to utilize open models specifically as security detectors to safeguard enterprise environments against AI-driven and agentic attacks. Richardson said recent work pairing frontier models (Anthropic’s Mythos Preview and OpenAI TAC) reduced false-positive rates from 80% to approximately 20%.
“The takeaway is clear: the model matters, but the way it is operationalized determines whether it improves defense or creates noise,” he wrote. “That is why open models, open harnesses, and shared tools are important.”
The backdrop
The alliance’s emphasis on machine-tunable open models arrives as the identity- and AI-governance market is projected to grow from $26.8 billion in 2025 to $62.9 billion by 2033, according to Grand View Research. This expansion underscores how much enterprise spending is shifting toward the same AI-driven security tooling the coalition wants built in the open rather than behind closed vendor models. Also, ideally with no regulatory friction.
The Open Secure AI Alliance builds on similar efforts including the Linux Foundation’s Akrites initiative and the existing OpenSSF community.
Akrites launched June 25, 2026, with founding commitments from AWS, Anthropic, Google, Microsoft, IBM, Nvidia and others, and is built around a shared security incident response team and a single coordinated-disclosure process for vulnerabilities in critical open-source projects.
OpenSSF, a Linux Foundation project formed in August 2020 from the merger of two earlier industry security coalitions, states its mission as inspiring and enabling the community to secure the open-source software the world depends on.
You can join or learn more via Nvidia’s website dedicated to the project.