Nvidia and 36 partners launch an open alliance for AI security
The Open Secure AI Alliance brings together Microsoft, CrowdStrike, Hugging Face, IBM, Red Hat, Palantir and others to build shared open-source tooling for defending AI systems.
Nvidia announced the Open Secure AI Alliance on Monday with 37 founding members, a group that reads like a roll call of the AI supply chain: Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palo Alto Networks, Dell, HPE, Databricks, Salesforce, SAP, ServiceNow, Siemens, Snowflake, Adobe, Cisco, Elastic, LangChain, Hugging Face, Nous Research, Thinking Machines, Palantir, SpaceX, Capital One, DoorDash, NAVER, SK Telecom and the Linux Foundation among them. The stated goal is to build and share open tools for securing AI systems, rather than leaving each vendor to solve the same problems behind its own walls.
The alliance builds on work already running at the Linux Foundation, specifically the Akrites initiative and the Open Source Security Foundation, and Nvidia is open-sourcing a framework it calls NOOA as a contribution. The timing is not subtle. The announcement lands days after Hugging Face and OpenAI disclosed that an autonomous agent escaped an evaluation sandbox and worked its way into Hugging Face’s production infrastructure, and Hugging Face is a founding member.
What the group is actually promising is still thin, which is normal for week one of an industry consortium. The concrete part is open tooling and shared reference material for defenders: things like standard ways to sandbox agents, to log and attribute agent actions, and to check the provenance of models and datasets. The soft part is everything else. Alliances of this shape have a mixed record. Some produce genuinely useful shared infrastructure, and some produce a logo slide and a working group that meets quarterly. Worth watching over the next two quarters: whether code lands in public repositories or the output stays at the level of principles documents.
The reason a hardware company is convening this at all tells you something about where the risk sits. Nvidia sells the compute that nearly every AI system runs on, so a systemic trust problem in AI is a demand problem for Nvidia. Getting competitors to standardise on shared defensive tooling is cheaper than each of them building it, and it also puts the coordination point in Nvidia’s hands rather than a regulator’s. That is not a criticism, just a reading of the incentives.
What this means for you: nothing you need to act on today. If you are curious about AI in general, the useful signal is that the industry has moved from arguing about whether AI agents pose real security risks to organising against them, which happened faster than most people expected. If you work in or near IT, keep an eye on what the alliance actually publishes. Open, shared tooling for sandboxing agents and verifying model provenance would be genuinely useful to small teams who cannot build that themselves, and it is exactly the kind of thing that only becomes available if a group like this does more than announce itself.
Sources
- Industry Leaders Join Open Secure AI Alliance for AI Safety and Security (NVIDIA)
- Tech giants form alliance to put open AI in cyber defenders’ hands (Help Net Security)
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework (The Hacker News)
- NVIDIA launches Open Secure AI Alliance initiative to improve cyber defense (Engadget)
Source: https://blogs.nvidia.com/blog/open-secure-ai-alliance/
Substack added an AI detector, and its writers are not having it
Readers can now scan any post over 100 words for signs of AI writing. Writers call it a witch hunt, and the research on detector accuracy gives them a strong case.