OpenAI, Google, and Anthropic absent from Nvidia-led Open Secure AI Alliance - 30+ companies join security alliance after OpenAI agent breach
Alliance Formation and Goals
Industry leading tech companies have formed an “Open Secure AI Alliance” that will build open-source models, agent harnesses, and cybersecurity tools, arguing that defenders need locally controlled AI after closed-model safeguards reportedly obstructed analysis of the OpenAI-Hugging Face breach. A coalition of over 30 tech industry leaders, including Nvidia, Microsoft, SpaceX, The Linux Foundation, Adobe, and Siemens, has formed the alliance with the aim of building and distributing open source tools for AI safety and security, according to an official Nvidia blog post on Monday.
The Nvidia-led coalition - comprising a mix of infrastructure, cloud computing, cybersecurity, and enterprise software leaders - will serve as a collaborative effort to develop open tools for identifying and patching AI vulnerabilities, sharing security frameworks, and establishing identity verification and audit standards across the AI software stack.
Absence of Major AI Companies
OpenAI, Google, and Anthropic, companies behind proprietary, “closed” AI models, are conspicuously absent from the alliance. Curiously, some of the biggest names in AI are not listed among the members.
Why Open Models Are Essential for Cybersecurity
“The world needs both closed and open models. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense - with no single point of failure,” the announcement reads.
Contributors across the alliance are currently building or offering various tools to create an open defense stack.
The OpenAI-Hugging Face Breach
The initiative was directly galvanized by the OpenAI HuggingFace security incident earlier this month, in which an autonomous OpenAI test agent slipped out of its sandbox and breached the AI startup Hugging Face. During the incident, safety guardrails on several frontier closed models prevented developers from performing critical forensic analysis. Hugging Face eventually had to use GLM-5.2 - an open-weight model from Beijing-based Z.ai - running the model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.
Based on the incident, the alliance contends that being unable to inspect, modify, or run a model locally - impossible in closed systems but doable with open systems - presents a fundamental weakness in relying exclusively on closed AI systems for cyber defense.
The Open Secure AI Alliance therefore aims to give entities access to advanced open models, agent harnesses, and security tools that they can independently deploy and adapt, reducing dependence on any single provider while strengthening defenses across a multi-vendor AI ecosystem. “That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control,” the post says.
Chinese Open-Weight Models
Chinese models such as DeepSeek and the newly released Kimi K3 are open-weight, and are seeing growing adoption, including by U.S. companies, due to their open features. Meanwhile the Trump administration is reportedly gearing up to ban Chinese AI models over security concerns.
Policy Considerations
The alliance acknowledges the potential risks of open source tools but argues that closed systems are not an outright solution. “Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI,” the announcement reads.
Unlike regulators who have voiced concerns over open-source technology, the alliance urges policymakers to treat open-weight models as defensive assets rather than liabilities. It also argues that placing AI development solely in the hands of a few closed providers creates dangerous single points of failure.
“The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them,” the alliance contends.
Founding Members
According to the announcement, “The Open Secure AI Alliance - building on the leadership of the Linux Foundation’s Akrites initiative and OpenSSF community work - will work to remediate and disclose vulnerabilities using open technologies.”
Founding members include:
- NVIDIA
- Dell Technologies
- Synopsys
- Microsoft
- IBM
- Red Hat
- CrowdStrike
- Palo Alto Networks
- Cloudflare
- Hugging Face
- Databricks
- SpaceXAI
- The Linux Foundation
Conspicuously absent from the alliance are OpenAI, Google, and Anthropic, companies behind proprietary, “closed” AI models.
Get Tom's Hardware's best news and in-depth reviews, straight to your inbox. Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.
Etiido Uko is a news contributor for Tom's Hardware covering the latest updates in big tech and the PC industry. He is a mechanical engineer and senior technical writer with over nine years of experience in documentation and reporting. He is deeply passionate about all things engineering and technology, and is an expert in gadgets, manufacturing, robotics, automotive, and aerospace.
Comments
No comments yet. Start the discussion.