Nvidia has stitched together the biggest security coalition the AI industry has seen — and drawn its most conspicuous fault line to date. On July 27, the chipmaker unveiled the Open Secure AI Alliance, a bloc of industry heavyweights pledging to build shared, open-source tools for defending AI systems. The founding roster reads like a who's who of enterprise computing: Microsoft, IBM, Red Hat, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Hugging Face, Dell, Salesforce, SAP, the Linux Foundation and Elon Musk's SpaceXAI, among others. Missing, pointedly, are the three companies that define the frontier of closed AI: OpenAI, Google and Anthropic.

The absence is the story. Nvidia's pitch is that cybersecurity in the age of autonomous agents cannot depend on a handful of "opaque" model providers, and the alliance's founding manifesto argues the point with unusual bluntness. "Just as open source created a shared foundation for software," the group wrote, "the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy."

A breach that became a rallying cry

The timing is not incidental. The alliance launched just days after a security incident at Hugging Face, the model-hosting hub, in which — according to the company's own July disclosure — an AI agent ran loose and forced defenders into a scramble. Nvidia's account frames it as a parable for the whole open-versus-closed debate: when closed AI tools "unable to distinguish attackers from defenders" blocked forensic analysis, Hugging Face fell back on the open-weight GLM 5.2 model, running it on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.

Nvidia CEO Jensen Huang made the argument personally, posting on X as the alliance went live. "Attackers have frontier AI," Huang wrote. "During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion." The message doubles as a marketing thesis and a warning: if defenders cannot inspect and run advanced models themselves, they are hostage to vendors at the exact moment speed matters most.

Reported membership counts have varied — the Linux Foundation and Nvidia's own blog list 37 inaugural partners, while some outlets, including trade tracker AI Weekly, put the figure as high as 44 as additional names were confirmed in the days after launch. Either way it is a sprawling coalition spanning cloud (Databricks, Snowflake, HPE, NetApp), security (Fortinet, Zscaler, Elastic), enterprise software (ServiceNow, Siemens, Adobe) and a notable cluster of open-model labs, including Mistral, Nous Research, Reflection AI and Thinking Machines Lab.

What the alliance is actually shipping

Crucially, Nvidia arrived with code, not just a mission statement. It open-sourced the NVIDIA Labs Object-Oriented Agent, or NOOA, a research framework now on GitHub that is meant to make agent "harnesses" — the scaffolding that lets a model observe context and take actions — easier to test, trace, audit and govern. The framework reflects a growing consensus that an AI agent is not merely a model but a full stack of identity, permissions, guardrails, logs and evaluation, and that securing the harness matters as much as securing the weights.

Other members brought their own pieces of what the group calls an "open defense stack": HPE is advancing the SPIFFE/SPIRE zero-trust identity standard, Hugging Face offered its Safetensors weight format to the PyTorch Foundation, IBM and Red Hat extended their Lightwell supply-chain signing project, Microsoft contributed its MDASH multi-model scanning harness, and SpaceXAI open-sourced its Grok Build coding agent. The effort builds directly on prior Linux Foundation work, including the Akrites initiative and the OpenSSF community.

The Linux Foundation, a neutral convener for projects run by competitors, endorsed the launch through CEO Jim Zemlin. "Open source became the backbone of modern computing because it let everyone see, improve, and secure the technology they rely on," Zemlin said. "AI deserves the same foundation... the Linux Foundation is glad to support open collaboration on these practices." In its own post, the foundation pointedly praised Nvidia for "contributing working code, and not just thoughts about the need for safety."

Why it matters

Strip away the security framing and the alliance looks like the clearest institutional expression yet of the industry's deepening split over open weights. Nvidia has a commercial stake in a diffuse, multi-vendor ecosystem — the more places models run, the more GPUs it sells — and a strategic interest in preventing a few closed labs from controlling the entire value chain. Rallying 37-plus companies around "openness as a security posture" is a way to convert that interest into a policy movement, complete with a section of the manifesto explicitly lobbying regulators not to impose "blanket restrictions" on open frontier systems.

That the three leading closed-AI labs sat it out sharpens the line. Nvidia has not said whether OpenAI, Google or Anthropic were invited or might join later, and the trio's silence leaves an early hole in Huang's stated vision of open and closed systems defending shared infrastructure together.

What to watch next

The test is whether the alliance becomes a durable standards body or a press-release coalition. Watch for governance details — who steers NOOA and the "open defense stack," and whether the sprawling membership produces interoperable tooling or fragments. Watch, too, for movement from the absent three: any decision by OpenAI, Google or Anthropic to join, publicly decline, or launch a rival closed-security effort will reveal whether the open-versus-closed divide is hardening into permanent camps. And watch policymakers, the audience Nvidia is most plainly courting, as debates over open-weight regulation intensify heading into GTC Berlin this October.

"Attackers have frontier AI. During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion."
- Jensen Huang, CEO, Nvidia
37+
Founding partners
July 27
Launch date
17,000+
Breach actions analyzed
3
Top labs absent