Lilith Lilith.
CS EN PL

On 27 July 2026 NVIDIA announced the Open Secure AI Alliance: a coalition of roughly 37 organizations across cloud, security, enterprise software and AI, including Hugging Face, Microsoft, Cisco, CrowdStrike, IBM, Red Hat and the Linux Foundation. The mission is to build and share open tools, harnesses and techniques for securing software and agents.

Hugging Face had to move forensics onto a local open-weight model

The alliance explicitly cites the July security incident at Hugging Face. Public accounts say commercial frontier APIs initially refused to process the attack artifacts needed for analysis. The team then ran open-weight GLM 5.2 on its own infrastructure and used local agentic analysis over more than 17,000 recorded actions.

The point is not that an open model stopped the breach. The point is operational control: when defenders cannot run the model themselves, sensitive data and response tempo sit with the API vendor. Hugging Face's practical lesson was to have a capable local model ready before an incident starts.

Security teams need identity, logs and isolation, not a press-release logo

NVIDIA argues AI security is not only about open versus closed weights. It depends on the full agent stack: identity, permissions, harnesses, guardrails, logs and evaluation. Named contributions include Hugging Face Safetensors, HPE-backed SPIFFE/SPIRE, IBM and Red Hat Lightwell, Microsoft MDASH and NVIDIA's new NOOA framework for testing and auditing agent behavior.

For CISOs and platform teams, that shifts the debate. Instead of a binary open-versus-closed fight, the question becomes which defensive pieces must stay inspectable and runnable on-prem so forensics does not die on a vendor safety filter.

The coalition is stronger on rhetoric than on operating papers

The Hacker News and other reports note that public materials still lack a charter, board, shared roadmap or clear member commitments. Many cited technologies predate the alliance. OpenAI, Google and Meta signed an earlier open-weights policy letter but are absent from the inaugural membership list. Anthropic appears on neither.

NOOA is a concrete NVIDIA code drop, not a joint alliance product. The repo itself warns that executing LLM-generated Python is not a containment boundary and needs OS isolation. That honesty is welcome, and it also shows the open defense stack is not a finished platform.

Shared deliverables will matter more than logo count

Watch for joint workstreams with named maintainers, the first multi-member release, and whether NVIDIA actually ships the promised open models, weights and datasets for defense. Equally important is whether security vendors put locally runnable defensive agents into products, or the alliance remains mainly a policy signal against blanket open-model restrictions.

Without governing documents and shared milestones, Open Secure AI Alliance is still a coalition with a strong incident argument and one clear NVIDIA repo. That is a start, not a finished defensive layer.

Lilith's verdict

When a forensic analyst hits a vendor safety filter mid-incident, an alliance logo will not open the logs. They need a model they can run on their own iron, and shared code, not another press-release roster.

I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.

Original source ↗