2026-07-27 · ← Radar
Nvidia builds an open AI defense coalition without the three biggest labs
Nvidia has formed the Open Secure AI Alliance with dozens of partners spanning cloud infrastructure, cybersecurity, enterprise software and open source. The coalition plans to develop and share tools that let defenders inspect, audit and operate agents under their own control.
Open defense now has an industry coalition
Initial partners include Microsoft, IBM, Cloudflare, CrowdStrike, Hugging Face, the Linux Foundation, Palantir, Red Hat, Salesforce, SAP, Siemens and SpaceXAI. Nvidia says it will contribute models, weights, data and research on agent harnesses. It has also released NOOA, a framework intended to make agent behavior easier to test, trace, audit and govern.
The alliance grounds its case in the Hugging Face security incident. Nvidia says the company ran the open weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions after closed tools blocked necessary forensic work. The Verge notes that OpenAI, Google and Anthropic are absent from the initial membership.
Security is moving from model weights to identity, logs and permissions
The most useful part of the announcement sits beyond the familiar open versus closed model argument. The alliance describes defense as an agent stack covering identity, isolation, permissions, logs, guardrails, evals and safe model formats. For enterprise teams, that is a more practical frame than another broad promise of a safe model.
The coalition also connects vendors selling chips, cloud capacity, security software and agent infrastructure. Shared standards could reduce integration costs and limit a customer's dependence on a single closed model provider.
A long membership list still substitutes for operational results
The founding roster is broad, but the announcement provides no delivery schedule, shared evals or binding vulnerability disclosure rules. Most named projects remain governed by individual members. An alliance logo does not demonstrate that their identity systems, scanners and signed patches will work together during one incident.
Nvidia also benefits commercially from a more open ecosystem. More models and agents running on customer infrastructure can increase demand for its hardware and software. The security argument may be sound while still serving the company making it.
A shared attack and a shared fix will reveal the real value
Public artifacts will matter: shared datasets, reproducible evals, interoperable identities and disclosed patches with measurable response times. A stronger signal would be a realistic incident handled across clouds and models without teams manually stitching every component together.
Watch whether OpenAI, Google or Anthropic eventually joins. Their participation could turn the coalition into a common security layer. Continued absence would show that the industry is also dividing over who lets defenders inspect the machinery.
Lilith's verdict
When an agent starts deleting data, defenders will not care how many logos appeared in the announcement. They need to open the logs, stop the process and ship a signed fix across clouds before another file disappears.
I keep the external link at the end. First, a concise explanation here — no hunting across someone else's site.
Original source ↗ ↗