Nvidia and 36 other companies argue that cybersecurity defenders need access to AI systems they can run and manage themselves. The newly formed group does not include major AI companies such as OpenAI, Anthropic, or Google.
U.S. chipmaker Nvidia and a coalition of 36 technology firms launched the Open Secure AI Alliance on Monday to develop open-source security tools for artificial intelligence systems. The initiative follows a recent incident where closed AI models reportedly complicated efforts to investigate a breach involving a company’s own servers.
The alliance includes Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI, and the Linux Foundation. It expands on existing Linux Foundation projects, including the Akrites initiative and OpenSSF security efforts. However, OpenAI, Anthropic, and Google — which lead the development of some of the most advanced closed AI models — are not among the founding members.
The group’s formation was influenced by the recent security incident involving Hugging Face.
OpenAI said AI models used in an internal hacking benchmark, with cyber safety restrictions intentionally reduced for testing, managed to break out of a controlled environment and gain the ability to execute commands on Hugging Face’s production systems.
Nvidia said the response process encountered another challenge because closed AI tools were unable to accurately differentiate between malicious attackers and security teams conducting defensive analysis. As a result, Hugging Face turned to GLM 5.2, an open-weight model developed by Chinese AI company Z.ai and operated on its own infrastructure, to examine more than 17,000 actions and help contain the breach.
Nvidia said defenders need the ability to inspect, adapt, and deploy advanced AI models on their own systems, particularly when quick action is required during a security incident.
Alliance members are also contributing their own technologies. Nvidia released NOOA, a framework designed to test and audit AI agent behavior, through GitHub. Microsoft contributed MDASH, a system that deploys multiple AI agents to discover exploitable vulnerabilities, while SpaceXAI open-sourced its Grok Build coding agent and said it plans to release the weights of its Grok models.
The alliance launches as cybersecurity teams face growing threats worldwide, with cryptocurrency networks and wallets remaining frequent targets due to the large financial incentives involved and the irreversible nature of blockchain transactions.
Last week, four protocols lost more than $35 million combined in attacks, including AFX, Verus, and Bitcoin scaling network B². None of the incidents involved breaking cryptographic protections. Instead, attackers exploited trusted permissions and control systems — the same type of complex, multi-step operations where AI agents are rapidly improving.
Unlike conventional security breaches, funds stolen from compromised blockchain contracts typically cannot be recovered once transactions are finalized.





