Person in a black leather jacket speaks on stage with a blurred background of a modern office interior.

Nvidia-backed AI security alliance races ahead with open proposals as industry pressure builds

Nvidia-backed OSAA is moving fast on AI security, opening proposals and drawing 120+ companies as it shapes open-model safeguards.

In short

Nvidia’s new Open Secure AI Alliance has rapidly expanded past 120 members and is already floating public proposals for AI security practices. The group is focusing first on incident reporting, blame-free analysis and shared tools for protecting open AI systems.

  • The Open Secure AI Alliance has grown to more than 120 companies within about a week.
  • Its first working group is drafting AI security guidance on incident reporting and post-incident review.
  • Big names such as Adobe, Cisco, Intel, Microsoft and Visa are in, while Anthropic, OpenAI and Google are not yet members.
  • Members are contributing tools and standards that could eventually form a security stack for open AI agents.

The Nvidia-backed Open Secure AI Alliance has moved from launch to action in less than a week, opening public comment on early security proposals and gathering more than 120 companies around a shared effort to make AI systems safer. The rapid rollout matters because the group is trying to shape the rules for securing AI agents and open-weight models before governments or adversaries define those rules first.

Formed in the wake of a broader push for open AI policy, the alliance is already developing practical guidance on incident reporting, post-incident analysis and the exchange of security findings. It is also starting to catalogue open-source tools and components from member companies that could eventually become the foundation for a common security stack for enterprise AI deployments.

The work is unfolding at Black Hat in Las Vegas, one of the cybersecurity industry’s marquee gatherings, where the alliance is using the conference’s momentum to accelerate discussion among researchers, vendors and enterprise buyers. While the proposals are still early-stage and relatively modest, the speed with which the group is organizing suggests a clear ambition: to give open AI a security framework that is ready before the technology spreads even further across business workflows.

What is the Open Secure AI Alliance doing now?

The Open Secure AI Alliance, or OSAA, is already circulating draft ideas for public review and asking industry participants to weigh in. The alliance’s first working group, the Shared AI Findings Exchange, abbreviated as SAFE, is focused on how organizations should handle AI-related security incidents in a way that is transparent, repeatable and useful to the broader ecosystem.

At this stage, the proposals are not sweeping policy statements or technical mandates. Instead, they are practical coordination tools meant to help companies respond to incidents more consistently and with less confusion. That includes defining how to report an incident confidentially, how to notify affected parties and how to perform a review that avoids finger-pointing so the industry can learn from what went wrong.

Those aims may sound incremental, but in a sector where AI security practices remain fragmented, even a shared template can be significant. Enterprises deploying agents and open-weight models are increasingly asking how to verify model behavior, contain misuse and document failures in ways that satisfy both regulators and customers.

Why the SAFE working group matters

SAFE matters because incident handling is one of the weakest links in emerging AI security. If a model is manipulated, a tool chain is compromised or an autonomous agent behaves unexpectedly, the industry still lacks a universal playbook for who reports what, to whom and when. OSAA is trying to close that gap before a major breach forces a rushed response.

The group is also trying to normalize blame-free reviews, a concept borrowed from mature security and safety disciplines. The idea is simple: if organizations can share what happened without turning every disclosure into a legal or reputational fight, then others can avoid repeating the same mistakes. That is especially relevant in AI, where the attack surface is expanding quickly and many failures are subtle rather than dramatic.

The alliance’s position, echoed in its founding letter, is that openness can be a path to stronger AI safety and security rather than a liability.

How big is the alliance already?

The alliance has grown to more than 120 companies in roughly a week, an unusually fast start even by AI-industry standards. That level of early buy-in suggests both urgency and broad commercial interest in building shared security norms around open AI systems, especially as large companies and infrastructure vendors seek to reassure customers that openness does not mean recklessness.

Membership includes a mix of major technology brands and enterprise-facing firms. Among the better-known participants are Adobe, BlackRock, Cisco, Intel, Microsoft and Visa. The alliance also includes Hugging Face, which has become a key distribution and collaboration hub for open model development.

Several members are already contributing specific pieces of technology that could help form a more complete security toolkit. Nvidia, for example, has pointed to its family of open models and its open-source vulnerability scanner Garak. Okta is working on identity-related technology for AI agents. Red Hat is focused on governance. Amazon has contributed its open agent-building tool Strands Agents and Cedar, an authorization language designed to help define access rules.

Who is missing?

Notably absent so far are Anthropic, OpenAI and Google, three influential companies that have all played prominent roles in AI product development and, in some cases, discussions around openness. Their absence does not necessarily signal opposition, but it does show that the alliance does not yet represent the entire AI industry.

That matters because a standards effort gains power when the most important developers and platform providers participate. The alliance can still be meaningful without them, but broader adoption would likely depend on whether those companies eventually decide that being outside the room is riskier than helping define the agenda from within.

What is driving the push for open AI security now?

The push is being driven by a combination of policy uncertainty, security anxiety and the rapid growth of open-weight models. In recent weeks, the U.S. AI community was rattled by reports that the Trump administration was weighing restrictions on Chinese open-weight models. That possibility helped spur the open letter that preceded OSAA, as companies argued that the United States should support open-source AI instead of undermining it.

That letter was championed by Nvidia and signed by more than 200 technology companies. OpenAI and Google signed that letter, even though they have not joined the alliance itself so far. The broader message from the letter was that open ecosystems can strengthen U.S. competitiveness, transparency and resilience, especially if policy is shaped in ways that support domestic innovation rather than constraining it.

For many in the ecosystem, the concern is not only geopolitical competition. It is also the practical reality that open models, once widely distributed, can be adapted by attackers, researchers and enterprises alike. That flexibility is part of what makes open AI valuable, but it also increases the need for shared security tools, monitoring practices and disclosure standards.

Why do open-weight models change the security equation?

Open-weight models change the security equation because they can be downloaded, modified and deployed in environments that the original developer does not fully control. That gives companies more freedom and more visibility, but it also makes misuse harder to track. An enterprise may be able to inspect the model weights, yet still struggle to know whether the model has been altered, integrated unsafely or embedded into a vulnerable agent workflow.

In that context, the alliance’s goal is to turn openness into a managed advantage. Rather than treating open source as a security problem to be suppressed, OSAA is trying to show how the ecosystem can build layered defenses around identity, authorization, model scanning, governance and incident response.

That approach also reflects a broader industry shift. AI security is no longer just about preventing prompt injection or limiting harmful outputs. It now includes protecting agent identities, controlling tool access, monitoring model supply chains and documenting failures when autonomous systems make mistakes at scale.

How members are contributing

Members are not starting from zero. Many are already building pieces of the puzzle in public, and the alliance is effectively trying to map those pieces together. Nvidia’s vulnerability scanner Garak is one example of a tool that can help identify weaknesses in models and applications. Okta’s work on identity aims to address the problem of giving AI agents access to systems without the same accountability as human users. Red Hat’s governance efforts are aimed at clarifying how organizations control and supervise agent behavior. Amazon’s contributions point to how enterprise-grade agent frameworks and policy languages can support safer deployments.

If those efforts converge, enterprise customers may eventually get a clearer blueprint for how to secure AI systems from the start rather than bolt on protections after deployment. That possibility is one reason the alliance is attracting attention beyond the usual open-source crowd.

Milestone What happened Why it matters
Open letter published Nvidia-backed letter urged the White House to support open-source AI Created the political and industry momentum for a coordinated response
OSAA launched The Open Secure AI Alliance formed with broad industry participation Gave the ecosystem a dedicated forum for AI security coordination
SAFE working group formed Members began drafting proposal language for public comment Shows the alliance is already moving from concept to practice
Black Hat discussions Members met in Las Vegas during the cybersecurity conference Connects AI security work with the broader cybersecurity community

How does this compare with other industry alliances?

It compares favorably in speed, if not yet in depth. Many industry coalitions spend months or even years agreeing on scope, membership and governance before producing public artifacts. OSAA, by contrast, has moved quickly from formation to draft proposals and open comment, which signals a strong sense of urgency among its members.

That speed may be partly a function of the moment. AI has entered a phase in which enterprises are no longer just experimenting with chatbots; they are embedding models into workflows, customer support, coding, document processing and agent-based automation. As those uses become operational, security concerns become board-level concerns. Industry groups that can offer practical guidance early may shape procurement decisions, vendor roadmaps and future standards.

Still, an alliance is only as valuable as the quality of its output and the willingness of members to implement it. If OSAA develops a credible framework, it could become a reference point for enterprises, cloud providers and open-model developers. If it stalls, it risks becoming another high-profile announcement that generated headlines but little lasting change.

What does this mean for the U.S. open AI ecosystem?

It means the U.S. open AI ecosystem now has a more organized attempt to define itself on security terms. That is important because the narrative around open models has often been polarized: some argue they are a democratizing force, while others see them as a pathway to easier misuse. OSAA is trying to reframe that debate by suggesting that openness and security can be mutually reinforcing if the industry builds the right guardrails.

For U.S.-based developers and startups, that framing may be especially useful. A common concern has been that restrictive policy or a fragmented security environment could put domestic open-weight efforts at a disadvantage against better-coordinated international rivals. If the alliance can produce practical tools and recommendations, it may help U.S. firms compete not just on model quality, but on trustworthiness and operational maturity.

That argument has already been voiced inside the ecosystem. Leaders from U.S. open-weight AI labs, including Arcee, have suggested that openness itself may be one of the strongest defenses against external threats, whether those threats are technical, commercial or geopolitical. The logic is that broad inspection, community testing and shared infrastructure can expose weaknesses faster than closed systems can hide them.

What comes next?

What comes next is likely more drafting, more public comment and more member contributions as the alliance turns from a newly formed coalition into a functioning standards and coordination body. The pace may slow slightly once the initial excitement fades, but the early trajectory suggests the group wants to publish useful material quickly rather than wait for perfect consensus.

That matters because AI security is evolving faster than formal policy. By the time regulators settle on a framework, the industry may already have adopted de facto practices shaped by groups like OSAA. If that happens, the alliance could end up influencing the real rules of the road for open AI in the U.S., even without the force of law.

Key companies and contributions

One reason the alliance is drawing attention is the range of specific projects members are putting on the table. The list is not exhaustive, but it shows the breadth of the effort.

  • Nvidia: open models and the Garak vulnerability scanner.
  • Okta: identity tools for AI agents.
  • Red Hat: governance work for agent oversight.
  • Amazon: Strands Agents and the Cedar authorization language.
  • Hugging Face: open-model infrastructure and ecosystem support.

Those contributions suggest the alliance may evolve into something more concrete than a policy statement. If the members continue sharing tools, patterns and incident-handling guidance, OSAA could become a practical reference layer for companies building and deploying open AI systems.

Why the alliance’s pace stands out

The alliance’s pace stands out because it shows how quickly the AI industry can mobilize when policy, security and competition intersect. In many sectors, coalition-building is slow. In AI, however, competitive pressure and public scrutiny often force companies to move almost immediately. The result here is a group that formed from a letter, gathered a large membership base, created a working group and started opening proposals to comment in a matter of days.

That kind of speed does not guarantee success. But it does indicate that major companies see a real need for coordination around open AI security, and that they believe waiting is riskier than acting.

For now, the alliance’s biggest achievement may be that it has changed the conversation. Open AI security is no longer just an academic concern or a niche developer issue. It is becoming a mainstream industry project with recognizable names, public drafts and a clear agenda. The next question is whether the alliance can turn that momentum into durable standards that enterprises actually use.

If it can, the group may help define a new baseline for how open AI is built, shared and defended. If it cannot, the open-source ecosystem may still end up inheriting the security lessons, only later and at a higher cost.

Frequently asked questions

What is the Open Secure AI Alliance?

The Open Secure AI Alliance is an industry group led by Nvidia that aims to improve AI security for open models and AI agents. It brings together companies to share tools, develop guidance and create common practices for handling security incidents and model governance.

Why was the alliance formed so quickly?

The alliance formed quickly because companies wanted to respond to rising policy uncertainty and security concerns around open-weight AI models. Pressure over possible U.S. restrictions on Chinese models helped accelerate the push for a coordinated, pro-open-source industry response.

What is SAFE in the OSAA?

SAFE is the alliance’s Shared AI Findings Exchange working group. It is focused on practical AI security procedures such as confidential incident reporting, notification of affected parties and blame-free post-incident analysis so organizations can learn from failures.

Which companies are part of the alliance?

The alliance includes more than 120 companies, among them Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, Hugging Face, Okta, Red Hat and Amazon. Notable names that have not joined yet include Anthropic, OpenAI and Google.

Why does this matter for enterprises?

It matters because enterprises need clearer ways to secure AI agents, manage access, scan models and report incidents. If OSAA succeeds, it could produce shared standards and tools that make open AI deployments safer and easier to trust at scale.

Share this 🚀