NVIDIA, Palantir, Hugging Face, Microsoft, Adobe, IBM, Red Hat, SpaceX and other partners have launched the Open Secure AI Alliance, a 33-member industry effort aimed at improving the security of open-source software and open-weight AI models. The group said it will develop open techniques and tools for faster vulnerability identification, disclosure, and patching, while building on existing work from the Linux Foundation's Akrites initiative and OpenSSF. Organizers said the push reflects growing concern that defenders need AI systems they can inspect and run on their own infrastructure, citing lessons from the recent Hugging Face security incident.
The alliance is also positioning AI security beyond model behavior alone, emphasizing infrastructure risks such as provenance, identity, deployment accountability, and secure data pipelines. NVIDIA argued that open models and open harnesses can improve transparency, incident response, and shared remediation, and pointed to its open-source NVIDIA Labs Object-Oriented Agent (NOOA) project as a contribution for testing, tracing, auditing, and governance of AI agents. Supporters said the initiative could help establish common standards for securing AI infrastructure, though some observers criticized its largely U.S.-centric membership and called for broader international participation.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
NVIDIA introduced the NVIDIA-labs OO Agents (NOOA) framework as the first named technical contribution associated with the Open Secure AI Alliance. The framework is intended to make AI agent behavior easier to test, trace, audit, and govern, with NVIDIA noting that execution of LLM-generated Python still requires OS-level sandboxing outside the framework.
NVIDIA and more than two dozen other companies announced the formation of the Open Secure AI Alliance to improve the security of open-source software and open-weight AI models. The initiative focuses on vulnerability identification, remediation, disclosure, and broader security standards for open AI infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
13 references tracked. Mallory keeps watching after this page renders.
securitymagazine.com
Open sourcetomshardware.com
Open sourcenextgov.com
Open sourcethehackernews.com
Open sourcephoronix.com
Open sourcehelpnetsecurity.com
Open sourcetheregister.com
Open sourcezdnet.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.