Imagine cybersecurity teams around the world sharing AI models, research and defensive tools as quickly as attackers exchange new techniques. NVIDIA has launched the Open Secure AI Alliance, bringing together companies from cloud computing, cybersecurity, enterprise software and open-source development. Its founding participants include Microsoft, IBM, Cisco, CrowdStrike, Cloudflare, Hugging Face, Palantir, Red Hat, Salesforce, SAP, ServiceNow, SpaceXAI and the Linux Foundation.
The alliance argues that defenders need access to both open and closed AI systems. Open tools can be inspected, adapted and deployed within an organisation’s own environment, giving security teams more visibility into how a model works. NVIDIA says it will contribute open models, model weights, datasets and research into agent harnesses. Partners are expected to develop and share techniques for finding vulnerabilities, analysing software behaviour and protecting increasingly autonomous AI agents.
A recent security incident involving OpenAI and Hugging Face helped shape the initiative. During the response, some closed AI services reportedly blocked legitimate forensic activity because their safeguards could not distinguish defenders from attackers. Hugging Face used an open-weight model inside its own systems to examine thousands of actions and help contain the intrusion. The episode highlighted a difficult problem: defensive researchers sometimes need capabilities that resemble the techniques used in an attack.
Open models do not automatically make cybersecurity safe. A capable model can also be modified to weaken safeguards, generate malicious code or help an attacker scale their work. The alliance will therefore need credible testing, access controls and disclosure practices, not simply more powerful tools. It must also show how participating companies will handle disagreements about which models, datasets and defensive capabilities should be released publicly.
For organisations, the announcement signals that AI security is becoming an ecosystem rather than a feature purchased from one vendor. Companies will need to protect the models they deploy, monitor the agents acting on their behalf and verify the software those agents produce. Shared defensive technology could give smaller security teams access to stronger tools, but human oversight will remain essential. The goal is not an AI system that makes every decision alone; it is a faster, more collaborative defence against attacks already moving at machine speed.
