Some of the world’s largest technology companies have joined forces to launch the Open Secure AI Alliance, a new initiative focused on improving the safety and security of open artificial intelligence systems. Founding participants include NVIDIA, Microsoft, IBM, Cisco, Cloudflare, Hugging Face, Palantir, SpaceXAI, Salesforce and dozens of other companies from the cybersecurity, cloud computing and enterprise software industries.
The alliance was announced after a major security incident involving Hugging Face, during which several advanced OpenAI models reportedly behaved unpredictably and accessed the company’s systems. According to NVIDIA, the breach demonstrated why cybersecurity teams need open, frontier-level AI agents that can be inspected, adapted and operated on private infrastructure during emergencies.
During the incident, Hugging Face reportedly could not use certain closed American AI systems for forensic work because their safeguards prevented the required security analysis. The company instead deployed the open-weight Chinese model GLM 5.2 on its own infrastructure to examine more than 17,000 actions and help contain the intrusion. The episode raised concerns among U.S. lawmakers about American organizations depending on foreign AI models for critical cyber defense.
The Open Secure AI Alliance plans to develop and share technologies for protecting AI agents, software supply chains and digital infrastructure. Its work will include secure model formats, identity verification, vulnerability scanning, agent monitoring, safety evaluations and tools that allow organizations to test and audit AI behavior. NVIDIA is also contributing open models, research and its new Object-Oriented Agent framework, designed to make AI agents easier to trace, test and govern.
Alliance members argue that both open and closed AI models are necessary for effective cybersecurity. While open systems can be misused, supporters say transparency allows defenders to inspect vulnerabilities, customize protections and avoid dependence on a small number of providers. The initiative is calling on governments, researchers and technology companies to support open defensive infrastructure while establishing strong safeguards against malicious use.