Analyst(s): Nick Patience, Fernando Montenegro, Mitch Ashley
Publication Date: July 28, 2026
NVIDIA and more than 35 partners, including Microsoft, IBM, Cisco, CrowdStrike, and Hugging Face, have formed the Open Secure AI Alliance, a coalition building open models, agent harnesses, and security tooling for AI-era cyber defense. We examine what the launch means for the open-versus-closed AI debate, NVIDIA’s platform ambitions, and the policy fight over open-weight models.
What Is Covered in This Article:
- NVIDIA and more than 35 companies, including Microsoft, IBM, CrowdStrike, Cisco, Hugging Face, and Palantir, have formed the Open Secure AI Alliance to build open models, agent harnesses, and security tools for AI cyber defense.
- The Alliance extends the Linux Foundation’s Akrites initiative and OpenSSF’s existing work, and cites the July 2026 Hugging Face security incident, where an open-weight model succeeded where closed tools failed, as its founding case study.
- The launch follows Jensen Huang’s July 24 open letter, signed by roughly 25 companies arguing that open-weight models are essential to US AI leadership.
- Anthropic and OpenAI are absent from both efforts, a gap that sits uneasily next to the Alliance’s argument that openness is the safer security choice.
- The announcement arrives amid a live Washington debate over restricting Chinese open-weight models such as Moonshot AI’s Kimi K3, adding a geopolitical edge to the timing.
The News: NVIDIA and more than 35 companies, including Microsoft, IBM, Cisco, CrowdStrike, Salesforce, SAP, ServiceNow, Palantir, Databricks, Snowflake, Dell Technologies, HPE, Red Hat, Hugging Face and the Linux Foundation, have formed the Open Secure AI Alliance, a coalition dedicated to developing and sharing open models, agent harnesses, and security tooling to help defenders counter AI-enabled cyber threats. The Alliance builds on the Linux Foundation’s Akrites initiative and OpenSSF’s existing vulnerability-remediation work, and cites Hugging Face’s use of the open-weight GLM 5.2 model to contain a recent security incident as the case for why defenders need frontier tools they can run and inspect on their own infrastructure. Founding technical contributions include NVIDIA’s newly open-sourced NVIDIA Labs Object-Oriented Agents (NOOA) agent-harness framework, HPE’s work on SPIFFE/SPIRE identity standards, Hugging Face’s donation of the Safetensors format to the PyTorch Foundation, IBM and Red Hat’s Lightwell supply-chain signing tool, Microsoft’s MDASH agentic security scanner, and SpaceXAI’s open-sourced Grok Build coding agent. The launch follows Jensen Huang’s July 24 open letter – his first-ever post on X – signed by roughly 25 companies arguing that open-weight AI models are essential to preserving US AI leadership.
NVIDIA’s Open Secure AI Alliance Bets Open Models Beat Closed Ones on Defense
Analyst Take: The Open Secure AI Alliance is the clearest sign yet that NVIDIA sees open source not just as a market to compete in, but as a security argument it wants to own. The coalition brings together more than 35 companies around a shared commitment to building open models, agent harnesses, and vulnerability-remediation tools for AI-era cyber defense. It arrives three days after Jensen Huang used his first-ever X post to defend open-weight models as essential to US AI leadership. The two moves resemble a coordinated push, timed for a moment when Washington is actively weighing restrictions on open-weight AI.
The Alliance: Transitioning from Economic Arguments to Cybersecurity Defense
While Huang’s letter made a broad economic case for open-weight models, the Open Secure AI Alliance focuses on a single, more defensible claim: open models and agent harnesses are superior cybersecurity tools. The coalition backs this with the Hugging Face incident, where open-weight models succeeded in investigating a breach while closed tools hindered the process. This concrete evidence is specifically tailored to recruit security teams seeking inspectability and control.
However, the term “inspectability” remains ill-defined. Open weights do not equal open training data, and licenses vary significantly. Buyers must scrutinize these definitions before assuming total transparency. Furthermore, the Hugging Face case highlights machine-speed containment rather than just licensing. The asymmetry is also double-edged: frontier-class open models empower defenders but are equally available to attackers without refusals. Open models should be viewed as defensive assets, not exclusive ones. Finally, the “run it yourself” advantage assumes significant GPU capacity and technical skill, which are capabilities Hugging Face possesses, but most enterprise security teams do not currently have.
The Absence That Defines the Coalition
The most notable fact about the Open Secure AI Alliance may be who is not in it. Anthropic and OpenAI, the two most prominent frontier labs still committed to closed-weight models, are absent from both the Alliance and Huang’s letter. That’s obviously quite significant, given that the Alliance’s central claim is that closed systems cannot be fully trusted for defensive work because defenders cannot inspect or adapt them. Their absence could reflect a genuine disagreement with the open-security thesis, a reluctance to lend credibility to a coalition built around a rival’s platform, or simply that neither was asked to join a group NVIDIA is using to advance its own ecosystem. Any of those readings to us is at least plausible.
There is also a fourth reading: both labs hold a published position that the Alliance does not adopt. Their argument is that weight release is irreversible, and that a frontier capability shipped openly cannot be recalled once misuse becomes apparent. The Alliance’s case rests on inspectability at the defender’s edge. The closed labs’ case rests on revocability at the source. Those are different risk models, and the launch does not resolve the tension between them.
Safety In Numbers Is Part Of The Pitch
There is a buyer-psychology dimension to a coalition this size that is easy to miss. Security teams do not buy tools in isolation; they buy into ecosystems, and they take comfort in moving where their existing stack and their peers are already moving. Our own data bears this out: in Futurum’s 1H2026 Cybersecurity Decision-Makers survey, integration with existing tools was cited by 29.3% of respondents as one of their top three factors when selecting a security vendor (N=929, unweighted), a broadly shared consideration rather than a niche one. A 35-logo roster of the vendors those teams already run, from Microsoft and Cisco to CrowdStrike and IBM, is therefore not only a policy statement but also a fit-and-safety signal aimed squarely at that instinct. The risk for buyers is mistaking breadth of endorsement for proof of the underlying claim, since a long membership list says a great deal about coordination and very little, on its own, about whether open models are actually the safer defensive choice.
Convenient Timing, Given the Kimi K3 Fight
The Alliance’s launch arrives in the middle of a live Washington debate over restricting Chinese open-weight models, including Moonshot AI’s Kimi K3, which the White House has accused of using distillation to copy US models. NVIDIA’s letter explicitly defends distillation as a normal part of AI development rather than misappropriation, and its cybersecurity coalition reinforces the same underlying message: do not restrict open models, because defenders need them. Of course, NVIDIA has a commercial stake here, in that chip volume scales with the breadth of the open ecosystem, closed or open, foreign or domestic, that runs on its hardware. That does not make the security argument wrong, but it is the context for NVIDIA’s advocacy.
Where This Fits the Sovereign AI Picture
The Alliance’s technical contributions – identity standards (SPIFFE/SPIRE), supply-chain signing (Lightwell), safe weight formats (Safetensors), and agent-harness auditability (NOOA, MDASH) – map onto the layers of the AI supply chain that determine who actually controls a deployment, separate from who trained the underlying model. The core argument in our sovereign AI supply-chain work is that sovereignty is decided across identity, harness, and governance layers as much as the model-weights layer, and those are exactly the layers this Alliance is targeting. For companies and governments already wary of single-vendor dependence, an open, auditable agent stack is a more useful sovereignty lever than an open model card.
One consequence deserves attention. Identity standards, signing, and weight formats are software delivery infrastructure, which means the teams that will actually adopt these contributions are platform engineering and release engineering, not the SOC. That relocates the evaluation authority. The Alliance is pitching security teams while shipping artifacts that platform teams will decide whether to run.
The governance question the Alliance raises is narrower than the open-versus-closed question. It is who grants an agent production credentials during an incident, who can revoke them at machine speed, and what the audit record looks like afterward. The question of whether the model is open or closed remains unresolved, and no contribution announced today answers it.
NVIDIA’s Real Play: Owning the Defense Stack, Not Just the Chips
It would be a mistake to read the Open Secure AI Alliance purely as altruism or policy advocacy. NVIDIA is using it to plant a flag in agent-harness standard-setting the way CUDA once planted a flag in compute; contributing NOOA gives NVIDIA a seat at the table for how agent behavior gets tested, traced, and audited across the industry, even as the underlying weights and code are given away freely. That is consistent with NVIDIA’s approach to the AI-RAN sovereign silicon push: cede the commodity layer, own the platform layer beneath it. If the Alliance’s harness and identity standards gain real adoption outside their originating vendors, NVIDIA will have shaped the rules of AI cybersecurity without ever selling a security product outright.
The members beyond NVIDIA have a parallel incentive. For any vendor building agentic features on top of someone else’s frontier model, a capable open-weight alternative is leverage, since it loosens the grip the closed labs hold over both pricing and roadmap. As the cost of AI, and token consumption in particular, climbs with every new agentic workflow, the ability to run inference on a model you can host yourself, at a cost you can predict and control, becomes a strategic advantage rather than a procurement detail. Backing strong open models is, for much of this roster, a way to keep the model layer competitive and cheap so that it does not hold pricing power over the applications built on top of it.
The Open Secure AI Alliance faces three critical tests moving forward. First, will tools such as Microsoft’s MDASH, NVIDIA’s NOOA, and IBM and Red Hat’s Lightwell achieve broader adoption within independent, third-party security frameworks? Second, will regulatory discussions in Washington recognize the narrative that “open models are defensive assets” as an established truth, or continue to treat it as a debated position? And third, will Anthropic and OpenAI have anything to do with it?
What to Watch:
- Whether Anthropic, OpenAI, or other closed-frontier labs respond publicly to the Alliance’s framing, join later, or continue to sit outside it.
- How quickly NVIDIA’s NOOA framework and Microsoft’s MDASH scanner see adoption outside their own ecosystems, versus remaining vendor-specific showcases.
- Whether Washington’s debate over restricting Chinese open-weight models, including Kimi K3, hardens or softens in response to the Alliance’s defensive-asset argument.
- Whether the Alliance converges on shared technical standards or remains a loose coalition of separately branded member contributions.
- How vendors NVIDIA does not control — AMD, Google, and independent open-model labs — position themselves relative to this coalition.
See the announcement, including the list of all signatories to the Open Secure AI Alliance on the NVIDIA blog.
Disclosure: Futurum is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.
Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum as a whole.
Other Insights From Futurum:
So This Is How AIs Attack: Observations From the OpenAI & Hugging Face Incident
At GTC 2026, NVIDIA Stakes Its Claim on Autonomous Agent Infrastructure
The US Just Switched Off Anthropic’s Frontier Model: What Happens Next?
