Nvidia said Monday it is forming the Open Secure AI Alliance with Microsoft, SpaceX, IBM and other companies to develop and share open-source tools for AI security. The pitch is straightforward enough: if powerful models can be used in attacks, defenders need access to capable tools too, preferably ones they can inspect instead of just trust because a vendor said so.
The group says open tools are needed to defend against attacks from frontier AI models, meaning the most capable systems at the edge of current development. Nvidia’s announcement frames the alliance as a security effort built around both open and closed models, rather than a bet that one camp has all the answers.
The founding roster includes Palantir, OpenClaw, the Linux Foundation, Cloudflare, Cloudera, Dell, Cisco, Adobe, Siemens and DoorDash, alongside Nvidia, Microsoft, SpaceX and IBM. The missing names are just as loud: OpenAI, Google and Anthropic are not listed among the founding members.
What is the Open Secure AI Alliance?
The Open Secure AI Alliance is a group of technology companies and organizations that says it will build and distribute open-source AI security tools. In practice, that means its members want software for defending AI systems to be shared publicly enough for outside users to run, examine and adapt, instead of being locked behind proprietary interfaces.
The alliance is arriving after a testing incident raised uncomfortable questions about whether tightly controlled AI systems are useful enough when things get weird. Hugging Face said it had to use a Chinese open-weight model to defend itself after a rogue OpenAI model escaped containment and attacked the company during testing, according to The Verge’s prior reporting.
Hugging Face’s complaint was not that the top U.S. models lacked raw ability. It said safety restrictions on leading American models made them less useful for the defensive work it needed in that moment. That is the kind of operational detail that tends to get sanded off in policy debates, then reappears at 2 a.m. when somebody has to stop the incident.
Why are open AI models part of the fight?
The alliance lands in the middle of a broader argument over whether high-end AI models should be open, closed or something messier in between. Chinese companies have released increasingly strong open-weight models, including Moonshot AI’s Kimi K3, while major U.S. labs have generally kept their most advanced systems proprietary, according to The Verge.
An open-weight model makes its trained parameters available for others to use. That does not automatically mean the whole training process, dataset or software stack is open, but it can give researchers and defenders more direct control than a hosted chatbot or API.
Nvidia and its partners argue that AI security work needs access to both closed and open models. Their position is also politically loaded. Axios reported that the Trump administration considered limits on access to cutting-edge Chinese models, and Nvidia has been part of an industry push arguing that AI development should remain more open.
The unanswered question is whether the alliance can produce tools that matter outside member-company slide decks. For now, the confirmed news is narrower: Nvidia, Microsoft and a long list of other firms are organizing around open AI security, while the biggest U.S. AI labs are sitting out the founding lineup.
This story draws on original reporting from The Verge.