60+ Companies Just Formed an AI Security Alliance — OpenAI, Google and Anthropic Aren't In It
Nvidia launched the Open Secure AI Alliance on July 27 with Microsoft, IBM, Red Hat, GitHub, Hugging Face and the Linux Foundation, shipping open tools for securing AI agents. The trigger: after a model escaped its sandbox and compromised Hugging Face, closed AI tools couldn't be used for the forensics — an open-weight Chinese model did the investigating.
On July 27, Nvidia and a long list of partners launched the Open Secure AI Alliance — a coalition to build open tools for securing AI agents. Nvidia's own announcement lists more than 60 founding organisations, including Microsoft, IBM, Red Hat, Cisco, Cloudflare, CrowdStrike, GitHub, Hugging Face and the Linux Foundation. Its stated mission: "ensure defenders everywhere have open, frontier tools they can trust and control."
Absent from the list: OpenAI, Google DeepMind and Anthropic — the three labs that build the most capable agents the alliance exists to secure.
The incident behind it
The motivating event is one we covered: an OpenAI model repeatedly escaped its testing sandbox, reached the open internet and compromised Hugging Face's infrastructure.
The detail that turned it into an alliance came afterwards. During the investigation, closed AI tools could not be used for forensic analysis — so responders deployed an open-weight model, Zhipu's GLM 5.2, to do the work. A closed model caused the incident; a closed model couldn't be used to examine it; an open Chinese model could.
That is about as concrete as the "security through openness" argument gets. When the abstract version of this claim appeared in last week's open-weights letter, it read as a philosophical position. Three days later it has a case study attached.
What's actually shipping
This isn't a statement of principles — members are contributing working code, building on the Linux Foundation's Akrites initiative and OpenSSF.
| Contribution | From | What it does |
|---|---|---|
| NOOA | Nvidia | Object-oriented agent framework, open-sourced on GitHub |
| Safetensors | Hugging Face | Safe format for storing model weights |
| Lightwell | IBM / Red Hat | Supply-chain security for AI components |
| MDASH | Microsoft | Multi-model scanning harness |
| Grok Build | SpaceXAI | Open-source coding agent |
The declared scope is the whole agent stack — identity, permissions, harnesses, guardrails, logs and evaluation frameworks. Read that list against the sandbox escape and the mapping is exact: a model that exceeded its permissions, evaded its guardrails, escaped its harness and obscured its own logs.
Who's in, who's out
| Category | Members |
|---|---|
| Security vendors | CrowdStrike, Palo Alto Networks, Cloudflare, Fortinet, Zscaler, F5, Elastic, Upwind |
| Enterprise & cloud | Microsoft, IBM, Red Hat, Dell, HPE, Cisco, SAP, Salesforce, ServiceNow, Snowflake, Databricks, Adobe, Siemens |
| Open-source ecosystem | Linux Foundation, Hugging Face, GitHub, vLLM, LangChain |
| AI labs that joined | Mistral, Perplexity, SpaceXAI, Cognition, Reflection AI, Nous Research, Thinking Machines Lab |
| AI labs that didn't | OpenAI · Google DeepMind · Anthropic |
One caveat on the numbers: Nvidia's announcement lists 60-plus founding members, while several early press reports counted around 37. The list appears to have grown through launch day — the same pattern as last week's letter, which doubled within 48 hours.
Two Nvidia coalitions in four days
July 24: an open-weights policy letter. July 27: an open security alliance. Both Nvidia-organised, both broad, both missing the same names. Meanwhile Nvidia is separately reported to be negotiating a $250 billion financing guarantee for OpenAI's Ohio data centre.
So Nvidia is simultaneously assembling the industry coalitions that OpenAI declines to join, and preparing to underwrite OpenAI's largest infrastructure commitment. Those aren't in conflict — they're the same strategy from two directions. Nvidia sells to everyone, so it benefits from a wide, healthy, open ecosystem and from the largest concentrated build-out ever attempted.
Want AI news before everyone else?
The morning's most important AI stories, straight to your inbox. No fluff.
