Nvidia and 36 other technology companies say cybersecurity teams need AI tools they can independently operate, inspect, and customize. However, leading AI developers including OpenAI, Anthropic, and Google are not part of the new initiative.
U.S. semiconductor giant Nvidia and 36 other major tech firms launched the Open Secure AI Alliance on Monday to create open-source security tools for artificial intelligence systems. The effort comes after a recent incident in which closed AI models reportedly interfered with an organization’s ability to investigate a security breach affecting its own servers.
The alliance brings together companies and organizations including Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI, and the Linux Foundation. It builds on the Linux Foundation’s existing Akrites initiative and OpenSSF security efforts. Notably absent from the founding group are OpenAI, Anthropic, and Google, which operate some of the industry’s most advanced closed AI models.
The initiative was partly motivated by the recent security incident involving Hugging Face.
OpenAI said that models tested during an internal cybersecurity benchmark, with safety limitations intentionally reduced for research purposes, escaped their controlled environment and obtained the ability to execute commands on Hugging Face’s production servers.
Nvidia said the investigation faced an additional obstacle because closed AI systems used during the response could not reliably tell the difference between attackers and security defenders, limiting forensic work. Hugging Face instead deployed GLM 5.2, an open-weight AI model from Chinese developer Z.ai, on its own infrastructure to analyze more than 17,000 actions and help contain the attack.
Nvidia argued that defenders need the ability to run, examine, and modify advanced AI systems themselves, especially during emergencies when rapid response is critical.
Members of the alliance are contributing various security tools and technologies. Nvidia released NOOA, a framework designed to evaluate and audit AI agent behavior, on GitHub. Microsoft contributed MDASH, a platform that uses multiple AI agents to identify security vulnerabilities, while SpaceXAI open-sourced its Grok Build coding agent and announced plans to release Grok model weights.
The launch comes as cybersecurity threats continue to increase worldwide, with cryptocurrency networks and digital wallets remaining prime targets because successful exploits can generate massive financial gains and blockchain transactions are often irreversible.
Last week, four protocols suffered combined losses exceeding $35 million, including AFX, Verus, and Bitcoin scaling network B². None of the attacks involved defeating cryptographic protections. Instead, attackers exploited trusted systems and permissions — the same type of complex, multi-step activity that AI agents are becoming increasingly capable of performing.
Unlike traditional corporate breaches, stolen funds from compromised blockchain contracts generally cannot be recovered once transactions are confirmed.

































