NVIDIA, Microsoft, CrowdStrike Launch Open Secure AI Alliance to Strengthen AI Cybersecurity
NVIDIA, Microsoft, CrowdStrike, and more than 30 leading technology companies have announced the formation of the Open Secure AI Alliance (OSAA), a collaborative initiative focused on developing open-source technologies that enhance artificial intelligence security, transparency, and resilience.
Officially unveiled on July 27, 2026, the alliance aims to accelerate the creation of community-driven AI security tools while addressing the rapidly evolving cyber threats targeting AI models, autonomous agents, and enterprise AI deployments.
The initiative builds upon the Linux Foundation’s Akrites project and the Open Source Security Foundation (OpenSSF), reinforcing industry-wide collaboration to improve vulnerability management, secure AI development, and responsible disclosure practices.
NVIDIA, Microsoft, CrowdStrike Launch Open Secure AI
The alliance emerges at a critical time as organizations increasingly rely on AI-powered systems to automate business operations, software development, cybersecurity, and decision-making.
While AI continues to improve productivity and innovation, it has also introduced new attack surfaces, including prompt injection, autonomous exploitation, model manipulation, supply chain attacks, and unauthorized agent behavior.
The Open Secure AI Alliance seeks to counter these risks by promoting transparent, auditable, and interoperable security frameworks that defenders can inspect, customize, and deploy across diverse environments.
One of the alliance’s central principles is that AI security should not depend solely on proprietary technologies controlled by a limited number of vendors.
Instead, its members argue that open-source security tools provide greater transparency, foster community validation, eliminate single points of failure, and enable organizations to verify how AI systems behave under real-world conditions.
Open defensive technologies also encourage faster vulnerability discovery and remediation while supporting collaborative security research across academia, governments, and private industry.
The importance of open AI security tools was highlighted during a cybersecurity incident involving Hugging Face earlier this year.
During the July 2026 security breach, proprietary AI-based defensive tools reportedly struggled to accurately distinguish legitimate security analysts from malicious attackers, delaying forensic investigations.
To overcome these limitations, Hugging Face deployed its self-hosted open-weight GLM 5.2 model, which analyzed more than 17,000 recorded actions throughout the intrusion.
The open deployment enabled investigators to perform transparent analysis, accelerate incident response, and successfully contain the breach while maintaining complete visibility into the AI system’s reasoning process.
The Open Secure AI Alliance includes an extensive roster of technology leaders spanning cloud computing, cybersecurity, enterprise software, and AI research.
Founding members include NVIDIA, Microsoft, CrowdStrike, Adobe, Cisco, Cloudflare, Databricks, Dell Technologies, Elastic, Hewlett Packard Enterprise (HPE), IBM, Palo Alto Networks, Red Hat, Salesforce, SAP, Snowflake, Hugging Face, and numerous other organizations committed to advancing secure AI infrastructure.
Several members have already contributed significant open-source security technologies to the initiative. NVIDIA introduced its NOOA (NVIDIA Labs Object-Oriented Agent) framework, an open-source project designed to improve traceability, governance, and behavioral auditing for autonomous AI agents operating within complex environments.
Microsoft contributed MDASH, a multi-agent vulnerability assessment harness that coordinates specialized AI agents to identify, validate, and demonstrate exploitable security weaknesses across applications and infrastructure.
HPE expanded its work on SPIFFE and SPIRE, zero-trust identity frameworks that cryptographically authenticate AI agents and services before granting access to sensitive resources.
Additional contributions strengthen software supply chain security and secure model deployment. Hugging Face continues promoting Safetensors, a secure model weight format designed to eliminate remote code execution risks commonly associated with unsafe serialization methods.
IBM and Red Hat introduced Lightwell, a digitally signed software supply chain framework that helps verify the integrity of updates and security patches.
Other contributors are expanding open-source AI development tools, secure evaluation frameworks, and defensive testing environments to improve AI governance across enterprise ecosystems.
Beyond technical innovation, the alliance is also encouraging policymakers to recognize open AI security technologies as defensive assets rather than regulatory liabilities.
Members argue that overly restrictive policies targeting open AI models could unintentionally centralize critical AI capabilities within a handful of closed providers, reducing transparency and limiting independent security research.
Instead, the coalition advocates for collaborative governance, shared datasets, red-teaming frameworks, standardized evaluation methodologies, and open security tooling that enables governments, enterprises, and researchers to collectively strengthen AI resilience.
As artificial intelligence becomes increasingly integrated into critical infrastructure, the Open Secure AI Alliance represents a significant industry effort to ensure cybersecurity evolves alongside the next generation of intelligent systems.
No Comment! Be the first one.