Open source software is a crucial pillar of the global economy. It supports cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts.
Cybersecurity is one of the three biggest beneficiaries of open source software. The Open Secure AI Alliance – building on the leadership of the “Linux Foundation”S Akrites initiative and OpenSSF Community Work – will work to remediate and disclose vulnerabilities using open technologies.
Just as open source created a common foundation for software, the United States and its partners now face a choice when it comes to AI security: whether the defenses that protect our infrastructure are housed in a few opaque systems or based on open models, systems and tools that any defender can study, adapt and deploy.
The world needs both closed and open models. Open models and open systems are critical to cybersecurity because they democratize defense capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement closed border models with customizable, localized controls. Open source enables massively distributed, community-driven and self-controlled defense – without a single point of failure.
Open models, like any powerful technology, can be abused, including through attempts to weaken defenses or repurpose capabilities for cyberattacks. However, these risks are not unique to open systems and must be managed wherever advanced AI is deployed.
The youngest Hugging Face security incident provided a stark reminder: cyber defenders need open, breakthrough agent systems for self-defense. When closed AI tools that couldn’t distinguish attackers from defenders blocked essential forensic analysis, Hugging Face ran the open GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the breach.
This incident highlighted a practical truth: If defenders cannot inspect, adapt, and power their own infrastructure with advanced AI, their ability to respond is limited at the very moment when speed matters most. Companies and countries need defense tools and techniques for open borders so that critical industries can build security systems in a multi-vendor ecosystem and avoid single points of failure.
That is the mission of the Open Secure AI Alliance: to ensure that defenders everywhere have open, groundbreaking tools they can trust and control.
Leaders in cloud computing, cybersecurity, enterprise software, open source foundations and AI research – including NVIDIA, Adobe, cadence, Capital one, Cisco, Cloudera, Cloud flare, knowledge, CrowdStrike, Data blocks, Dell Technologies, DoorDash, Elastic, HPE, Hugging face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous research, OpenClaw, Palantir, Palo Alto Networks, Red hat, reflection AI, Salesforce, SAP, SK Telecom, ServiceNowSiemens, Snowflake, SpacexAI, Table of contents, Thinking Machines Lab and Trends are founding partners of the Open Secure AI Alliance, a movement to develop and share open technologies, techniques and tools to protect software and agents in the age of AI.
Some argue that open models are inherently less secure because they can be abused for cyberattacks or modified to remove guardrails. These risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not stop determined attackers from seeking out or exploiting powerful AI.
The right response is not to deny defenders access to powerful open systems. It’s about combining openness with strong protections, clear rules against malicious misuse, rigorous assessment and rapid remediation. In cybersecurity, the safer path is one that gives more defenders the ability to test, verify and strengthen the systems society relies on.
Defenders need both cross-border models and cross-border models that work together to allow them to choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security requires it.
Table of Contents
Open research improves cybersecurity and AI safety
An AI agent is not just a language model. It is a complex system made up of models, belts and guardrails.
True AI security depends on the entire agent stack – identity, permissions, harnesses, guardrails, protocols and evaluation – and not just on whether the model weights are open or closed. Open harnesses and tools make it easier for many defenders to review, test and improve these controls.
NVIDIA contributes open models, model weights, data and new agent usage research to the Open Secure AI Alliance to accelerate the development of new cybersecurity tools and techniques.
The new open source NVIDIA Labs Object-Oriented Agent (NOOA) Project is now available on GitHub to make advanced AI security features more accessible to agents. The NOOA research framework enables better integration of harnesses into models to facilitate testing, tracking, monitoring, and controlling agent behavior.
Across the alliance, contributors are building an open agent defense stack – from identity and isolation to secure model formats, multi-model scanning, and secure coding workflows.
HPE contributes to this SPIPFE/SPIREwhich creates Zero Trust Identity Framework standards and methodologies that can cryptographically verify AI agents and services to ensure that only authorized workloads communicate and access corporate resources.
Hugging Face offered Safetensors – a secure format for storing AI model weights that provides transparency and guarantees that no code is being executed remotely – for the PyTorch Foundation.
IBM and Red Hat Light fountain extends security across the open source supply chain with digitally signed patches.
Microsoft’s MDASH Multi-model agent scanning system orchestrates specialized AI agents to discover, discuss and prove exploitable bugs.
SpaceXAI has made this open source Grok build Terminal-based AI coding agent to promote trust, transparency and new features and plans to open source the Grok model series weights to support the developer and research communities.
A call to policy makers and regulators
As policymakers and regulators grapple with AI security, it will be critical to recognize open models, systems and security tools as defensive assets rather than liabilities in AI and cybersecurity policy. Blanket restrictions on open AI systems would weaken defense capability and risk concentrating power, dependence and vulnerability in a few closed providers.
Companies and governments should invest in a common open infrastructure for AI defense – datasets, assessment frameworks, attack simulators and red teaming tools – just as previous generations invested in open source software.
The future we should create
The age of AI agents can be one of resilience and shared security. With the right decisions, open, secure AI systems can give defenders the tools they need, increase competition, expand technology leadership, and ensure the security of this exceptional technology is open to all.
This future will not be secured if one assumes that secrecy alone means security. This is ensured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved, and open enough to mobilize the entire defender community.
This future is worth working for – and the Open Secure AI Alliance invites governments, industry and researchers to join together in defending the AI era.
Find out more or share your interest when joining the Open Secure AI Alliance.
https://blogs.nvidia.com/blog/open-secure-ai-alliance/
