[Edaily Reporter Han Kwangbeom ] NVIDIA announced on the 27th that it has launched the “Open Secure AI Alliance,” an open consortium aimed at strengthening artificial intelligence (AI) security and safety, in collaboration with global IT and cybersecurity leaders, including Korean companies such as Naver (NAVER(035420)) and SKTelecom(017670).
This alliance was established based on the achievements of the Akrites initiative, led by the Linux Foundation, and the OpenSSF community. Rather than relying on AI defense systems within opaque, closed systems operated by a handful of companies, the alliance aims to build a large-scale, distributed cyber defense network without single points of failure by utilizing open models, harnesses, and tools that anyone can research, adapt, and deploy.
NVIDIA cited the recent Hugging Face security incident as a prime example illustrating the need for open systems. Hugging Face explained that when essential forensic analysis was blocked by the safety filters of a closed-source AI tool—which could not distinguish between attackers and defenders—the company ran the open-weight model “GLM 5.2” on its own infrastructure to analyze over 17,000 instances of activity and contain the intrusion. The analysis suggests that if defenders cannot directly control and inspect advanced AI on their own infrastructure, their ability to respond at critical moments may be limited.
Major global tech companies and research institutions, including NVIDIA, Microsoft (MS), Adobe, Cisco, CrowdStrike, Databricks, HPE, IBM, Palantir, Palo Alto Networks, Red Hat, Salesforce, and SpaceX AI, have joined this consortium as founding members. Among Korean companies, Naver and SKTelecom are participating as partners and plan to collaborate on the development of agent protection and defense technologies.
The alliance’s participating companies plan to build an open defense stack that includes AI agent identity, isolation, secure model formats, multi-model scanning, and secure coding workflows.
NVIDIA has released “NVIDIA Labs Object-Oriented Agent (NOOA),” a research framework designed to assist in testing, tracking, auditing, and managing agent behavior, on GitHub, and has stated that it will continue to contribute to open-source model and data research.
Additionally, HPE explained that it is supporting the cryptographic verification of AI agents through the “SPIFFE/SPIRE” project, a zero-trust identity standard, while Hugging Face has provided the “Safetensors” model storage format—designed to mitigate remote code execution risks—to the PyTorch Foundation.
IBM and Red Hat are expanding supply chain security with “Lightwell,” a digital signature-based patching solution, while Microsoft plans to utilize “MDASH,” a multi-model Agent AI scanning harness for bug detection and verification. SpaceX AI is also reportedly planning to open-source “Grok Build,” a terminal-based AI coding agent, along with the Grok model weights.
NVIDIA pointed out that blanket regulations on open frontier AI systems could weaken defensive capabilities and increase dependence on specific closed-source providers, urging policymakers, businesses, and governments to actively invest in open infrastructure.
NVIDIA stated, “We must not assume that AI safety can be ensured through secrecy alone,” adding, “We hope that governments, industry, and researchers around the world will work together to safeguard the AI era by building systems that are robust enough to withstand scrutiny and open enough to unite the entire community of defenders.”