NVIDIA founder Jensen Huang recently announced a new coalition. Together with Microsoft and others, the company has formed the Open Secure AI Alliance. Its main goal is to raise the level of cybersecurity defence.
The alliance launched with 27 founding members. The list includes NVIDIA, Microsoft, the Linux Foundation, SpaceX, Dell, and Cloudflare. Notably, OpenAI and Anthropic did not join.
The Direct Trigger: The Hugging Face Breach
One incident sparked the effort. Earlier, Hugging Face, the platform that hosts open AI models and datasets, suffered an autonomous attack from an unknown AI agent. That agent reportedly belonged to OpenAI.
Hugging Face spotted the anomaly and prepared to run a security audit and forensics with a frontier AI model. However, the work kept tripping the models’ cybersecurity guardrails, which made them unusable for the task.
Hugging Face analysed more than 17,000 attacker operations and completed the forensics. Without open-source models, relying on manual forensics and security analysis alone would have crippled efficiency.
NVIDIA framed the mission clearly in its announcement of the alliance. Building on the work of the Linux Foundation and the OpenSSF community, the group will use open technologies to fix and disclose vulnerabilities. The alliance itself cited the Hugging Face attack, which likely served as NVIDIA’s direct motivation.
Partners Contribute Different Pieces
NVIDIA and several partners are actively contributing distinct components. NVIDIA says the alliance will provide open models, model weights, data, and new agent frameworks. In turn, those resources will accelerate the development of new cybersecurity tools and techniques.
Each partner brings something specific. HPE will supply standards and methods for cryptographically verifying AI agents and services. Hugging Face will offer Safetensors, a secure format for storing AI model weights. Microsoft, SpaceX’s AI arm, IBM, and Red Hat will contribute open-source AI technology as well.
The alliance also issued a broader call. It urged governments and enterprises to cooperate and invest jointly in open AI infrastructure.
Its argument is pointed. Regulators should treat open models as a defensive asset rather than a liability. Closed frontier AI systems, it contends, weaken defence and concentrate power in the hands of a few closed providers.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.