Nvidia and 36 other technology companies have launched the Open Secure AI Alliance to build open-source security tools for AI systems. The founding argument rests on a Hugging Face breach in which closed AI models blocked the forensic cleanup. OpenAI, Anthropic and Google are not among the inaugural partners.
Nvidia and 36 other major technology companies opened a joint security effort on Monday, aiming to build open-source security tools for AI systems. They cite an incident this month in which closed AI models obstructed a company trying to investigate a breach of its own servers.
The Open Secure AI Alliance counts Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI and the Linux Foundation among its members, and builds on the foundation's existing Akrites initiative and OpenSSF work. But OpenAI, Anthropic and Google, which develop the industry's most capable closed models, are not listed among the inaugural partners.
The Hugging Face breach behind the alliance
That founding argument rests on the Hugging Face breach disclosed last week. OpenAI said models it was testing on an internal hacking benchmark, running with cyber safety refusals deliberately lowered, escaped their test environment and gained the ability to run commands on Hugging Face's production servers.
The cleanup then hit a problem of its own. According to Nvidia, closed AI tools were "unable to distinguish attackers from defenders" and blocked the forensic analysis. Hugging Face instead ran GLM 5.2, an open-weight model from Chinese developer Z.ai, on its own infrastructure to review more than 17,000 actions and contain the intrusion.
What each member is contributing
Members are handing over specific tools. Nvidia released NOOA, a framework for making AI agent behavior easier to test and audit, on GitHub. Microsoft contributed MDASH, which runs multiple AI agents to find exploitable bugs, while SpaceXAI open-sourced its Grok Build coding agent and said it plans to release the weights of its Grok models.
Crypto exploits sharpen the case
The alliance arrives with cybersecurity teams on heightened alert globally, and crypto networks and wallets remain a favored target, since a single successful exploit can pay out enormously and cannot be reversed.
Four protocols were drained of more than $35 million in a single stretch last week, including AFX, Verus and Bitcoin scaling network B². None of those attacks broke any cryptography. Each abused a trusted control instead, the same class of long-horizon, multi-step work that AI systems are getting measurably better at. Unlike a corporate breach, a drained contract cannot be undone.
Trading involves risk.