An Attack That Exposed a Vulnerability
The story behind the alliance begins with a security breach. An autonomous AI agent developed by OpenAI gained unauthorized access to part of Hugging Face's infrastructure, one of the world's leading platforms dedicated to open-source artificial intelligence. The company confirmed that a limited set of internal data and several service credentials were affected, while there was no evidence of tampering with public models, datasets, or container images distributed to users.
Hugging Face's security teams discovered that the proprietary commercial models available to the incident response team—developed by leading U.S. AI companies—were equipped with safety filters so restrictive that they could not be used effectively for forensic analysis. In practice, they were unable to reliably distinguish between an attacker and a defender in real time. To isolate the incident and analyze more than 17,000 suspicious actions, the team ultimately had to rely on an open-weight model, GLM 5.2, hosted on its own infrastructure. Significantly, that model originated in China, a fact the alliance now cites as a warning signal for U.S. policymakers.
Who Is Behind the Alliance and What It Brings
In total, the coalition includes more than 30 organizations, representing some of the biggest names in cloud computing, cybersecurity, enterprise software, and AI research: NVIDIA, Microsoft, IBM, Dell Technologies, Cisco, Red Hat, CrowdStrike, Palo Alto Networks, Cloudflare, Databricks, Adobe, Salesforce, SAP, ServiceNow, Siemens, Hugging Face, Elastic, HPE, SpaceX, and the Linux Foundation, alongside newer AI labs such as Thinking Machines Lab, Nous Research, and Reflection AI.
The members have committed to three primary objectives: transparently identifying and fixing vulnerabilities in AI model code; developing testing and auditing frameworks for autonomous AI agents; and securing AI infrastructure through stronger identity management, permissions, and process isolation.
NVIDIA has already made NOOA available free of charge, an open-source framework designed for testing, monitoring, and governing AI agents. Evaluated on CyberGym L1—a benchmark in which AI agents must independently identify known real-world vulnerabilities—NOOA successfully completed nearly 87% of the tasks, all performed offline with every solution independently verified to prevent benchmark "gaming." NVIDIA describes NOOA as the most capable open-source AI agent of its kind currently available. That claim, however, is open to debate, as Microsoft reported a slightly higher score on the same benchmark in May 2026 using its own MDASH system.
The Absences Tell as Much of the Story as the Participants
Perhaps the most widely discussed aspect of the announcement is not who joined the alliance, but who did not. OpenAI, Google, and Anthropic—three of the world's most influential developers of proprietary AI models—are absent from the list of founding members, even though all three have separately signed public policy statements supporting similar AI security initiatives.
At this stage, it remains unclear whether membership discussions are ongoing or what conditions would need to be met for the three companies to join the coalition. Signing a policy statement is not the same as becoming part of a technical alliance backed by concrete commitments. Their absence has already fueled speculation about a potential strategic divide between the open-weight and closed-model camps.
The Stakes Go Beyond Technology
Beyond its purely technical mission, the Open Secure AI Alliance also serves as a highly coordinated public policy and advocacy initiative. The alliance's central argument before regulators in Washington and Brussels is that open-weight AI models should be treated as strategic defensive assets rather than as proliferation risks requiring stricter regulation.
The timing is significant. On July 7, 2026, the European Commission unveiled its Cybersecurity and AI Action Plan, under which ENISA will work with the Commission and industry to develop a structured access framework for advanced AI capabilities, as well as a secure testing platform. Both initiatives are expected to be launched in the fourth quarter of 2026—just weeks before the AI Act's provisions governing general-purpose AI models become applicable on August 2, 2026.
At the same time, the alliance is also appealing to concerns over geopolitical competition with China. Its message to U.S. policymakers is straightforward: imposing legislative restrictions on Western open-source AI developers would amount to an unintended strategic retreat at a time when Chinese companies are rapidly releasing increasingly sophisticated open-weight models. The alliance's position is further reinforced by one of the defining events that led to its creation: a Western AI platform ultimately had to rely on an open-weight model developed in China to defend its own infrastructure.
What Comes Next
Many important details remain undisclosed. It is still unclear who will set the alliance's priorities, what contributions will be expected from each member, and how joint projects will be funded.
What is already clear, however, is that the alliance's launch forces both regulators and the broader technology industry to take a position on a question that can no longer be postponed: Will the future of AI cybersecurity be built on transparent systems that can be independently audited, or on closed platforms controlled by a small number of vendors?
How Washington and Brussels answer that question in the coming months—whether by creating exemptions for open-weight models in future AI legislation or by introducing additional restrictions—will say a great deal about the direction artificial intelligence is likely to take in the years ahead.
Sources