News
Nvidia and 30+ Companies Form Open Secure AI Alliance After OpenAI Agent Breach

Nvidia, Microsoft, SpaceX, Palantir, Adobe, CrowdStrike, Dell and Hugging Face have announced a joint alliance to build open AI security tools, a week after an autonomous OpenAI agent broke into Hugging Face.
Contents
Nvidia and more than thirty other technology companies announced on Monday the launch of the Open Secure AI Alliance, a coalition aimed at developing and sharing open tools for securing AI systems. The move comes a week after OpenAI admitted that one of its autonomous agents went rogue and broke into the Hugging Face platform.
Response to the agent breach
The spark for the alliance was a mid-July incident in which OpenAI reported that one of its internal agents had autonomously carried out an unauthorized break-in of Hugging Face's systems. The company described the incident as a case of the agent going rogue, which set off a wave of questions about just how far autonomous AI systems can act beyond their intended scope of authority.
The case reverberated widely across the industry because it showed that threats to open-source infrastructure can now come not only from outside attackers but also from poorly supervised AI systems belonging to the model makers themselves. Nvidia and its partners decided to respond with a joint initiative before similar incidents start repeating on a larger scale.
Who is in the alliance
Dozens of companies from the US and Europe have joined the Open Secure AI Alliance. Founding members named include Nvidia, Microsoft, SpaceX, Palantir, Adobe, CrowdStrike, Dell Technologies and Hugging Face, along with Cisco, Cloudflare, HPE, Red Hat, Salesforce and SAP. It's a mix of chip, cloud, cybersecurity and AI platform providers that normally compete with one another in the market.
Each company is contributing its own tools to the alliance. Nvidia is providing the open-source agentic framework NOOA (Nvidia Labs Object-Oriented Agent), published on GitHub and designed to help control the behavior of AI agents. Microsoft is contributing its MDASH vulnerability-scanning system, and Hugging Face its Safetensors format for securely storing model weights. The goal is a set of tools that organizations can independently inspect, adapt and run without depending on a single vendor.
Open models versus closed ones
Behind the alliance lies a broader dispute over the future of open AI models. Nvidia argues that restricting access to open systems would weaken defensive capabilities and concentrate power, dependence and vulnerability to attack in the hands of a few closed providers. The company stresses that it is precisely open, advanced agentic systems that give defenders tools comparable to those attackers could use.
Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers - Nvidia
This argument fits into a broader campaign by Nvidia and parts of the industry in favor of open model weights, running in parallel with policy discussions in Washington over regulating access to the most powerful AI systems.
A different initiative, same problem
The Open Secure AI Alliance is a separate initiative from the Linux Foundation's Akrites project, launched a month earlier, which focuses more narrowly on coordinated disclosure of vulnerabilities in open-source software and which is being built by, among others, Anthropic, AWS, IBM and Microsoft. Both initiatives, however, are responding to the same phenomenon: AI models have radically sped up the pace at which vulnerabilities in critical software can be discovered, and open source's largely volunteer-driven maintenance structure hasn't been able to keep up.
A month after Akrites launched, its Glasswing project had already uncovered 23,000 vulnerabilities, including 6,000 critical ones, illustrating the scale of the problem the whole industry is now facing.
What it means for companies in Poland
For Polish companies using AI models and agents from major providers, the key takeaway is the precedent itself: even leading AI labs don't fully control the behavior of their autonomous systems, and the fallout from such incidents can hit the entire open-source infrastructure that most corporate software relies on. The open tools the alliance has promised, if they actually reach widespread use, could over time make it easier for security teams to independently verify how AI agents behave in their own environments, rather than relying solely on a vendor's assurances.
For now, the alliance is still at the stage of declarations and initial technology contributions, and its real impact will only become clear once individual tools reach production use outside the founding companies.
