AERIOXFLUX
Tech & Culture
Tech & Culture · cybersecurity

Nvidia's AI Security Alliance Has 50 Members and Two Holes

The Open Secure AI Alliance launched with more than 50 founding partners and a pile of donated tooling — and without OpenAI, Anthropic, Google, or Amazon.

Flux Desk·2026-07-29·5 min read

Nvidia announced the Open Secure AI Alliance on July 27, and the founding roster is the story. More than 50 organizations signed on at launch — Adobe, Box, Cadence, Capital One, Cisco, Cloudflare, Cognition, CrowdStrike, Crusoe, Databricks, Dell, DoorDash, Elastic, F5, Fortinet, G42, GitHub, HPE, Hugging Face, IBM, LangChain, Microsoft, Mistral, NAVER, NetApp, Nokia, Nous Research, Palantir, Palo Alto Networks, Perplexity, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, Uber, vLLM, Zscaler, and more.

Read that list again for who is not on it. OpenAI is absent. Anthropic is absent. So are Google and Amazon — leaving Microsoft as the only one of the three big American clouds at the table.

An alliance about securing AI systems, launched with essentially every major security vendor, every major open-weight lab, and one hyperscaler — but neither of the two labs whose models sit inside the largest share of enterprise deployments.

What's actually being contributed

This is not a press-release coalition with a whitepaper and a logo wall. Members showed up with code.

Nvidia open-sourced NOOA — NVIDIA Labs Object-Oriented Agent — a research framework on GitHub aimed at agent harnesses. Its pitch is making safety capabilities accessible at the harness layer rather than the model layer: better integration between the harness and the model for testing, tracing, auditing, and governance. That is a meaningful choice of altitude. Most AI-safety tooling targets model weights or model outputs. NOOA targets the scaffolding that actually decides what a model is allowed to touch.

HPE contributed SPIFFE/SPIRE, the zero-trust workload identity framework. If agents are going to call tools across organizational boundaries — which is precisely what the new MCP specification just made cheap — every one of them needs a cryptographic identity that isn't an API key in an environment variable. SPIFFE is the most mature answer that exists.

Hugging Face brought Safetensors, the format that made loading model weights stop being arbitrary code execution. IBM and Red Hat contributed Lightwell, a system for signed patches across the open-source supply chain. Microsoft contributed MDASH, a multi-model agentic scanning harness. SpaceXAI contributed Grok Build, its open-source coding agent, with model weight releases stated as planned.

The alliance sits under the Linux Foundation, building on the existing Akrites initiative and OpenSSF. That is the correct home for it — neutral governance, an established process for the boring parts, and two decades of institutional memory about what happens to consortium code when the founding sponsor loses interest.

The stated thesis: transparency beats secrecy

The alliance's framing is that defenders globally should have open frontier tools for cybersecurity, and that security through transparency outperforms security through withholding.

This is a real argument with a long track record in security, and it is also a competitively convenient argument for the specific companies making it. Nvidia sells the compute regardless of whose model wins; the more open the model layer, the more the value concentrates in silicon. Hugging Face, Mistral, vLLM, Nous Research, and Thinking Machines are all open-weight-aligned by business model. The security vendors — CrowdStrike, Palo Alto, Zscaler, Fortinet — want the detection surface to be inspectable because inspectable is what they sell against.

None of that makes the thesis wrong. It does explain why the roster looks the way it does.

Why the absences are structural, not petty

It would be easy to read OpenAI's and Anthropic's non-participation as a snub. It is more likely a straightforward incompatibility.

The alliance's organizing premise is that safety-relevant tooling should be open and shared. The core commercial premise of both frontier labs is that their most capable systems are not open, and that the safeguards around those systems are part of what they sell. A lab that gates model access behind graduated trust tiers is not obviously able to sign a charter built on open frontier tooling for defenders — because "defenders" and "everyone" are the same set once the tools are public.

Both labs also already have their own venues. Both sit as platinum members of the Agentic AI Foundation, the Linux Foundation fund that took over the Model Context Protocol and shipped its stateless rewrite this week. Neither is refusing to collaborate on open infrastructure in general. They are declining this one, on security specifically.

Google's and Amazon's absences are harder to read as principled. Both run enormous security organizations, both publish open tooling, and both have obvious commercial reasons to want agent identity and supply-chain integrity standardized. Their absence at launch reads more like sequencing than refusal — founding-member lists are negotiated, and Microsoft moving first tends to slow the other two down rather than speed them up.

What to watch

Consortium launches are cheap and consortium maintenance is expensive. The measurable question over the next two quarters is whether the donated pieces converge into something composable or sit in adjacent repos as parallel donations.

The natural integration test is already obvious. Take SPIFFE/SPIRE for agent identity, MDASH for scanning, Safetensors for weight integrity, Lightwell for signed patches, and NOOA for harness-level tracing, and you have most of the components of an end-to-end story: an agent with a verifiable identity, running scanned models with verified weights, on a patched supply chain, under an auditable harness. If the alliance ships that as a coherent reference stack, it will have earned the roster.

If it ships five README updates, the absences will stop looking like sequencing and start looking like judgment.

#nvidia#ai-security#open-source#linux-foundation#agents

The state of AI, in flux.

The directory + magazine for AI tools and the workflows people use to make money with them.

🔥 The Sauce Drop

The week's highest-earning AI workflows, in your inbox.

Some outbound links are affiliate links — Flux may earn a commission at no cost to you; this never affects rankings. Earnings figures are self-reported and not guarantees of income; most people earn less, some earn nothing.