The Open Secure AI Alliance is the official name of a new coalition unveiled on July 27 by Nvidia and 36 other inaugural partners. Its stated goal is to develop and share open technologies, techniques and tools for protecting software and AI agents.
The initiative builds on earlier work by the Linux Foundation’s Akrites project and the OpenSSF community. It is not a regulator or a finished standard. It is a collaboration framework for components that can be inspected, tested and reused.
The founding partners
The official list includes Nvidia, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab and TrendAI.
OpenAI, Google and Anthropic do not appear on the inaugural list. Their absence is confirmed by the official announcement, but it does not by itself establish opposition: none of the three provided an explanation in the launch material.
What the projects contribute
- Nvidia is contributing NOOA, a research framework for testing, tracing, auditing and governing agent behaviour.
- HPE highlights SPIFFE and SPIRE for cryptographically verifying the identity of services and workloads.
- Hugging Face contributes Safetensors, a weight format designed to prevent remote code execution when files are loaded.
- IBM and Red Hat are working on Lightwell to sign patches across the software supply chain.
- Microsoft contributes MDASH, a scanning harness that coordinates multiple agents to discover and prove exploitable flaws.
Why it matters
Agents do more than generate text: they read repositories, run tools, call services and modify files. A permissions or traceability failure can be just as serious as a model weakness.
Opening the harnesses and controls allows more teams to inspect how decisions are made and share fixes. It also creates a challenge: publishing a tool does not guarantee maintenance, adoption or neutral governance. The alliance will need to demonstrate deliverables, licences and vulnerability-response processes.
An agent preparing a patch
The model may propose the code change, but the surrounding system must verify which identity is acting, limit repository access, preserve the reasoning and tools used, test in isolation and require approval before merging.
What remains unclear
The announcement names projects and members, but does not set a common timetable, budget, legal structure or success metrics. It also does not explain how disagreements will be resolved when the interests of model vendors, security companies and open foundations diverge.
VERIFICATION SOURCENvidia’s official announcement and partner list ↗VERIFICATION SOURCEAxios context on the open-model debate ↗VERIFICATION SOURCELinux Foundation’s Akrites project ↗Is the alliance run only by Microsoft, Nvidia and IBM?
No. They are prominent members, but the announcement lists 37 inaugural partners spanning infrastructure, security, enterprise software, research and open source.
Are OpenAI, Google and Anthropic founding partners?
They are not on the official launch list. That alone does not explain why they did not join.
Will the alliance certify AI models?
The announcement does not create a certification mark. It describes collaboration on open security tools, techniques and components.
Verified sources and original reporting.
Nexus AI wrote and contextualized this article using Nvidia, Axios and Linux Foundation · Jul 27, 2026. The complete story is on this page; the reference is provided so readers can check the original information.
Check the main source ↗


