“AI security advances when the industry builds in the open, together… By sharing models, tooling and research in the open, we can broaden the community of defenders.”
Open Secure AI Alliance · Independent guide · July 27, 2026
A clear map of the Open Secure AI Alliance
Lightweight community page: what launched, why it matters, which open tools to open first, and where the official sources live. Not affiliated with NVIDIA or the Alliance.
Context
Why this alliance exists
The public case is practical: during the July 2026 Hugging Face security incident, closed AI tools blocked essential forensics. An open-weight model run on their own infrastructure helped analyze tens of thousands of actions and contain the intrusion.
The Alliance’s stated mission is to give defenders open models, harnesses, and tools they can inspect, adapt, and control — complementing closed systems rather than replacing them. It builds on Linux Foundation Akrites work and the OpenSSF community.
News
What’s new
Day-zero notes from public announcements. Update this list as partners ship more.
-
2026-07-27
Open Secure AI Alliance launches
NVIDIA and a broad set of cloud, security, enterprise, and open-source partners announce a shared effort for open AI safety and security tooling.
-
2026-07-27
NOOA research framework on GitHub
NVIDIA Labs Object-Oriented Agents (NOOA) published to help make agent behavior easier to test, trace, audit, and govern.
-
2026-07-27
Partner contributions called out
Public materials highlight safe model formats (Safetensors), zero-trust identity (SPIFFE/SPIRE), multi-model scanning, and secure coding agent work.
-
2026-07-24
Adjacent: open-weight policy letter
Days earlier, a multi-company letter urged policymakers not to place premature restrictions on open-weight models — related narrative, separate from OSAA itself.
Tools
Open building blocks to explore
Primary links only. Start with one repo or standard, not all at once.
-
NOOA agent harness · GitHub
Research framework for integrating models with harnesses so agent behavior is easier to test, trace, audit, and govern.
-
Safetensors model format · GitHub
Safer weight storage format aimed at transparency and reducing remote-code-execution risks from unsafe serialization.
-
SPIFFE / SPIRE identity · standards
Zero-trust identity for workloads — useful as agents become first-class actors that need cryptographic verification.
-
OpenSSF supply chain security
Shared practices and community for securing open-source software — part of the Alliance’s foundation narrative.
-
Official interest form join via NVIDIA
Governments, industry, and researchers should use NVIDIA’s form — not this community page — for Alliance membership interest.
On the record
Primary quotes
Lightweight cards with links to X — not full embeds (faster, fewer trackers, still citable).
“Attackers have frontier AI. Defenders need a frontier AI ecosystem—the best open and closed models, force-multiplied by a global community… That’s why we created the Open Secure AI Alliance.”
Ecosystem
Inaugural partners (partial)
NVIDIA, Microsoft, IBM, Red Hat, Hugging Face, CrowdStrike, Palo Alto Networks, Cisco, Cloudflare, Databricks, Dell, HPE, Elastic, LangChain, Linux Foundation, Palantir, Salesforce, SAP, Siemens, Snowflake, Adobe, ServiceNow, Thinking Machines Lab, and many others listed in the official announcement.
FAQ
Frequently asked questions
Short answers. Expand a question for detail.
Is this the official Open Secure AI Alliance website?
No. This is an independent community guide. Official information lives on NVIDIA’s blog, partner posts, and NVIDIA’s Alliance contact form.
What is the Open Secure AI Alliance?
A multi-company initiative announced July 27, 2026 to develop and share open technologies, techniques, and tools that help secure software and AI agents — so defenders can inspect, adapt, and run capable systems themselves.
Why did this launch now?
Public materials cite rising AI-enabled threats and the Hugging Face incident, where closed tools blocked forensics and an open-weight model helped defenders respond on their own infrastructure.
Does this replace closed AI models?
No. The stated framing is that defenders need both open and closed systems. Open tools add transparency, localization, and control; closed models remain part of the ecosystem.
What can I use today?
Start with NOOA on GitHub for agent harness research, Safetensors for safer weight formats, and SPIFFE/SPIRE for workload identity. Use the official NVIDIA form if you want to express interest in joining the Alliance.
How do I join the Alliance?
Use NVIDIA’s official contact page. This site cannot enroll partners and does not speak for the Alliance.
Are osaa.ai / osaa.dev official domains?
Not at the time of writing. This page notes domain interest for an independent community home. Official branding and domains belong to the Alliance and its members if and when they publish them.
Sources
Primary links
Prefer these over summaries when accuracy matters.
Contact
Domain & community
Interested in osaa.ai / osaa.dev, or have a correction for this guide? Reach out on X.
@lviswanath on X ↗