Unofficial Community Field Guide · Not affiliated with NVIDIA or the Alliance · Official Sources ↓

INDEPENDENT COMMUNITY DASHBOARD · UPDATED: 07 AUG 2026

Open Secure AI Alliance Guide

A living, single-page tracker mapping the open AI security stack, SAFE RFC progress, member updates, curated open-source tools, and primary sources.

Members: 120+ Orgs
SAFE RFC: Open for Feedback
Core Tools: 8 Registered

Why this alliance exists

The public case is practical: during the July 2026 Hugging Face security incident, closed AI tools blocked essential forensics. An open-weight model run on their own infrastructure helped analyze tens of thousands of actions and contain the intrusion.

The Alliance’s stated mission is to give defenders open models, harnesses, and tools they can inspect, adapt, and control — complementing closed systems rather than replacing them. It builds on Linux Foundation Akrites work and the OpenSSF community.

Living Timeline & Alliance Changelog

Dated changelog of material updates, RFC milestones, tool releases, and membership expansion.

2026-08-12 SAFE

SAFE RFC Phase 2 Remains Open for Public Feedback

Shared AI Findings Exchange draft framework active for public comment. Review ongoing discussions on incident reporting protocols.

2026-08-11 Membership

SUSE Joins Open Secure AI Alliance

SUSE pledges commitment to open sovereign AI infrastructure, Linux kernel security boundaries, and hardened runtime environments.

2026-08-04 SAFE

Shared AI Findings Exchange (SAFE) RFC Published

Draft incident-reporting framework for AI agents and foundation models released under Linux Foundation stewardship.

2026-07-27 Announcements

Open Secure AI Alliance Formally Formed

NVIDIA, Hugging Face, AWS, and Linux Foundation announce open defense stack to secure AI models, data pipelines, and agent runtimes.

SAFE Status Dashboard

Current state of the Shared AI Findings Exchange (SAFE) RFC initiative under Linux Foundation stewardship.

🟢 OPEN FOR PUBLIC COMMENT

Comment Deadline: Sept 1, 2026 · GitHub Activity: 42 open issues, 14 active PRs

Major Community Feedback Themes:

  • Standardized schema for reporting agent sandbox escapes and prompt injection incidents.
  • Cryptographic identity signatures for verified threat intelligence sharing.
  • Privacy-preserving telemetry protocols for multi-node foundation model inference.
Join SAFE RFC Discussion on GitHub ↗ View GitHub RFCs Repo ↗

Tools & Contributions Registry

Curated directory of open-source frameworks, security sandboxes, format standards, and identity engines.

Agent harness for testing, tracing, auditing, and governing AI agents. Integrates foundation models with control systems.

Owner: NVIDIA Labs ⭐ 850 · Jul 2026

Safetensors ↗

Production-ready

Safe, ultra-fast tensor storage format preventing arbitrary code execution risk during model weight loading.

Owner: Hugging Face (PyTorch Foundation) ⭐ 12,800 · Aug 2026

Zero-trust cryptographic identity standard and runtime for heterogeneous cloud workloads and agent microservices.

Owner: CNCF / SPIFFE Community ⭐ 4,200 · Aug 2026

OpenShell ↗

Production-ready

Isolated runtime sandbox and kernel security wrapper for safe sub-agent execution and untrusted LLM tool calls.

Owner: Linux Foundation / OpenSSF ⭐ 1,420 · Aug 2026

Garak ↗

Beta

LLM vulnerability scanner probing foundation models for prompt injection, jailbreaks, hallucination, and data leakage.

Owner: NVIDIA / Open Source Community ⭐ 3,850 · Aug 2026

Cedar Policy Engine ↗

Production-ready

Expressive language for fine-grained access control policies and authorization logic in automated agent workflows.

Owner: AWS / Cedar Policy Community ⭐ 2,900 · Aug 2026

vLLM ↗

Production-ready

High-throughput and memory-efficient LLM serving engine featuring PagedAttention and secure model execution.

Owner: vLLM Team / UC Berkeley ⭐ 31,500 · Aug 2026

Automated security health check tool evaluating open-source code repositories for risk mitigation standards.

Owner: OpenSSF / Linux Foundation ⭐ 6,100 · Aug 2026

Membership Tracker

Tracking membership expansion from initial 37 partners to 120+ participating organizations.

🔥 Recently Joined (Last 2–3 Weeks):

SUSE Databricks CrowdStrike Red Hat SentinelOne Canonical

Inaugural & Major Partners:

NVIDIA · Hugging Face · AWS · Linux Foundation · OpenSSF · Palo Alto Networks · Cisco · Google Cloud · Microsoft · Meta · IBM · Cloudflare · Databricks · Dell · HPE · Elastic · LangChain · Palantir · Salesforce · SAP · Siemens · Snowflake · Adobe · ServiceNow

View Official Full Partner List on NVIDIA Blog ↗

Selected Coverage & Analysis

Curated roundup of high-signal reporting on sovereign AI security and alliance milestones.

  • 2026-08-07 Box joins the Open Secure AI Alliance

    Box has become a founding member of the Open Secure AI Alliance, contributing to open AI security tooling and governance. Read the announcement.

  • JUL 28, 2026 · SILICONANGLE
    NVIDIA and Hugging Face unite to establish open AI defense standards

    Analysis of why sovereign AI requires vendor-neutral security primitives.

  • JUL 27, 2026 · AXIOS
    Open Secure AI Alliance forms at Linux Foundation

    Context on post-incident industry alignment following Hugging Face model registry vulnerability discoveries.

  • JUL 28, 2026 · SILICONANGLE
    NVIDIA and Hugging Face unite to establish open AI defense standards

    Analysis of why sovereign AI requires vendor-neutral security primitives.

  • JUL 27, 2026 · AXIOS
    Open Secure AI Alliance forms at Linux Foundation

    Context on post-incident industry alignment following Hugging Face model registry vulnerability discoveries.

  • Frequently Asked Questions

    Short answers to common questions about the alliance and this community guide.

    Is this the official Open Secure AI Alliance website?

    No. This is an independent community guide. Official information lives on NVIDIA’s blog, partner posts, and NVIDIA’s Alliance contact form.

    What is the Open Secure AI Alliance?

    A multi-company initiative announced July 27, 2026 to develop and share open technologies, techniques, and tools that help secure software and AI agents — so defenders can inspect, adapt, and run capable systems themselves.

    Why did this launch now?

    Public materials cite rising AI-enabled threats and the Hugging Face incident, where closed tools blocked forensics and an open-weight model helped defenders respond on their own infrastructure.

    Does this replace closed AI models?

    No. The stated framing is that defenders need both open and closed systems. Open tools add transparency, localization, and control; closed models remain part of the ecosystem.

    What can I use today?

    Start with NOOA on GitHub for agent harness research, Safetensors for safer weight formats, and SPIFFE/SPIRE for workload identity. Use the official NVIDIA form if you want to express interest in joining the Alliance.

    How do I join the Alliance?

    Use NVIDIA’s official contact page. This site cannot enroll partners and does not speak for the Alliance.

    Are osaa.ai / osaa.dev official domains?

    Not at the time of writing. This page notes domain interest for an independent community home. Official branding and domains belong to the Alliance and its members if and when they publish them.

    Domain & Community

    Interested in osaa.ai / osaa.dev, or have a correction for this guide? Reach out on X.

    @lviswanath on X ↗