American chipmaker Nvidia and 36 other major technology companies launched an alliance on Monday to build open-source security tools for AI systems, citing an incident this month in which closed AI models obstructed a company's attempt to investigate a breach of its own servers.
The Open Secure AI Alliance includes Microsoft, IBM, Red Hat, Cloudflare, CrowdStrike, Palantir, Databricks, Hugging Face, SpaceXAI and the Linux Foundation, and builds on the foundation's existing Akrites initiative and OpenSSF work. OpenAI, Anthropic and Google, which develop the industry's most capable closed models, are not listed among the inaugural partners.
The founding argument rests on the Hugging Face breach disclosed last week, as CoinDesk reported.
OpenAI said models it was testing on an internal hacking benchmark, running with cyber safety refusals deliberately lowered, escaped their test environment and gained the ability to run commands on Hugging Face's production servers.
According to Nvidia, the cleanup then ran into a problem of its own. Closed AI tools, "unable to distinguish attackers from defenders," blocked the forensic analysis. Hugging Face instead ran GLM 5.2, an open-weight model from Chinese developer Z.ai, on its own infrastructure to review more than 17,000 actions and contain the intrusion.
"When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most," Nvidia said.
Members are contributing specific tools. NVIDIA released NOOA, a framework for making AI agent behavior easier to test and audit, on GitHub. Microsoft contributed MDASH, a system that runs multiple AI agents to find exploitable bugs, while SpaceXAI open-sourced its Grok Build coding agent and said it plans to release the weights of its Grok models.
The alliance arrives with cybersecurity teams on heightened alert globally, and crypto networks and wallets remain a favored target, since a single successful exploit can pay out enormously and cannot be reversed.
Four protocols were drained of more than $35 million in a single stretch last week, including AFX, Verus and Bitcoin scaling network B², and none of the attacks broke any cryptography. Each abused a trusted control, the same class of long-horizon, multi-step work that AI systems are getting measurably better at. Unlike a corporate breach, a drained contract cannot be undone.
coindesk.com