The aftermath of OpenAI’s Hugging Face breach continues to ripple throughout the tech ecosystem. Yesterday, Nvidia announced the Open Secure AI Alliance, a coalition of industry leaders looking to “ensure defenders everywhere have open, frontier tools they can trust and control.”
Companies participating in the alliance include Adobe, CapitalOne, Cisco, Cloudflare, CrowdStrike, Databricks, Elastic, HPE, Hugging Face, IBM, LangChain, The Linux Foundation, Microsoft, NetApp, Nvidia, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake, SpaceX, Synopsys, Thinking Machines and Trend AI.
The announcement blog post directly references the Hugging Face breach, saying the “security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense,” noting that when closed-source AI tools blocked forensic analysis during the incident, it was the open-weight model GLM 5.2 that helped the company to remediate.
At launch, OpenAI and Anthropic aren’t part of the initiative. The news comes the same day that Dario Amodei, cofounder and CEO of Anthropic, released a blog post claiming the startup has never advocated for a ban on open-weight models, but does support measures including not selling powerful chips or chipmaking equipment to China and a crackdown on industrial-scale distillation operations.
Supporting Open Source AI
The Open Secure AI Alliance is launching at a time when the Trump Administration is threatening potential sanctions against Chinese AI model providers. On July 21, U.S. Treasury Secretary Scott Bessent said the U.S. government will look into whether Chinese AI models have been distilled from American models, telling Fox Business, “if we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft.”
Then on July 22, Director Michael Kratsios, Assistant to the President and Director of the White House Office of Science and Technology Policy for Science and Technology, accused Chinese AI startup Moonshot AI of distilling Anthropic’s Fable to develop its Kimi K3 model. He said, “covert industrial distillation aimed at stealing proprietary U.S. technology and undermining American research is unacceptable.”
The alliance is also responding to the fallout from the Hugging Face breach, which, according to a blog post by OpenAI, occurred when GPT 5.6 Sol and a prerelease model escaped an isolated testing environment and breached Hugging Face’s systems.
“During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion. That’s why we created the Open Secure AI Alliance,” Nvidia founder and CEO Jensen Huang posted on X yesterday.
The breach highlights the failures of frontier AI vendors’ guardrails: OpenAI’s systems caused the incident in the first place, while frontier AI models failed to help Hugging Face remediate during the incident response.
Collaborating To Address Risk
While frontier AI labs like OpenAI and Anthropic have worked alongside third party organizations to secure critical systems with proprietary models via Trusted Access for Cyber and Project Glasswing projects, Nvidia’s initiative instead focuses on looking to secure software with open tools.
“No company is going to secure AI on its own. The Open Secure AI Alliance brings together technology providers, researchers, governments and cybersecurity professionals because this is a challenge the industry has to solve collectively,” Scott Beale, CEO of ISC2, a member organization for cybersecurity professionals, told me via email.
“OpenAI, Anthropic and Google aren’t in this alliance, and that tells you what it’s actually about. The pitch is that enterprises shouldn’t have to rent their agent security layer from three closed vendors,” Lidan Hazout, cofounder and CTO of AI agent security startup Capsule Security, told me via email.
Hazout adds that the timing matters, and suggests that Hugging Face “won’t be the last one,” and that we should “expect a lot more rogue agent cases over the next year.” His observation is that each one of these incidents will end in a forensics problem, and that whoever is running those investigations will want a model they can run themselves.
What Now?
Just before the alliance was announced, Huang signed an open letter in support of open weight models, which called on the U.S. government “not to conflate legitimate model development techniques with misappropriation,” a reference to the allegations made against Moonshot AI for allegedly distilling Fable. The Open Secure AI Alliance highlights potential resistance to sanctions against Chinese AI providers.
At this stage, organizations participating in the alliance have made a number of releases to support the effort. For example, Nvidia has made the Nvidia Labs Object-Oriented Agent (NOOA) available on GitHub to make AI safety capabilities more accessible for agent harnesses.
Likewise, HPE has contributed SPIFFE/SPIRE, which creates zero-trust identity framework standards and can cryptographically verify AI agents and services. Microsoft has contributed MDASH, a multi-model agentic scanning harness that orchestrates specialised AI agents to discover vulnerabilities, and SpaceXAI has open-sourced the Grok Build terminal-based coding agent.
“The alliance is a strong start because it recognises a basic truth: defenders need access to capable, inspectable AI if they are going to keep pace with AI-enabled threats,” Kevin Kirkwood, CISO at threat detection provider Exabeam, told me via email. “Open models, shared datasets, evaluation frameworks, and defensive tooling can shorten the time from threat discovery to detection and response.”
Peter Garraghan, founder and CSO at AI security vendor Mindgard, told me via email, “This is the right call to make, security through obscurity has never worked out in the long run, as all it does is make the defender’s life much more difficult against attackers who have less moral and legal qualms in using technology.”
However, there are some limitations to note. Most notably, the absence of OpenAI and Anthropic. Kirkwood warned, “The initiative will remain incomplete without broader participation and clearer accountability. The major frontier model developers need to be at the table, and the industry needs agreed rules for liability when an agent exceeds scope. Better tools help defenders fight dark AI. Better governance keeps the defensive tools from becoming part of the problem.”


