Decoding the world of cybersecurity

Open alliance assembles AI security stack

Nvidia, SAP, Siemens, Microsoft, and other technology companies have formed an alliance to develop open tools for AI-agent identity, testing, monitoring, vulnerability discovery, and governance.

Open alliance assembles AI security stack
Summary
  • The Open Secure AI Alliance combines cloud, enterprise, industrial, open source, and cybersecurity suppliers.
  • Planned work covers agent identity, permissions, guardrails, logging, evaluation, vulnerability discovery, and remediation.
  • The alliance has not yet published a detailed governance model, delivery timetable, or assurance process.

Nvidia has brought together cloud, enterprise-software, industrial, open source, and cybersecurity companies in an alliance intended to build shared security infrastructure for artificial-intelligence models and agents.

The Open Secure AI Alliance includes Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Hugging Face, the Linux Foundation, Palo Alto Networks, Red Hat, SAP, ServiceNow, Siemens, Snowflake, Synopsys, and other suppliers involved in model development, enterprise technology, infrastructure, and security.

Its proposed work includes open models, evaluation harnesses, tools, datasets, and techniques covering agent identity, permissions, guardrails, logging, testing, vulnerability discovery, remediation, and disclosure.

The group builds on existing activity associated with the Linux Foundation’s Akrites project and the Open Source Security Foundation. Nvidia is also contributing NOOA, a framework intended to support testing, tracing, auditing, and governance of AI agents.

According to the alliance’s launch material, open models and tools can give organisations greater visibility into defensive systems and allow sensitive code or operational data to remain within controlled infrastructure.

The members bring different commercial interests across hardware, cloud services, security products, enterprise applications, development tools, and model deployment. The alliance has not yet published detailed arrangements for governance, funding, release management, maintenance, assurance, or responsibility when shared technology fails.

Its formation follows an incident disclosed by Hugging Face in which AI-driven defensive agents analysed large volumes of attacker activity. That experience provides an early example of automated defensive use, while broader enterprise adoption will depend on repeatable testing across different systems and threat conditions.

Agent identity becomes infrastructure

Open technology can support independent testing, local deployment, and scrutiny of model behaviour. European organisations pursuing sovereign or controlled AI environments may also prefer systems that do not require proprietary source code, operational logs, or sensitive business data to leave their infrastructure.

SAP and Siemens give the alliance a direct connection to European enterprise and industrial environments. Their participation could influence how security controls are incorporated into business software, engineering systems, manufacturing platforms, and infrastructure where autonomous actions require strict limits.

Open weights and source code do not remove supply chain risk. Models depend on training data, orchestration layers, tool permissions, plugins, retrieval sources, evaluation datasets, compute infrastructure, and update mechanisms. Each component can introduce defects, malicious changes, or dependencies that are not visible from the model alone.

Agent identity will become a central control where autonomous systems can open tickets, change code, query repositories, isolate devices, or alter cloud resources. Each agent needs a verifiable identity, narrowly defined authority, and records showing which action it took, under which policy, and on whose instruction.

Logging must preserve enough context to reconstruct responsibility. Recording that an agent invoked a tool is insufficient where the organisation cannot identify the model version, input context, retrieved material, policy decision, human approval, and resulting system change.

Vulnerability-discovery models also carry dual-use capability. Systems designed to find weaknesses before release may be used to locate exploitable defects. Access control, responsible disclosure, abuse monitoring, and isolation therefore remain relevant even where the underlying model is openly available.

Procurement assessments will need to examine maintainers, signed updates, data collection, vulnerability handling, isolation, audit evidence, and liability rather than relying on the open label. Interoperable controls will be more valuable than a collection of disconnected demonstration projects.

The alliance has sufficient membership to influence how AI-agent security is implemented across enterprise platforms. Its output will become measurable when maintained technology, evaluation results, governance documents, and deployments in regulated environments begin to appear.

×