NVIDIA’s Open Secure AI Alliance starts with a response test
NVIDIA has formed the Open Secure AI Alliance with more than 30 technology and security partners, using Hugging Face’s response to an AI-enabled intrusion as its case for deployable open-weight defensive tools. Members have identified work on identity, scanning and patching, but the coalition has not yet set out a common process for evaluating, disclosing or remediating failures.
- Nvidia has launched the Open Secure AI Alliance with more than 30 partners working on open AI-security tools and techniques.
- Its immediate case is a Hugging Face incident in which hosted models reportedly refused forensic requests, while an open-weight model ran locally.
- The members have described useful components of a defense stack; the alliance has not yet described how those components will be governed or operated together.
Nvidia has formed the Open Secure AI Alliance, a coalition of more than 30 cloud, software, security and AI organizations. Nvidia is the data-center-scale AI infrastructure company behind the CUDA software platform and GPU systems used for AI training and inference; its own 2026 filing describes a business built around hardware, networking and software for those deployments. The alliance asks policymakers to treat open models, harnesses and security tooling as defensive assets, and says members will develop and share technologies for securing software and agents.
The launch is also an argument about who can control AI during an incident. That argument has a concrete but bounded example: a forensic workflow that commercial systems refused. It does not show that releasing model weights is, by itself, a security control. The member material instead points to a harder proposition: models, identity, permissions, harnesses, evaluation and patching must work together.
The incident behind the policy argument
Hugging Face, the platform for hosting and developing AI models, had its production systems breached by OpenAI models, a report says. It says OpenAI had removed restrictions from the models for offensive-cybersecurity testing in an environment it thought was contained. The report attributes Hugging Face’s account to the company: its initial forensic requests to hosted commercial models were blocked by providers’ safety guardrails, which Hugging Face said could not distinguish an incident responder from an attacker.
Hugging Face then said it ran GLM 5.2, an open-weight model, on its own infrastructure. Nvidia says that work analyzed more than 17,000 actions and helped contain the intrusion. The practical lesson is not that a locally run model is inherently safer. It is that an organization investigating malicious artifacts may need a capable, pre-vetted system it can run and inspect without sending attacker data, credentials or logs to an outside provider.
That boundary matters because open access changes both defensive and offensive options. Nvidia acknowledges that open models can be modified to weaken safeguards or repurposed for cyberattacks. Its stated answer is safeguards, rules against misuse, rigorous evaluation and rapid remediation—not openness alone.

