Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progress
The Open Secure AI Alliance (OSAA), a coalition spearheaded by Nvidia that has rapidly expanded to include over 120 member organizations, is wasting no time. Just one week after its inception, the group has already established a dedicated working group dubbed SAFE (Shared AI Findings Exchange) and is actively soliciting open feedback on its initial security proposals.
Managed by the Linux Foundation, these early-stage guidelines were introduced this week during the Black Hat cybersecurity conference in Las Vegas. While the current proposals are foundational rather than revolutionary, they represent a critical first step in standardizing how the industry handles AI-related threats.
Establishing a Security Framework
The initial focus of the OSAA centers on creating a unified language for AI defense. The proposed guidelines prioritize three core pillars:
- Confidential Incident Reporting: Establishing secure channels for disclosing AI-related cybersecurity breaches.
- Standardized Alerting: Protocols for notifying affected parties when an AI system is compromised.
- Blame-Free Analysis: Creating a collaborative environment to conduct post-mortem investigations, ensuring the entire ecosystem can learn from individual failures.
This initiative aims to provide enterprises with a robust, open-source framework to secure their AI agents and defend against malicious actors—a necessity highlighted by recent incidents, such as the unauthorized infiltration of Hugging Face models.
Industry Contributions and Technical Synergy
Beyond policy, OSAA members are actively cataloging open-source technologies to bolster the collective defense. Major industry players are already contributing significant assets to the cause:
- Nvidia: Providing its family of open models and the Garak LLM vulnerability scanner.
- Amazon: Contributing the Strands Agents building tool and the Cedar authorization language.
- Red Hat: Focusing on the critical area of agent governance.
- Okta: Developing specialized identity technology for AI agents.
The alliance boasts a heavy-hitting roster, including Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa. However, the absence of Anthropic, OpenAI, and Google remains a notable point of contention. While OpenAI and Google were signatories to the original open letter that catalyzed the group’s formation, they have yet to formally join the alliance.
“Openness may be one of the most important paths to AI safety and security,” the group stated in their founding letter.
A Strategic Response to Global Pressures
The formation of the OSAA follows a period of intense industry anxiety regarding potential U.S. government restrictions on open-weight models, particularly those originating from China. The alliance serves as a proactive measure to demonstrate that the open-source community can self-regulate and secure its own infrastructure.
Proponents of the movement, including leadership at the open-weight AI lab Arcee, argue that this collaborative, transparent approach is the most effective strategy to neutralize security threats—whether real or perceived—posed by international competitors.
By moving at "AI speed," the OSAA is signaling that it intends to be more than just a lobbying group; it is positioning itself as a functional, technical engine for the future of secure, open-source artificial intelligence. As the group gains momentum, the industry will be watching closely to see if the remaining tech giants choose to align with this collective effort.