A New Tech Alliance Is Already Tackling AI Security — Here's What's Happening

One week after its public launch, the Open Secure AI Alliance (OSAA) has grown to over 120 member companies and released its first concrete proposals for public feedback: a set of guidelines for confidential AI cybersecurity incident reporting, alerting affected parties, and conducting blame-free reviews after something goes wrong. TechCrunch
The Linux Foundation, an OSAA member, is managing the proposal process. The guidelines were developed while OSAA members gathered at the Black Hat conference in Las Vegas. TechCrunch
Nvidia announced OSAA on July 27, 2026, describing the alliance as uniting industry leaders to develop techniques and tools that safeguard software by rapidly and responsibly identifying and addressing security issues. Nvidia Blog The announcement followed a hack at Hugging Face, which Reuters identified as the proximate context for the coalition's formation. Reuters The alliance aims to produce stronger defensive agents, open tooling, better deployment practices, and shared evaluation frameworks. Trend Micro
OSAA originated from an open letter, championed by Nvidia and signed by over 200 tech companies, urging the White House to support open source AI efforts rather than restrict them. Open source means the underlying code is freely available for anyone to inspect, modify, and build upon. OpenAI and Google signed that letter. Neither company, nor Anthropic, has joined OSAA. TechCrunch
The current membership roster includes Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, and Hugging Face. TechCrunch
Beyond the guidelines, OSAA members are contributing and cataloging open source technology relevant to AI security. Nvidia has contributed an entire family of open models and Garak, an open source tool that scans large language models for vulnerabilities. Amazon contributed Strands Agents, a tool for building AI agents, and Cedar, a language for writing rules about who or what can access specific resources. Okta is developing technology to give AI agents their own digital identities. Red Hat is working on governance — the rules and oversight for how autonomous AI agents operate. TechCrunch Nvidia Blog
The speed of OSAA's first deliverable is notable. Industry consortia typically take months to ratify governance structures before producing technical proposals. Having a working group chartered, proposals drafted at a security conference, and an open comment period open within seven days suggests either a high degree of pre-launch coordination among founding members or a decision to release early-stage work and improve it in public. The involvement of the Linux Foundation as the administrative home for the process gives the alliance governance infrastructure that a brand-new body would otherwise lack.
The gap between the original open letter's signatories and the actual OSAA membership is worth flagging. OpenAI and Google both signed the letter advocating for open source AI but have not joined the alliance that emerged from it. Anthropic, which did not sign the letter, is also absent. The three companies that have built the most capable closed AI models are, collectively, on the outside of an effort focused on securing open AI systems. Whether this reflects substantive disagreement about the open-source approach to AI safety, competitive positioning, or simply a timing mismatch is not clear from public statements.
The contributions themselves point to where the alliance sees concrete gaps. Garak scans AI models for weaknesses. Cedar provides fine-grained rules for what AI agents are allowed to do. Okta's identity work tackles the problem of verifying that an AI agent is who it claims to be before it takes an action. Red Hat's governance track addresses the rules around how autonomous agents operate throughout their lifecycle. Strands Agents provides the tools to build agents in the first place. Taken together, the contributions sketch a full picture: identity, authorization, build-time tooling, model-level probing, and incident response.
The guidelines fill the operational layer that sits above individual tools. Confidential reporting with blame-free analysis is the model that CERT/CC, a long-standing cybersecurity coordination center, used for decades in traditional information security, now adapted for AI-specific incidents. The open comment period now determines whether that adaptation proves workable for organizations whose incidents may involve prompt injection — crafting inputs that trick an AI into doing something unintended — or data theft through an AI's tool access, or adversarial inputs that exploit how a model behaves rather than weaknesses in underlying infrastructure.
OSAA is a week old. The proposals are open for comment, not finalized. The tooling contributions exist but have not been integrated into any shared framework. What OSAA has shown in its first week is momentum and a coherent division of labor across member companies. What it has not yet shown is whether that momentum produces standards that the broader industry adopts, or whether the companies building the most powerful closed models feel compelled to engage on open security terms they did not help shape.


