Nvidia's Open Secure AI Alliance Releases First Proposals a Week After Launch

One week after its public launch, the Open Secure AI Alliance (OSAA) has grown to over 120 member companies and released its first concrete proposals for open comment: a set of guidelines under the Shared AI Findings Exchange (SAFE) working group covering confidential AI cybersecurity incident reporting, affected-party alerting, and blame-free post-incident analysis. TechCrunch
The Linux Foundation, an OSAA member, is managing the SAFE proposal process. The guidelines were developed while OSAA members gathered at the Black Hat conference in Las Vegas. TechCrunch
Nvidia announced OSAA on July 27, 2026, describing the alliance as uniting industry leaders to develop techniques and tools that safeguard software by rapidly and responsibly identifying and addressing security issues. Nvidia Blog The announcement followed a hack at Hugging Face, which Reuters identified as the proximate context for the coalition's formation. Reuters The alliance aims to produce stronger defensive agents, open tooling, better deployment practices, and shared evaluation frameworks. Trend Micro
OSAA originated from an open letter, championed by Nvidia and signed by over 200 tech companies, urging the White House to support open source AI efforts rather than restrict them. OpenAI and Google signed that letter. Neither company, nor Anthropic, has joined OSAA. TechCrunch
The current membership roster includes Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, and Hugging Face. TechCrunch
Beyond the SAFE guidelines, OSAA members are contributing and cataloging open source technology relevant to AI security. Nvidia has contributed an entire family of open models and Garak, an open source LLM vulnerability scanner. Amazon contributed Strands Agents, an open agent building tool, and Cedar, a policy authorization language (a way to define fine-grained rules for who or what can access specific resources). Okta is developing agent identity technology within the alliance. Red Hat is working on agent governance. TechCrunch Nvidia Blog
The speed of OSAA's first deliverable is notable. Industry consortia typically take months to ratify governance structures before producing technical proposals. Having a working group chartered, proposals drafted at a security conference, and an open comment period open within seven days suggests either a high degree of pre-launch coordination among founding members or a decision to release early-stage work and iterate in public. The involvement of the Linux Foundation as the administrative home for SAFE lends the process established governance infrastructure that a brand-new body would otherwise lack.
The gap between the original open letter's signatories and the actual OSAA membership is worth flagging. OpenAI and Google both signed the letter advocating for open source AI but have not joined the alliance that emerged from it. Anthropic, which did not sign the letter, is also absent. The three companies that have built the most capable closed frontier models are, collectively, on the outside of an effort focused on securing open AI systems. Whether this reflects substantive disagreement about the open-source approach to AI safety, competitive positioning around proprietary model security, or simply a timing mismatch is not clear from public statements.
The contributions themselves point to where the alliance sees concrete gaps. Garak addresses LLM probing for vulnerabilities at the model level. Cedar provides fine-grained authorization, which maps naturally to agent-permission boundaries. Okta's agent identity work tackles authentication for non-human actors — AI agents that need to prove who they are before taking actions. Red Hat's governance track addresses the lifecycle and policy controls around autonomous agents. Strands Agents provides the build-time tooling. Taken together, the contributions sketch a stack: identity, authorization, build-time tooling, model-level probing, and incident response.
The SAFE guidelines fill the operational layer that sits above individual tools. Confidential reporting with blame-free analysis is the model that CERT/CC used for decades in traditional information security, adapted for AI-specific incidents. The open comment period now determines whether that adaptation proves workable for organizations whose incidents may involve prompt injection (crafting inputs that trick a model into unintended behavior), data exfiltration through tool calls, or adversarial inputs that exploit model behavior rather than infrastructure vulnerabilities.
OSAA is a week old. The proposals are open for comment, not finalized. The tooling contributions exist but have not been integrated into any shared framework. What OSAA has shown in its first week is momentum and a coherent division of labor across member companies. What it has not yet shown is whether that momentum produces standards that the broader industry adopts, or whether the companies building the most powerful closed models feel compelled to engage on open security terms they did not help shape.


