The Open Secure AI Alliance has launched with inaugural partners including NVIDIA, Adobe, Akamai, Atlassian, Box, Cadence, Capital One and Cisco, setting out to build and share open technologies, techniques and tools for AI safety and security. The group says it will use those open technologies to remediate and disclose vulnerabilities.
The announcement lands now because AI security has moved from theory to live-fire incident response. Open source software already underpins much of the cloud, enterprise and internet stack, and the alliance is pitching its work as a way to give defenders open models and open harnesses they can inspect, adapt and control rather than rely on black-box systems.
The case for that approach was sharpened by a recent security incident involving Hugging Face. During that intrusion, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the breach, a response the alliance points to as proof that cyber defenders need open, frontier agentic systems for self-defense. The alliance argues that open models can also be misused for attacks, which is why it wants defensive tools built in the open and available to more than a narrow set of users.
The new group builds on the Linux Foundation’s Akrites initiative and OpenSSF community work, and frames the choice facing the United States and its partners as one between opaque systems and open models, harnesses and tools. It says the point is to ensure defenders everywhere have open, frontier tools they can trust and control. What it has not said yet is when the first tools, techniques or vulnerability disclosures will arrive, leaving the launch big on ambition and short on the timetable security teams will be watching for next.

