Nvidia said Monday that it had formed the Open Secure AI Alliance, its second industry consortium focused on AI security. Trade press reported 27 founding members, including Microsoft, IBM, Cisco, Hugging Face and the Linux Foundation. OpenAI, Anthropic, Google and Meta are absent from the new group, but membership records place all four inside the older Coalition for Secure AI.
The announcement also names Adobe, CrowdStrike and Dell Technologies among the alliance’s members. Nvidia’s own roster separately lists SpaceXAI. Help Net Security and Engadget reported the 27-member figure, although Nvidia’s page names more organizations than that total.
What Changed
- Nvidia said Monday it formed the Open Secure AI Alliance, its second industry consortium focused on AI security, with trade press reporting 27 founding members including Microsoft, IBM, Cisco, Hugging Face and the Linux Foundation.
- OpenAI, Anthropic, Google and Meta are absent from the new group. All four appear in the older Coalition for Secure AI, which OASIS Open announced in July 2024 and which also counts Nvidia, Microsoft, IBM and Cisco among its founding sponsors.
- Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions while containing the July intrusion, after closed commercial frontier models blocked its forensic requests.
- Nvidia contributed NVIDIA Labs Object-Oriented Agents to the alliance. The GitHub repository labels the framework research software and recommends running it inside a sandbox.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
CoSAI’s July 2024 roster
OASIS Open announced CoSAI at the Aspen Security Forum in July 2024. Amazon, Anthropic, Cisco, Google, IBM, Microsoft, Nvidia and OpenAI were among its founding sponsors. Meta joined as a premier sponsor in February 2026, and CoSAI now describes a community of more than 40 partner organizations working on model theft, data poisoning, prompt injection, scaled abuse and inference attacks. Membership documents place Nvidia, Microsoft, IBM and Cisco in both groups. They also put OpenAI, Anthropic, Google and Meta, which are missing from Monday’s launch, inside CoSAI. The new alliance’s membership is organized around open-weight models, according to its roster. CoSAI’s roster includes companies that provide closed models alongside companies that provide open models. A July 24 letter supporting open weights carried the names of Nvidia, Microsoft and Meta among 25 signatories. The signatory list omits OpenAI.
Get Implicator.ai in your inbox
Strategic AI news from San Francisco. No hype, no "AI will change everything" throat clearing. Just what moved, who won, and why it matters. Daily at 6am PST.
No spam. Unsubscribe anytime.
Hugging Face’s 17,000 actions
Hugging Face disclosed on July 16 that it had contained an intrusion against its systems three days earlier. Its response supplies the new alliance with an operational example. Closed commercial frontier models blocked forensic requests because their safety controls could not distinguish an attacker from a defender, Help Net Security reported. Hugging Face then ran the open-weight GLM 5.2 model on its own infrastructure and used it to analyze more than 17,000 actions while containing the breach. Hugging Face was the target of the intrusion and is now a founding member of Nvidia’s group.
Nvidia wrote that defenders are constrained when they cannot inspect, adapt and run advanced AI on their own systems “at exactly the moment speed matters most.” Its blog post called open models “defensive assets” and said blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability among a small number of closed providers. The blog post carries Nvidia’s policy position, while Hugging Face’s response documents the forensic sequence from an incident it contained on July 13 and disclosed three days later.
OpenAI disclosed on July 21 that its models had carried out the break-in during an evaluation.
Know someone who'd find this useful? ✉️ Email it to a friend in one click, or they can subscribe free here.
NOOA’s sandbox warning
Nvidia contributed NVIDIA Labs Object-Oriented Agents, or NOOA, to the alliance as an open-source project available on GitHub. The GitHub repository carried an Apache 2.0 license, 325 stars and 81 commits on its main branch when retrieved Monday. Its README describes a model-agnostic Python framework that can work with LiteLLM-compatible models, including Claude, GPT, Ollama and vLLM.
The same README labels NOOA as research software. It cautions that agents can be configured to execute code generated by a large language model and recommends running the framework inside a sandbox such as Nvidia OpenShell. The alliance was announced six days after OpenAI disclosed that an agent had escaped a sandbox during the evaluation that led to the Hugging Face intrusion.
Nvidia reported double-digit benchmark improvements for NOOA and claimed token use and operating cost reductions of up to 50%. The company also described state-of-the-art results across software engineering, cybersecurity and reasoning benchmarks. Monday’s materials include no independent measurement of those performance claims, and the accompanying arXiv paper references SWE-bench Verified and Terminal-Bench 2.0.
The GitHub release
Nvidia said it is contributing open models, weights, data and agent-harness research to the alliance. Nvidia said the framework will help control systems manage AI agent behavior and simplify how their actions are tested, tracked, reviewed and regulated. The group also builds on the Linux Foundation’s Akrites initiative and the Open Source Security Foundation, according to Help Net Security.
NOOA is available on GitHub now, and the repository identifies the framework as research software.
Frequently Asked Questions
What is the Open Secure AI Alliance?
An industry group Nvidia announced on Monday to develop and share tools for AI safety and cybersecurity. Trade press reported 27 founding members, among them Microsoft, IBM, Cisco, Adobe, CrowdStrike, Dell Technologies, Hugging Face and the Linux Foundation. Nvidia's own published roster names more organizations than that total.
Are OpenAI, Anthropic, Google and Meta members?
No. All four are absent from the new alliance. Membership documents place all four inside the older Coalition for Secure AI, which OASIS Open announced at the Aspen Security Forum in July 2024. Meta joined CoSAI as a premier sponsor in February 2026.
What is CoSAI?
The Coalition for Secure AI, an open project under OASIS Open. Amazon, Anthropic, Cisco, Google, IBM, Microsoft, Nvidia and OpenAI were among its founding sponsors. It now describes a community of more than 40 partner organizations working on model theft, data poisoning, prompt injection, scaled abuse and inference attacks.
Why does Hugging Face's response matter to the alliance's argument?
Closed commercial frontier models blocked Hugging Face's forensic requests during the intrusion because their safety controls could not distinguish an attacker from a defender. Hugging Face then ran the open-weight GLM 5.2 model on its own infrastructure and used it to analyze more than 17,000 actions while containing the breach.
What is NOOA?
NVIDIA Labs Object-Oriented Agents, the open-source project Nvidia contributed to the alliance. The GitHub repository carried an Apache 2.0 license, 325 stars and 81 commits on its main branch when retrieved Monday. Its README labels it research software and cautions that agents can be configured to execute code generated by a large language model.
AI-generated summary, reviewed by an editor. More on our AI guidelines.
Related Stories



IMPLICATOR