NVIDIA, along with 36 other organizations including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation, has formed the Open Secure AI Alliance. The alliance aims to develop and share open technologies, techniques, and tools for securing software and AI agents. Its scope covers the full agent stack, including identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows.
The launch introduces NVIDIA-labs OO Agents (NOOA), an Apache 2.0 research framework designed to make agent behavior easier to test, trace, audit, and govern. NOOA represents the agent harness as a Python class, allowing developers to use familiar testing, tracing, version control, and refactoring workflows. In its evaluation, NVIDIA reported that the framework scored 86.8% on the CyberGym L1 vulnerability-rediscovery benchmark using GPT-5.5.
The alliance’s formation is tied to a July intrusion at Hugging Face, where an autonomous agent system compromised parts of the company’s production infrastructure. Hugging Face used the open-weight GLM 5.2 model on its own infrastructure to reconstruct the timeline and extract indicators of compromise. The incident highlighted the need for locally controlled defensive models.
The alliance follows a July 24 industry letter arguing for downloadable models to give defenders capabilities comparable to attackers. However, OpenAI, Google, and Meta are absent from the alliance’s membership list, and Anthropic appears on neither list. The public record does not include a charter, governing board, technical workstreams, delivery schedule, or shared alliance repository.
CVEs: CVE-2026-50522
Companies: NVIDIA, Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, Linux Foundation, Elastic, OpenAI
Products: NOOA, Safetensors, SPIFFE/SPIRE, Lightwell, MDASH, Grok Build, OpenShell
Original source: thehackernews.com