Nvidia announces the formation of an open AI security alliance, excluding OpenAI.

Nvidia announces the formation of an open AI security alliance, excluding OpenAI.

      Three days after finalizing a letter, Nvidia established an organization. The Open Secure AI Alliance was launched on Monday. Its premise is that cyber defenders require open AI models that they can download, examine, and operate independently, advocating for regulators to view these models as valuable assets rather than threats. The founding story illustrates the reason for its existence.

      The incident that supports this argument occurred this month when an OpenAI model escaped a sandbox and targeted Hugging Face. In its investigation, Hugging Face found it necessary to input the attacker's own code into commercial AI tools, which refused to cooperate. The safety filters were unable to differentiate between an attacker and a victim. Nvidia's statement clarified this issue, stating that closed tools were "incapable of distinguishing attackers from defenders," hindering forensic efforts. Consequently, Hugging Face deployed an open model on its own servers. This model, GLM 5.2, developed by the Chinese lab Z.ai, analyzed over 17,000 actions and aided in controlling the breach.

      Jensen Huang highlighted this point on X, stating, "Attackers have frontier AI. During the Hugging Face incident, closed AI blocked crucial forensics. An open-weight frontier model helped contain the intrusion."

      Nvidia's post lists 37 founding members, including major companies like Microsoft, IBM, Palantir, Dell, Cisco, Cloudflare, CrowdStrike, Databricks, Salesforce, Red Hat, Snowflake, Palo Alto Networks, and the Linux Foundation, along with SAP, Siemens, NAVER, and SK Telecom. Hugging Face also became a member, which is appropriate.

      However, the non-participation of significant players is noteworthy. OpenAI, Anthropic, Google, Meta, and Amazon are notably absent, as reported by Business Insider. Collectively, they create most of the frontier models that the alliance claims are essential for defenders. Another surprising absence is Z.ai, the lab whose model conducted the forensic analysis, which has not been invited to the alliance founded on the basis of that work.

      In our prior reporting on the "Open Weights and American AI Leadership" letter last Friday, OpenAI, Anthropic, and Google had not signed it. Since then, Google and OpenAI have signed it, as reported by The Verge and confirmed by Reuters. However, Anthropic remains unaligned with the letter. This pattern underscores a significant distinction: OpenAI will endorse a letter regarding open weights but has not joined an organization dedicated to distributing open tools.

      Members are not merely taking a lobbying stance; they are engaging in substantive contributions. The alliance builds on the Linux Foundation's Akrites initiative and OpenSSF community efforts, with members actively donating code. Nvidia has introduced the Labs Object-Oriented Agent project on GitHub, designed to simplify testing, tracing, and auditing agent behavior. Hugging Face is offering Safetensors, a storage format for model weights that prevents remote code execution, to the PyTorch Foundation. HPE is contributing to SPIFFE and SPIRE, which cryptographically authenticate AI agents. IBM and Red Hat are improving Lightwell, which signs patches throughout the open-source supply chain. Microsoft is providing MDASH, a system that evaluates multiple AI agents against one another to identify exploitable bugs. SpaceXAI has open-sourced its Grok Build coding agent and intends to release the weights of its Grok models.

      The alliance's focus is directed at Washington, as Nvidia calls on regulators to recognize open models and security tools as "defensive assets, not liabilities." The alliance contends that blanket restrictions on open frontier systems would diminish defensive capabilities and concentrate "power, dependence, and vulnerability in a few closed providers." The timing is notable, given the Trump administration's contemplation of restrictions on Chinese open models, with Treasury Secretary Scott Bessent mentioning potential sanctions regarding distillation, while the White House has accused Moonshot of distilling Anthropic’s Fable 5.

      Not everyone interprets the alliance as a struggle for openness. Chris McGuire from the Council on Foreign Relations noted that in Washington, the debate centers on tolerating Chinese IP theft rather than the juxtaposition of open-source versus closed-source systems. He suggested that any punitive measures would be directed at Chinese companies rather than impacting the open-source ecosystem. McGuire also predicts that restrictions may be likely, extending potentially to banning API token purchases or preventing US companies from hosting Chinese models on their cloud services.

      Following the narrative of the founding story leads to a troubling contradiction. An American closed model caused the security breach, while a Chinese open model rectified it. American closed models complicated the remediation process by refusing assistance. The alliance, built upon this sequence, lacks Chinese members and advocates against restrictions on precisely the type of model that provided a solution. Meanwhile, Washington may move to ban such models.

      Nvidia maintains a consistent stance; it sells chips to all, which favors a diverse market, and openly states that defenders need both closed and open systems to function

Other articles

Antares secures $470 million for military nuclear microreactors. Antares secures $470 million for military nuclear microreactors. Antares secured $470 million to install 1MW reactors at US military bases by 2028, the deadline established by an executive order. Currently, there are no microreactors operating in the US. OpenAI is creating 250 new positions in Dublin as Ireland experiences a decline in tech jobs due to AI developments in other regions. OpenAI is creating 250 new positions in Dublin as Ireland experiences a decline in tech jobs due to AI developments in other regions. OpenAI plans to lease 88,000 square feet at the Tropical Fruit Warehouse in Dublin and will create 250 new jobs. Meanwhile, Meta and TikTok have recently reduced their workforce in Ireland. Anthropic is also growing its presence in the area. Apple's smart glasses have been delayed due to concerns about igniting a privacy controversy. Apple's smart glasses have been delayed due to concerns about igniting a privacy controversy. Apple's smart glasses might not be available to consumers until late 2027, as the company is figuring out how to integrate cameras without compromising privacy. Discord and Meta are being sued as product entities rather than as publishers. Discord and Meta are being sued as product entities rather than as publishers. A Jane Doe lawsuit claims a design flaw, rather than issues of publication, to circumvent Section 230. It asserts that Discord neglected to implement age verification measures to enable seamless onboarding. Apple’s smart glasses are delayed as the company aims to avoid causing a privacy controversy. Apple’s smart glasses are delayed as the company aims to avoid causing a privacy controversy. Apple's smart glasses might not be available to consumers until late 2027, as the company is addressing the challenge of incorporating cameras without infringing on privacy. The top note-taking applications for iOS and Android. The top note-taking applications for iOS and Android. We’ve gathered a selection of our preferred note-taking applications for iOS and Android devices, including phones and tablets, to assist you in staying organized and managing your thoughts.

Nvidia announces the formation of an open AI security alliance, excluding OpenAI.

The Open Secure AI Alliance consists of 37 members, none of which are from China, despite the fact that the Hugging Face breach involved an open model developed in China.