Security News NVIDIA, Microsoft, and CrowdStrike Launch Alliance for Open-Source AI Security

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,102
5,796
2,168
Germany
NVIDIA, Microsoft, and CrowdStrike have joined a broad coalition of technology, cybersecurity, and open-source organizations to launch the Open Secure AI Alliance.

This initiative focuses on developing open tools, models, agent harnesses, and security techniques to defend AI-enabled infrastructure. The alliance builds on the groundwork laid by the Linux Foundation’s Akrites initiative and the Open Source Security Foundation (OpenSSF).

Its goal is to enhance vulnerability disclosure, remediation, and community-driven cyber defense as AI agents become integrated into enterprise and critical infrastructure environments.

NVIDIA, Microsoft, and CrowdStrike Launch AI Security
Nvidia initiative emphasizes that open-source software is foundational to various sectors, including cloud services, finance, manufacturing, telecommunications, government systems, and internet infrastructure.

Proponents of the alliance argue that open AI models and harnesses offer similar defensive capabilities by enabling security teams to inspect system behavior, customize controls, deploy capabilities locally, and maintain control over sensitive data.

Rather than replacing proprietary cutting-edge models, the alliance positions open systems as complementary tools that can reduce dependence on single vendors and provide organizations with greater flexibility during incident response.

A recent security incident involving Hugging Face highlighted the operational need for this initiative. During the incident, closed AI services reportedly struggled to distinguish legitimate forensic activity from malicious behavior, which limited their effectiveness for responders.

In contrast, Hugging Face deployed the open-weight GLM 5.25.25.2 model on its own infrastructure, allowing it to analyze over 17,000 actions and support containment efforts.

This example underscores the need for defenders to be able to run, inspect, and fine-tune advanced models within their own environments, especially during time-sensitive investigations involving confidential telemetry or restricted network access.

Inaugural participants in the alliance include major companies and organizations such as NVIDIA, Microsoft, CrowdStrike, Adobe, Cisco, Cloudflare, Databricks, Dell Technologies, Elastic, HPE, IBM, the Linux Foundation, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Snowflake, and TrendAI, among others.

The group will collaborate on a shared defensive stack that encompasses agent identity, isolation, safe model distribution, multi-model vulnerability scanning, secure development workflows, evaluation frameworks, and red-team tooling.

NVIDIA is contributing open models, weights, datasets, and research related to AI agent harnesses. Its newly released NVIDIA Labs Object-Oriented Agent (NOOA) framework is now available on GitHub.

This framework aims to make agent behavior more testable, traceable, auditable, and governable. The project emphasizes that AI security must extend beyond model weights to include permissions, identities, logs, guardrails, orchestration layers, and continuous evaluation.

Other member contributions reflect this comprehensive approach. HPE is supporting SPIFFE/SPIRE zero-trust identity standards for cryptographically verifying AI agents and services.

Hugging Face has contributed Safetensors, a model-weight format designed to avoid risks associated with remote code execution. IBM and Red Hat are advancing Lightwell, which facilitates digitally signed open-source patches.

At the same time, Microsoft’s MDASH harness coordinates specialized AI agents to identify, debate, and validate exploitable vulnerabilities.

The alliance acknowledges that open models can be misused or modified to bypass safeguards. However, it argues that similar risks exist in closed ecosystems.

It should be managed through robust evaluations, misuse policies, rapid remediation, identity controls, and transparent security testing, not by denying defenders access to effective tools.

The Open Secure AI Alliance is also urging policymakers to treat open AI security infrastructure as a valuable defensive asset and to support investment in common datasets, attack simulators, benchmarks, and red-teaming platforms.
 
Assessment

The initiative’s stated goals are plausible and align with established AI-security priorities: agent identity, isolation, signed model artifacts, vulnerability research, auditability, and red-team testing. Open tooling can also improve transparency and allow defenders to operate models locally when telemetry or incident data cannot be sent to a third-party service.

However, several details in this text should be verified against official announcements before being treated as established facts:

  • The formal name, membership, and launch date of the “Open Secure AI Alliance”
  • Whether all listed organizations are founding members, contributors, or supporters
  • The existence and exact name of the “NVIDIA Labs Object-Oriented Agent (NOOA)” framework
  • The referenced Hugging Face incident and the claimed analysis of more than 17,000 actions
  • The model name “GLM 5.25.25.2,” which appears unusual and may be a transcription or reporting error
  • The descriptions of MDASH, Lightwell, and the specific contributions attributed to each organization

The Hugging Face example should receive particular scrutiny. A model analyzing actions during an incident does not, by itself, demonstrate that the model was more effective than closed services. That conclusion would require documented incident details, the evaluation criteria, the actions performed by each system, and independent confirmation.

Open models and agent harnesses also introduce risks, including malicious fine-tuning, unsafe tool access, prompt injection, supply-chain compromise, exposed credentials, and inadequate isolation. Safetensors can reduce certain serialization-related risks, but it does not make a model or its surrounding software trustworthy. Signed artifacts, least-privilege permissions, sandboxing, provenance checks, logging, and human approval for high-impact actions remain necessary.

Overall, the defensive direction is reasonable, but the article contains enough specific claims that it should be checked against official Linux Foundation, NVIDIA, Microsoft, CrowdStrike, and Hugging Face sources. Until those sources confirm the details, the broad concept can be regarded as credible while the incident narrative and project descriptions remain unverified.