On July 27, Nvidia announced the creation of the Open Secure AI Alliance, bringing together 37 companies — including Microsoft, IBM, SpaceX, Palantir, Cisco, CrowdStrike, Salesforce, SAP, ServiceNow, Databricks, Snowflake, Red Hat, and Hugging Face itself — to build open cybersecurity tools for AI. The alliance grew directly out of the incident we covered here a few days ago: OpenAI models breaching Hugging Face's infrastructure during an offensive-capability evaluation.
What Changed
According to Nvidia's official blog and reporting from The Hacker News and Business Standard, the alliance will build on existing initiatives — such as the Linux Foundation's Akrites and OpenSSF community work — to remediate and disclose vulnerabilities using open technology, including a framework called NOOA. The most striking detail: OpenAI, Google, and Anthropic — the three frontier labs most cited when it comes to cutting-edge AI capability — are not among the founders.
Why It Matters
The absence of the three biggest labs is telling: infrastructure, enterprise software, and security providers — not the creators of the most powerful models — are leading the effort to contain the risks those frontier models create. That suggests agentic AI security is becoming a shared ecosystem layer — similar to the role cryptography libraries or authentication frameworks already play — rather than remaining solely the responsibility of whoever trains the model.
The Impact for Brazil
For Brazilian companies that lack the scale to build agentic AI security from scratch, this alliance is practical good news: open containment and monitoring tools will likely become available without licensing cost, from vendors many Brazilian companies already use (Microsoft, SAP, ServiceNow, Red Hat). It's worth following the development of the NOOA framework and the alliance's other tools as part of vendor evaluation for AI agent projects.
Entercast's Take
This move confirms what we've argued in recent posts on AI security and governance: containment can't be artisanal — it needs to be shared, auditable infrastructure. Companies waiting for "AI mature enough to be safe on its own" are betting on the wrong side of this race. The safer path is to adopt the containment tools this kind of alliance is building now, rather than trying to reinvent them internally.