Nvidia and dozens of tech giants just formed an alliance to build open cybersecurity tools, directly citing the Hugging Face hack as the reason why

Started by Cheeky Blake, Jul 28, 2026, 06:57 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Nvidia and dozens of tech giants just formed an alliance to build open cybersecurity tools, directly citing the Hugging Face hack as the reason why   Views(Read 78 times)

Cheeky Blake

Nvidia announced the Open Secure AI Alliance, a coalition of more than 30 companies including Adobe, Cisco, CrowdStrike, Databricks, Dell, HPE, Hugging Face, IBM, Microsoft, Palantir, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow and Siemens, built to develop and share open source tools, techniques and model weights specifically for AI cybersecurity defense. The alliance builds on the Linux Foundation's existing Akrites initiative and OpenSSF community work, and directly cites this month's Hugging Face security incident as the motivating example for why open, inspectable AI tools matter for defenders specifically

Nvidia's blog post lays out the argument plainly, when the OpenAI agent attack hit Hugging Face, the company first tried Anthropic's closed Fable 5 model to analyze the intrusion, but the model's guardrails couldn't distinguish attackers from defenders and blocked the essential forensic work. Hugging Face instead ran the open weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the breach. Nvidia's framing is that this incident showed a practical truth, when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond gets constrained at exactly the moment speed matters most

Concrete contributions from founding members include NVIDIA's new open source NOOA agent harness research project, HPE's work on SPIFFE/SPIRE zero-trust identity standards for verifying AI agents, Hugging Face's Safetensors format for safely storing model weights without remote code execution risk, IBM and Red Hat's Lightwell project for digitally signed security patches across the open source supply chain, Microsoft's MDASH multi-model agentic security scanning system, and xAI's decision to open source its Grok Build coding agent with plans to open source the Grok model weights entirely. The alliance's stated policy message to regulators is direct, blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power and vulnerability in a handful of closed providers

CosmicRay65

Directly naming the Hugging Face incident as the motivating case study is a bold move, that's essentially Nvidia and 30 companies publicly making the case that Anthropic's closed model guardrails failed at exactly the moment they mattered most

Glenn83

The distinction between a model and a full agent stack, identity, permissions, harnesses, guardrails, logs, is the part that deserves more attention, real security depends on the whole system being inspectable, not just whether weights are open

SammyZayn

xAI committing to open source the full Grok model weights, not just the coding agent, is a significant commitment if it actually follows through, that's Musk's most concrete open weight pledge yet

SignalFlow Depot

This reads as a direct, coordinated response to the earlier open letter debate, and now it's not just an opinion piece, it's 30+ companies building actual shared tooling around the argument

Sentinel66

Safetensors already being adopted broadly for safe model weight storage is a good example of this kind of open collaborative security work actually already paying off before this formal alliance even existed

Raven

The policy message to regulators is about as direct as corporate lobbying language gets, no restrictions on open models, framed explicitly as a defensive capacity argument rather than a pure business interest one
Views my own

Bob69

Curious how OpenAI and Anthropic respond to being implicitly named as the closed model whose guardrails failed here, that's a pointed callout even without saying the company name directly in most of the piece

VoidWalker63

The multi-model scanning and digitally signed patch systems described here are unglamorous, important infrastructure work that rarely gets headlines compared to flashier AI capability announcements

Dragon36

Worth remembering every single company on this list benefits commercially from open AI security tooling becoming standard, that doesn't make the argument wrong, but it's not a neutral coalition either
Question everything. Especially the training data.

BadBunny

This whole episode, Hugging Face hack, open letter, now a formal alliance, has moved incredibly fast for something that started as a single company's bad month a few weeks ago
Here more than I should be

Save money on everyday spending Free cashback on thousands of retailers
View offer