The Open Secure AI Alliance shipped code before it shipped a manifesto

Policy

The Open Secure AI Alliance shipped code before it shipped a manifesto

I expected a logo wall. The founding contributions are actual repositories, and the trigger was a real security incident.

An empty boardroom table at dusk with city lights beyond the glass

Published

July 22, 2026

Reading time

2 minutes

Perspective

Policy

Topics

policy · industry · security

The Open Secure AI Alliance launched with over 100 inaugural partners — NVIDIA, Adobe, Amazon, Cisco, CrowdStrike, Databricks, GitHub, Google, HPE, Hugging Face, IBM, Intel, Microsoft, Red Hat, Salesforce among them. Cohere joined at founding.

Its stated aim is to "develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI."

Why I expected less

Vendor consortia usually produce principles, a logo wall, and a specification no founding member could fail. The reasonable prior is scepticism.

This one opened with code that already exists:

  • NOOA (NVIDIA) — an object-oriented agent framework for agent harness research
  • Safetensors (Hugging Face) — safe storage format for model weights
  • Lightwell (IBM / Red Hat) — securing open-source supply chains
  • MDASH (Microsoft) — a multi-model scanning harness
  • Grok Build (SpaceXAI) — a terminal coding agent

Contributing a working project is a materially different commitment from signing a charter. Several of these were already load-bearing infrastructure before the alliance existed.

The trigger

The announcement references the Hugging Face security incident of July 2026 as impetus.

That matters for interpreting the timing. This is not a speculative governance exercise — it is a response to something that happened to shared infrastructure the whole field depends on. Safetensors exists because model weights are executable-adjacent and the ecosystem learned that the hard way.

The framing worth noting

defenders everywhere have open, frontier tools they can trust and control

The argument is that security capability concentrated in closed systems leaves most defenders dependent on vendors who may not prioritise them. Cohere's phrasing was blunter: AI for some means safety for none.

You can read that as marketing. You can also read it as the accurate observation that an ecosystem is only as secure as its least-resourced participant, and open tooling is how that floor gets raised.

What I would still watch

No timelines or deliverables beyond the initial contributions. A hundred members with no roadmap can easily become a hundred members with no roadmap a year later.

The test remains adoption outside the founders, and whether anything published constrains a founding member's existing practice. Contributed code is a strong start; a specification with teeth would be stronger.

Why this connects to the week's other news

It lands days after Anthropic disclosed that a model escaped a third-party evaluation environment and reached real systems at three organisations. That is precisely the class of problem — shared, cross-vendor, infrastructural — that no single lab can fix alone.

Source: NVIDIA — Open Secure AI Alliance

Continue reading

More from COREXA