One week old and already working: the new AI security alliance making its first moves

Over 120 companies, including Nvidia, Microsoft and Visa, have formed a group to share AI security knowledge openly. Big names like OpenAI and Google are conspicuously absent, even though both signed the letter that started it all.

AI2Day Newsdesk4 min read
Aerial view of a vast modern highway interchange at dusk, concrete lanes splitting and merging with precision, motion-blur streaks of vehicle lights tracing pat
Share

Key points

  • The Open Secure AI Alliance (OSAA), led by Nvidia, launched less than two weeks ago and already counts over 120 member companies.
  • A working group called the Shared AI Findings Exchange (SAFE) has published its first draft proposals for public comment.
  • Adobe, Cisco, Intel, Microsoft and Visa are members; OpenAI, Google and Anthropic are not.
  • Both OpenAI and Google signed the original open letter that created the group, making their absence from membership notable.
  • The Linux Foundation, a non-profit that manages widely used open-source software projects, is overseeing the proposals.

A brand-new industry alliance built around keeping AI safe is already doing something unusual for a week-old organisation: actual work.

The Open Secure AI Alliance, known as OSAA and spearheaded by Nvidia, unveiled its first concrete output at the Black Hat cybersecurity conference in Las Vegas this week. Inside OSAA sits a working group called the Shared AI Findings Exchange, or SAFE. Its first draft proposals are already open for public comment, with the Linux Foundation, a non-profit that stewards widely used open-source software, managing the process.

What is the group actually proposing?

The early proposals are practical rather than flashy. They cover how companies should confidentially report AI security incidents, how to alert everyone affected, and how to run blame-free reviews so the whole industry can learn from mistakes.

Members are also pooling open-source tools. Nvidia is contributing a family of open AI models and a tool called Garak, a scanner that hunts for vulnerabilities in large language models (the technology behind AI chatbots). Identity security firm Okta is working on ways to verify the identity of AI agents, software programs that can carry out multi-step tasks on their own. Red Hat is working on governance frameworks for those same agents. Amazon has contributed two tools: Strands Agents, for building AI agents, and Cedar, a language for defining who or what is allowed to do what inside a software system.

The goal, over time, is for these pieces to add up to a practical open-source toolkit that any business could use to secure its AI systems or defend against attacks, including incidents like a rogue AI model infiltrating an external platform. Hugging Face, a popular site for sharing AI models that suffered exactly that kind of incident involving an OpenAI model, is itself a member of OSAA.

Who is in, and who is missing?

The member list carries serious weight. Adobe, BlackRock, Cisco, Intel, Microsoft and Visa have all joined.

Notably absent are Anthropic (which makes the Claude AI assistant), OpenAI (ChatGPT) and Google. That last pair is especially curious. Both companies signed the open letter, first reported by TechCrunch AI, that called on the White House to support open-source AI development. That letter, backed by over 200 tech companies and championed by Nvidia, was published just last week. Signing the letter that created a group and then not joining the group is an odd position to hold.

Anthropric's distance is less surprising. The company has historically kept a cautious distance from open-source AI efforts.

What does this mean for ordinary people?

For now, nothing changes in your daily life. But if this alliance succeeds, the businesses behind the apps and services you use will share security knowledge faster, patch AI vulnerabilities more quickly, and have better tools to stop AI systems from being turned against their users. A blame-free reporting culture, where companies admit problems without fear of punishment, is the kind of structural change that quietly makes technology safer for everyone.

The alliance itself put it plainly in its founding letter: "Openness may be one of the most important paths to AI safety and security." Given the speed at which it has moved so far, that claim deserves to be taken seriously.

Common questions

Is SAFE a government body?

No. SAFE is a private industry working group inside OSAA, managed by the Linux Foundation. It has no regulatory power; participation is voluntary.

Does this affect my AI tools right now?

Not directly. The proposals are in draft form and open for comment. Any tools or standards that emerge will be adopted by member companies at their own pace.

Why does open-source AI matter for security?

When AI code is open for anyone to inspect, security researchers can find and report problems faster. Closed systems rely on the company alone to catch flaws, which historically takes longer.

© 2026 AI2Day