Nvidia’s AI Security Alliance Moves Fast

Nvidia just proved that its new AI security coalition isn’t going to sit around drafting mission statements. According to TechCrunch AI, the Open Secure AI Alliance (OSAA), an industry group Nvidia spun up barely a week ago, has already grown past 120 companies and shipped its first working group. That group has a name: the Shared AI Findings Exchange, or SAFE. And it’s already putting proposals up for public comment.

What stands out here is the speed. Most industry consortia spend months on logistics before producing anything. This one built its first proposals while members were mingling at Black Hat in Las Vegas this week, the biggest gathering in the cybersecurity world. The Linux Foundation, itself a member, is managing the proposals.

What SAFE actually covers

The first batch of guidelines is practical, not revolutionary. TechCrunch AI reports they focus on the plumbing of AI security incidents:

  • How to confidentially report an AI cybersecurity incident
  • How to alert the people and organizations affected
  • How to run blame-free analysis afterward so everyone learns from it

That blame-free framing matters. It’s borrowed from mature security and aviation practices, where the goal is understanding what broke, not punishing whoever reported it. Applied to AI, it could make companies far more willing to disclose when an agent goes rogue or a model gets exploited.

Alongside the guidelines, members are contributing pieces of their own open source tech. A few examples from the reporting:

  • Nvidia is offering a family of open models plus Garak, an open source scanner for LLM vulnerabilities
  • Okta is working on identity tech for AI agents
  • Red Hat is building agent governance
  • Amazon has contributed Strands Agents, an open agent-building tool, and Cedar, an authorization language

String those together and you start to see the endgame: an open source toolkit an enterprise could use to secure its AI agents, or defend against an attacking one. TechCrunch AI points to a real case that makes this concrete, an OpenAI model that infiltrated Hugging Face. Hugging Face, notably, is now a member of this group.

Who’s in, who’s sitting out

The roster reads like a who’s who: Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa are all in. The absences are just as telling. Anthropic, OpenAI, and Google haven’t joined.

Here’s the twist. Both OpenAI and Google signed the original open letter that spawned this whole thing, the one urging the White House to back open source AI rather than crush it. That letter was championed by Nvidia and signed by more than 200 companies. Anthropic’s absence isn’t a shock, but OpenAI and Google staying out is worth watching, especially since both have shipped open weight models of their own and Google has a long open source track record. TechCrunch AI suggests they may still join as momentum builds.

Why this matters now

The context explains the urgency. Just a couple of weeks ago, news broke that the Trump administration was weighing a ban on Chinese open weight models. That rattled the industry and triggered the open letter, which argued Washington should support open efforts, not squash them.

The argument from open weight advocates is that openness is the defense, not the vulnerability. As the CTO of U.S. open weight lab Arcee frames it in the reporting, an open ecosystem is ultimately the best way to counter any threat, real or imagined, from Chinese AI labs. The group put it plainly in its letter: “Openness may be one of the most important paths to AI safety and security.”

For practitioners, the practical takeaway is this. If SAFE’s incident-reporting standards and the contributed tooling mature into real, adoptable frameworks, teams securing AI agents could get a shared, vendor-neutral playbook instead of stitching together proprietary point solutions. That’s a meaningful shift from the status quo, where AI security has been fragmented and mostly closed.

It’s early. These are proposals, not standards, and the biggest AI labs are still on the sidelines. But a heavyweight group that moves from open letter to working proposals in a single week is signaling something. They’re ready to put their tech where their letter was. Watch whether OpenAI and Google join, and whether SAFE’s guidelines harden into something enterprises actually deploy. You can find the full details at the original TechCrunch AI report.

Scroll to Top