News

Open Secure AI Alliance Targets Agent Security Across Multi-Vendor Clouds

NVIDIA and 36 other technology, cloud, cybersecurity and enterprise software organizations have launched the Open Secure AI Alliance, an industry effort to develop and share open technologies for protecting software and AI agents. The initiative covers the infrastructure surrounding agents -- including identity, permissions, isolation, harnesses, guardrails, logs and evaluation systems -- rather than focusing only on the security of AI models.

The cloud angle is explicit in the alliance announcement. NVIDIA said open source underpins cloud computing and argued that defenders need systems they can inspect, adapt and run on infrastructure they control. The announcement also calls for security systems that work across a multi-vendor ecosystem and avoid a single point of failure.

The alliance's 37 inaugural partners include Adobe, Capital One, Cisco, Cloudera, Cloudflare, CrowdStrike, Databricks, Dell Technologies, HPE, Hugging Face, IBM, the Linux Foundation, Microsoft, NetApp, Palo Alto Networks, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake and Synopsys. The group describes its objective as building an open defense stack for agents, but it has not announced a single integrated platform, reference architecture or release schedule. Those details are Not documented.

Open Secure AI Alliance
[Click on image for larger view.] Open Secure AI Alliance (source: NVIDIA).

Cloud Workload Identity Moves to the Agent Layer
One of the clearest connections to cloud infrastructure is HPE's work with the Secure Production Identity Framework for Everyone and SPIFFE Runtime Environment projects, commonly known as SPIFFE and SPIRE. NVIDIA said the projects can cryptographically verify AI agents and services so that only authorized workloads communicate with one another and access enterprise resources.

In its statement on joining the alliance, HPE said modern AI systems depend on agent frameworks, harnesses, guardrails, governance mechanisms and models that interact with enterprise environments. HPE identified SPIFFE/SPIRE as part of its contribution and said the framework provides zero-trust identity standards and methods for verifying agents, services and workloads.

The HPE SPIFFE and SPIRE project page describes the technologies as a foundation for service identity in cloud- and container-deployed microservices. SPIFFE defines open standards for authenticating software services through platform-independent cryptographic identities, while SPIRE implements those standards across different hosting environments. HPE also documents integrations with cloud-native technologies including Istio, Envoy, Sigstore and Open Policy Agent.

The SPIFFE project separately describes SPIFFE and SPIRE as a uniform identity control plane for modern, heterogeneous infrastructure spanning virtual machines in public clouds and private data centers. Its documented integrations include Amazon Web Services, Microsoft Azure, Google Cloud, Kubernetes, Istio, Dapr and HashiCorp Consul. Supported use cases include passwordless platform authentication, service-mesh connections, mutual authentication and bridging Kubernetes workloads with other platforms.

HPE has previously documented SPIFFE and SPIRE use within its GreenLake edge-to-cloud platform. According to HPE, the platform uses short-lived cryptographic identities and mutual TLS to authenticate internal and external microservices. HPE described the operational problem as securing applications distributed across data centers, multiple clouds, managed service providers and edge locations. The alliance announcement does not specify whether that GreenLake implementation will become an alliance reference design. That is Not documented.

Alliance Extends Beyond Runtime Security
The initiative also addresses the open source components that enter cloud applications through build, packaging and deployment pipelines. NVIDIA said the alliance will build on the Linux Foundation's Akrites initiative and work from the Open Source Security Foundation community. Akrites was established to coordinate the remediation and disclosure of vulnerabilities in critical open source software.

The Linux Foundation's Akrites announcement describes a shared Security Incident Response Team and a standardized coordinated vulnerability-disclosure process. The initiative provides a confidential coordination point intended to reduce duplicate vulnerability reports and conflicting patches. Fixes are returned to the affected projects' original repositories under their maintainers' terms, and Akrites can act as a maintainer of last resort when a critical package lacks an active maintainer.

IBM and Red Hat are contributing Lightwell to the alliance's broader defense stack. The Lightwell initiative provides access to signed libraries, remediations and patched artifacts for eligible open source vulnerabilities through Red Hat repositories. Red Hat said customers can integrate those repositories with existing software-delivery workflows and build processes.

Red Hat's Lightwell documentation describes two types of signed repositories. Its validated repository contains rebuilt versions of current open source libraries with verified provenance. Its remediated repository provides fixes for specific library versions already used in production, allowing organizations to address vulnerabilities without a full version upgrade or application-code modification. The repositories are documented as compliant with Supply Chain Levels for Software Artifacts Level 3.

Open Harnesses Address the Rest of the Agent Stack
The alliance announcement states that an AI agent is more than its underlying model. NVIDIA defines the agent stack as including models, harnesses, guardrails, identity, permissions, logs and evaluation mechanisms. The group says open harnesses allow defenders to inspect, test and improve those controls while operating defensive systems on their own infrastructure.

NVIDIA is contributing models, weights, data and agent-harness research. Its new NVIDIA Labs Object-Oriented Agents project, or NOOA, is an open source research preview that represents an agent as a Python class. Methods define capabilities, fields hold state, docstrings provide prompts and type annotations act as contracts. NVIDIA said the design allows agents to be tested, traced, reviewed, versioned and refactored with conventional software-development tools.

Microsoft's contribution is MDASH, a multi-model agentic scanning harness that coordinates specialized agents to discover, evaluate and demonstrate exploitable software defects. Hugging Face has offered its Safetensors model-weight format to the PyTorch Foundation, while IBM and Red Hat are contributing Lightwell's digitally signed patches. SpaceXAI is contributing the open source Grok Build coding agent, according to NVIDIA.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

Subscribe on YouTube