News

NVIDIA-Founded Open Secure AI Alliance Moves to Linux Foundation

The Open Secure AI Alliance, launched by NVIDIA in July to develop open security technologies for AI systems and agents, has moved under the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices.

The Linux Foundation announced the transition Sept. 2, saying the Alliance will continue work intended to help organizations inspect, audit and secure AI systems. The change follows the Alliance's July launch, when its stated scope already extended beyond AI models into agent runtimes, identity, permissions, isolation, guardrails and other infrastructure controls. Earlier coverage from Virtualization & Cloud Review examined that infrastructure focus and its applicability to multi-vendor cloud environments.

The Linux Foundation said the new governance model is intended to support collaboration across vendors, platforms and industries. The Alliance's current project site similarly describes its work as an open defensive stack of AI models, tools and techniques that defenders can inspect, adapt and run on infrastructure they control.

Neutral Governance for a Multi-Vendor Stack
The Linux Foundation said the transfer puts the Alliance under its neutral governance, with the goal of accelerating a shared, open security stack for AI. "AI security is a shared challenge," the Foundation said in announcing the move, adding that organizations need to collaborate across vendors, platforms and industries.

The governance change formalizes a role the Linux Foundation had already begun playing. When the Alliance launched July 27, the Foundation joined as an inaugural partner alongside NVIDIA, Microsoft and other cloud, security, enterprise software and AI organizations. The Linux Foundation said at the time that its role was to provide a neutral environment where organizations that also compete can collaborate on shared infrastructure.

Open Secure AI Alliance Inaugural Members (From July)
[Click on image for larger view.] Open Secure AI Alliance Inaugural Members (From July) (source: NVIDIA).

NVIDIA's original Alliance announcement framed that infrastructure requirement in multi-vendor terms. It said defenders need the ability to inspect, adapt and operate advanced AI on infrastructure they control, while critical industries need defensive tools capable of supporting security systems across a multi-vendor ecosystem without creating single points of failure.

The Alliance's current site makes portability another part of that model. "Portable defenses remain effective as models, vendors, and environments change," it states. The site says those defenses should support flexibility across models, infrastructure, applications and security services.

Its definition of the agent security stack also reaches into areas familiar to cloud and platform teams. The Alliance identifies models and inference, agent context, harnesses, policy, identity, governance, enforcement, containment and recovery, and a trusted foundation that includes hardware identity, isolation, protected keys and evidence.

Whole Agent Stack
[Click on image for larger view.] Whole Agent Stack (source: Linux Foundation).

The site says organizations need to govern the full agent stack rather than treating the language model as the complete security boundary. It identifies runtimes, identity, policy, enforcement points, observability and recovery as parts of the system that need to be open, testable and auditable.

SAFE Extends the Scope to Cloud Providers
One of the Alliance's active projects is the Shared AI Findings Exchange, or SAFE, a proposed incident-learning and assurance framework. The SAFE Request for Comments calls for confidential collection and analysis of AI incidents and near misses, notification of affected parties and conversion of recurring failures into evidence-based security controls.

SAFE's proposed membership includes model developers, AI deployers, enterprise customers, independent security researchers, critical-infrastructure operators, government and standards organizations, and "evaluation, hosting, cloud and tool providers."

The Linux Foundation's August description of SAFE likewise invited AI developers, enterprises, cloud providers, researchers and infrastructure operators to help shape the proposal. It said structured incident reviews should cover the complete AI operating stack, including models, safeguards, tools, runtime environments, monitoring, human operations and supply-chain dependencies.

SAFE goes further by identifying cloud infrastructure as a possible dependency in an incident investigation. Its proposed review framework asks whether a cloud, evaluation, data or tooling partner invalidated assumed controls. Evidence preservation could include prompts, traces, tool calls, logs, configurations, model and safeguard versions, third-party dependencies, workload identities, credentials, approval events and a complete incident timeline.

The proposal also describes defensive measures that could result from that shared incident analysis, including reusable tests, machine-readable policies, detection rules, reference configurations and incident-response guidance. For unintended access to real systems, the RFC lists possible recommendations such as default-deny network egress, target allowlists, independent isolation checks, real-time action monitoring and automatic stops when an agent's permitted scope is uncertain.

Microsoft Remains Part of the Alliance
Microsoft was among the organizations identified as inaugural Alliance partners. NVIDIA's launch announcement also identified Microsoft's MDASH as one contribution to the Alliance's broader defense stack, describing it as a multi-model agentic scanning harness that coordinates specialized AI agents to discover, debate and demonstrate exploitable software bugs.

Other documented contributions cover separate layers of the same stack. NVIDIA cited HPE's SPIFFE/SPIRE work for workload and service identity, Hugging Face's Safetensors format for model weights, IBM and Red Hat's Lightwell work around signed patches, and NVIDIA's own models, weights, data and agent-harness research.

Those contributions reinforce the Alliance's stated focus on controls surrounding agents rather than a single model or deployment environment. NVIDIA described the scope at launch as including identity, isolation, model formats, multi-model scanning and secure coding workflows.

About the Author

David Ramel is an editor and writer at Converge 360.

Featured

Subscribe on YouTube