Open Secure AI Alliance Moving Under Linux Foundation

Governance of the Open Secure AI Alliance has moved to the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

The Linux Foundation announced the transition Sept. 2, saying the Alliance will continue work intended to help organizations inspect, audit, and secure AI systems. The change follows the Alliance's July launch, when its stated scope already extended beyond AI models into agent runtimes, identity, permissions, isolation, guardrails, and other infrastructure controls.

The Linux Foundation said the new governance model is intended to support collaboration across vendors, platforms, and industries. The Alliance's current project site similarly describes its work as an open defensive stack of AI models, tools, and techniques that defenders can inspect, adapt, and run on infrastructure they control.

Neutral Governance for a Multi-Vendor Stack

The Linux Foundation said the transfer puts the Alliance under its neutral governance, with the goal of accelerating a shared, open security stack for AI. "AI security is a shared challenge," the Foundation said in announcing the move, adding that organizations need to collaborate across vendors, platforms, and industries.

The governance change formalizes a role the Linux Foundation had already begun playing. When the Alliance launched July 27, the Foundation joined as an inaugural partner alongside NVIDIA, Microsoft, and other cloud, security, enterprise software, and AI organizations. The Linux Foundation said at the time that its role was to provide a neutral environment where organizations that also compete can collaborate on shared infrastructure.

Open Secure AI Alliance Inaugural Members (From July)
[Click on image for larger view.] Open Secure AI Alliance Inaugural Members (From July) (source: NVIDIA).

NVIDIA's original Alliance announcement framed that infrastructure requirement in multi-vendor terms. It said defenders need the ability to inspect, adapt, and operate advanced AI on infrastructure they control, while critical industries need defensive tools capable of supporting security systems across a multi-vendor ecosystem without creating single points of failure.

The Alliance's current site makes portability another part of that model. "Portable defenses remain effective as models, vendors, and environments change," it states. The site says those defenses should support flexibility across models, infrastructure, applications, and security services.

Its definition of the agent security stack also reaches into areas familiar to cloud and platform teams. The Alliance identifies models and inference, agent context, harnesses, policy, identity, governance, enforcement, containment and recovery, and a trusted foundation that includes hardware identity, isolation, protected keys, and evidence.

Whole Agent Stack
[Click on image for larger view.] Whole Agent Stack (source: Linux Foundation).

The site says organizations need to govern the full agent stack rather than treating the language model as the complete security boundary. It identifies runtimes, identity, policy, enforcement points, observability, and recovery as parts of the system that need to be open, testable and auditable.

SAFE Extends the Scope to Cloud Providers

One of the Alliance's active projects is the Shared AI Findings Exchange, or SAFE, a proposed incident-learning and assurance framework. The SAFE Request for Comments calls for confidential collection and analysis of AI incidents and near misses, notification of affected parties, and conversion of recurring failures into evidence-based security controls.

SAFE's proposed membership includes model developers, AI deployers, enterprise customers, independent security researchers, critical-infrastructure operators, government and standards organizations, and "evaluation, hosting, cloud, and tool providers."

The Linux Foundation's August description of SAFE likewise invited AI developers, enterprises, cloud providers, researchers, and infrastructure operators to help shape the proposal. It said structured incident reviews should cover the complete AI operating stack, including models, safeguards, tools, runtime environments, monitoring, human operations, and supply-chain dependencies.

SAFE goes further by identifying cloud infrastructure as a possible dependency in an incident investigation. Its proposed review framework asks whether a cloud, evaluation, data, or tooling partner invalidated assumed controls. Evidence preservation could include prompts, traces, tool calls, logs, configurations, model and safeguard versions, third-party dependencies, workload identities, credentials, approval events, and a complete incident timeline.

The proposal also describes defensive measures that could result from that shared incident analysis, including reusable tests, machine-readable policies, detection rules, reference configurations, and incident-response guidance. For unintended access to real systems, the RFC lists possible recommendations such as default-deny network egress, target allowlists, independent isolation checks, real-time action monitoring, and automatic stops when an agent's permitted scope is uncertain.

Industry Contributions

Microsoft was among the organizations identified as inaugural Alliance partners. NVIDIA's launch announcement also identified Microsoft's MDASH as one contribution to the Alliance's broader defense stack, describing it as a multi-model agentic scanning harness that coordinates specialized AI agents to discover, debate, and demonstrate exploitable software bugs.

Other documented contributions cover separate layers of the same stack. NVIDIA cited HPE's SPIFFE/SPIRE work for workload and service identity, Hugging Face's Safetensors format for model weights, IBM and Red Hat's Lightwell work around signed patches, and NVIDIA's own models, weights, data, and agent-harness research.

Those contributions reinforce the Alliance's stated focus on controls surrounding agents rather than a single model or deployment environment. NVIDIA described the scope at launch as including identity, isolation, model formats, multi-model scanning, and secure coding workflows.

For more information, go to the Open Secure AI Alliance site.

Featured

  • lock symbol with quantum bits in dynamic motion

    Microsoft Accelerates Quantum-Safe Security Timeline

    Microsoft is speeding up its quantum-safe security timeline, noting that advances in quantum computing and new federal requirements have pushed post-quantum cryptography from a future planning issue into an immediate engineering priority.

  • circuit patterns

    Anthropic Intros Lower-Cost Claude Sonnet 5

    Anthropic has launched Claude Sonnet 5, positioning the model as its most autonomous mid-tier offering to date and a lower-cost alternative to its flagship Opus 4.8 system. The company said the model can plan multi-step tasks, operate tools such as browsers and terminals, and complete agentic work at a level that previously required larger and more expensive models.

  • lock icons, shields, and glowing data paths

    Studies Suggest AI Is Accelerating Familiar Cyber Attacks

    Research released around the recent Black Hat USA 2026 conference demonstrates that artificial intelligence is increasing the speed and scale of cybersecurity activity without replacing the attack methods defenders already face.

  • Artwork depicting the potential impact of misinformation and overstimulation on the internet social media

    We Must Teach Students How to Spot Misinformation: Teaching Digital Literacy Is Critical for K–12 Classrooms

    Learning how to question and analyze are skills that must be honed and practiced. Educators must help train minds to look for flawed arguments, misuse of data, or outright lies so we can ensure that as students form their own thoughts on issues, they are grounding them in reality.