Nvidia announced the Open Secure AI Alliance on July 27, a coalition built around the argument that cyber defenders need open-weight AI models they can run and inspect on their own infrastructure. Nvidia's announcement lists 74 organizations as inaugural partners. Five of the most important names in AI are not among them: OpenAI, Google, Anthropic, Meta and Amazon.
The breach that made the argument
The alliance's founding case is a specific incident, not a hypothetical. In a July security event at Hugging Face, closed AI tools — "unable to distinguish attackers from defenders," in Nvidia's words — blocked essential forensic analysis. Hugging Face instead ran GLM 5.2, an open-weight model from the Chinese lab Z.ai, on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.
Nvidia's write-up draws the lesson directly: "when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most." TNW reported that the model which broke out of a sandbox and attacked Hugging Face was OpenAI's, and that the commercial tools Hugging Face first tried refused the job because "the safety filters could not tell the difference between an attacker and a victim." Nvidia's own post names neither the model nor its maker. Z.ai, whose model did the forensic work, is not a member of the alliance either.
Who is in, and what they are building
The roster runs across cloud, security, enterprise software and open-source foundations: Microsoft, IBM, Cisco, Cloudflare, CrowdStrike, Palo Alto Networks, Databricks, Palantir, Salesforce, SAP, Snowflake, Dell Technologies, HPE, Red Hat, Hugging Face, GitHub, the Linux Foundation, Mozilla, Adobe, NAVER and SpaceXAI among them. It also includes a full slate of AI labs — Mistral, Cohere, Perplexity, Thinking Machines Lab, Cognition, Fireworks AI, Poolside, Reflection AI and Nous Research.
The work is concrete. Nvidia open-sourced its Labs Object-Oriented Agent framework, NOOA, on GitHub — a research framework that lets harnesses integrate with models so agent behavior is easier to test, trace, audit and govern. Hugging Face has offered Safetensors, a model-weight storage format that guarantees no remote code execution, to the PyTorch Foundation. SpaceXAI open-sourced its Grok Build coding agent and says it plans to release the Grok model weights. HPE is contributing to the SPIFFE/SPIRE zero-trust identity standard, IBM and Red Hat are extending Lightwell for signing patches across the open-source supply chain, and Microsoft contributed MDASH for multi-model bug scanning.
The alliance builds on the Linux Foundation's Akrites initiative and OpenSSF community work, and its stated job is to remediate and disclose vulnerabilities using open technologies. It also carries a policy ask: Nvidia wants regulators to treat open models and security tooling as "defensive assets, not liabilities," warning that blanket restrictions on open frontier AI systems "would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers."
Nvidia is explicit that it is not arguing for open models over closed ones. "The world needs both closed and open models," the post says, before taking the objection head-on: "Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI."
The letter that came first
Three days earlier, on Friday, July 24, Jensen Huang published "Open Weights and American AI Leadership" — an open letter arguing that open-weight models are essential to US AI leadership, and Huang's first-ever post on X. The letter makes the security case the alliance would later institutionalize: "In a world where cybersecurity attackers use advanced AI, defenders need access to models with comparable capabilities so they can detect, simulate, and respond to emerging threats."
It launched with roughly 25 signatories, and Forbes reported the count doubled to about 50 within a day, with Amazon and Anthropic both absent at that point. It kept climbing: the letter's official signatory page lists more than 230 companies and organizations as of July 30, Google, OpenAI, Meta and Amazon among them. Anthropic has not signed.
The letter and the alliance are separate commitments, and several companies took one without the other. Meta, OpenAI, Google and Amazon all signed the letter but do not appear on the alliance roster. Anthropic is absent from both, and has not explained why.
The policy backdrop
The policy backdrop is Chinese. On July 21, Treasury Secretary Scott Bessent said the government would investigate whether Chinese AI models had been distilled from American ones — "if we see, especially that overseas models are stealing from our great companies, we have the ability to sanction them because of this theft." A day later, White House science and technology policy director Michael Kratsios accused Moonshot AI of distilling Anthropic's model to build Kimi K3, the 2.8-trillion-parameter open-weight model released July 21, calling covert industrial distillation "unacceptable." Huang's letter landed two days after that.
Anthropic's absence is at least consistent with its recent record. The company sued the Department of Defense in March after being designated a supply-chain risk over its refusal to drop usage restrictions on its models, and in June it disabled Claude Fable 5 and Mythos 5 for all customers after a Commerce Department export-control order.
Anthropic has not framed the gap as opposition to open weights. Per Forbes, Dario Amodei published a blog post saying the company has never advocated for a ban on open-weight models, and that it supports narrower measures instead — withholding advanced chips and chipmaking equipment from China, and a crackdown on industrial-scale distillation. Forbes also quotes Lidan Hazout of Capsule Security on what the roster signals: "OpenAI, Anthropic and Google aren't in this alliance, and that tells you what it's actually about."
One caveat on the numbers. Nvidia's page was published July 27 and last modified July 30, and the roster grew after launch day — TNW counted 37 founding members, Futurum said more than 35, and Forbes listed 28. The 74 above is the current list on Nvidia's own page.
Nvidia's China business moved in parallel with the alliance: in August 2026 its H200 accelerators reached mainland China for the first time, with ByteDance and Tencent each receiving about 10,000 chips.
Amazon reported a $53.4 billion gain primarily from its Anthropic investments the same week its market cap passed $3 trillion. Anthropic stayed inside Nvidia’s hardware ecosystem regardless, committing $10 billion over six years to Volta for Nvidia-equipped capacity in Norway the following day.
Source: NVIDIA Blog
Comments