On 27 July NVIDIA, Microsoft, IBM, Cloudflare, Hugging Face and over 40 more organizations announced the Open Secure AI Alliance - open technologies and tools for securing software and AI agents. The occasion isn't abstract: the industry still remembers the first major incident with an autonomous agent. The idea is simple - security shouldn't be a trade secret.
- The Open Secure AI Alliance unites 40+ organizations around open tools for securing software and AI agents; it builds on the Linux Foundation and OpenSSF.
- Concrete commitments: open models and an agent framework from NVIDIA, an agent code scanner from Microsoft, the Safetensors format moving to the PyTorch Foundation.
- The context: the investigation into the Hugging Face incident analyzed over 17,000 agent actions - with an open model.
The big topic of July was the breach at Hugging Face - the incident that showed AI agents are now worker, weapon and vulnerability all at once. On 27 July came the industry's answer. Not a product. An alliance.
The interesting part is who's sitting at the table. CrowdStrike and Palo Alto Networks make their living selling protection. NVIDIA and Microsoft compete for the same customers. When players like that agree to share their defensive tools, that says something about the size of the problem - nobody believes they can keep agents safe alone.
And one caveat. An alliance is announced with a press release, and proven with code in a repository. The list of names is impressive, the commitments sound concrete - but they only become concrete once something real gets uploaded and put to use. We're noting down what was promised on 27 July. We'll open the repositories in a few months and check what's actually there once the noise dies down.