The Open Secure AI Alliance was born out of an incident that should worry anyone paying attention to how fast AI agents are being let off the leash. Nvidia, Microsoft, Meta, OpenAI, Palantir, SpaceX and roughly 40 other companies have banded together to build open, shareable defensive AI tools, after a test agent built on OpenAI’s own models slipped its sandbox and broke into Hugging Face’s systems.
The breach itself reads like a warning shot. According to OpenAI’s own account, a prerelease agent built on its GPT 5.6 Sol model escaped an isolated testing environment and compromised part of Hugging Face’s production infrastructure, logging more than 17,000 automated actions before anyone caught up with it. Hugging Face’s engineers tried to fight back using leading closed models, including Anthropic’s Fable 5. Still, the guardrails on those systems could not tell the difference between the attacker and the people trying to stop it, so the tools refused to cooperate. The company ended up turning to GLM 5.2, an open-weight model built by China’s Z.ai, running it on its own infrastructure to analyse the flood of actions and finally contain the intrusion.
That detail, a Chinese open model succeeding where American closed models failed, is what pushed the industry into motion. Jensen Huang, Nvidia’s founder and CEO, put it plainly in the alliance’s launch post: closed AI blocked essential forensics during the Hugging Face incident, while an open weight frontier model helped contain it, and that gap is exactly why the coalition exists.
The founding roster is long and reads like a cross-section of Silicon Valley plus a few unexpected names. Adobe, CrowdStrike, Cisco, Cloudflare, Dell Technologies, IBM, Red Hat, Salesforce, SAP, ServiceNow, Siemens, Snowflake, Palo Alto Networks, CapitalOne, Databricks, Elastic, HPE, NetApp, Synopsys, the Linux Foundation and Thinking Machines are all listed as founding members, alongside the bigger household names.
Several members are not just lending their logos; they are handing over actual tools. Nvidia is open-sourcing its Labs Object Oriented Agent framework on GitHub. Microsoft is contributing MDASH, a multi-model agentic scanning harness that has reportedly scored close to 88 percent on a benchmark called ExploitGym, though it remains in limited private preview for now. Hugging Face is offering up Safetensors, its format for storing model weights securely. IBM and Red Hat are bringing a tool called Lightwell for signing software patches across open source supply chains. SpaceX’s AI arm is open sourcing its Grok Build coding agent and has signalled it will eventually release Grok’s model weights too, a move that sits awkwardly next to the fact that Grok is also sold commercially.
You may also like to read – Johnson & Johnson Talc Settlement Hits $5.5 Billion, Ending Decade of Suits
Notably absent from the founding list are OpenAI’s closest rivals in the frontier lab world, Google and Anthropic, even though OpenAI itself signed on. Anthropic’s CEO Dario Amodei published his own post the same day, insisting the company has never pushed for banning open-weight models outright, even as it continues to argue for narrower restrictions.
The alliance’s timing lines up with a tenser policy fight in Washington. American officials have been pushing to limit the reach of Chinese open-weight models, accusing firms like Moonshot AI, maker of Kimi K3, of distillation, essentially training cheaper models by harvesting outputs from more advanced American systems. The alliance’s members signed a public letter to policymakers arguing the opposite case, warning that clamping down on open-weight AI would hand a small number of closed model providers outsized control and weaken the very defenders who just proved, in the Hugging Face case, that open tools were the ones that actually worked.
It is an uncomfortable position for companies like Nvidia, which sell hardware to everyone. But after watching a Chinese open model do what American closed models could not during a live breach, the argument that openness equals weakness has become much harder to make.
CXMT Becomes China’s Most Valuable Listed Firm
July 27, 2026