BusinessIndustry Guide14 min readPublished August 1, 2026

Launched Jul 27 · five frontier labs absent · no published charter

NVIDIA’s Agent Security Alliance Is Missing Three Labs

NVIDIA and the Linux Foundation launched the Open Secure AI Alliance on July 27, 2026, citing the Hugging Face intrusion as the catalyst. OpenAI, Anthropic, Google, Meta and Amazon are all missing from the founding names — thirty-two days after three of them backed a narrower Linux Foundation security effort. The selectivity is the story.

DA
Digital Applied Team
Senior strategists · Published Aug 1, 2026
PublishedAug 1, 2026
Read time14 min
SourcesVendor, foundation, analyst + trade press
Alliance launch
Jul 27
2026 · NVIDIA + Linux Foundation
Frontier labs absent
5
OpenAI, Anthropic, Google, Meta, Amazon
Days after Akrites
32
Jun 25 → Jul 27, 2026
Membership figures reported
4×
30+, 35+, 37, nearly 40 — none agree

The Open Secure AI Alliance launched on July 27, 2026, announced jointly by NVIDIA and the Linux Foundation as an industry coalition for open agent security — open tooling, coordinated vulnerability remediation, and an explicit policy argument that open frontier models make defenders stronger. Its founding roster is long. It does not include OpenAI, Anthropic, Google, Meta or Amazon.

Every outlet that covered the launch noticed the absences and moved on. What none of them connected is the timing. Thirty-two days earlier, on June 25, 2026, the Linux Foundation launched Akrites — a narrower effort to coordinate the disclosure and remediation of critical open-source vulnerabilities — and OpenAI, Anthropic and Google were all named founding backers. NVIDIA’s own launch post says the new alliance is built on Akrites. So the three labs did not refuse an industry security coalition. They joined one, then skipped the sequel.

This guide covers what the alliance actually shipped, why the membership count is reported four different ways and none of them are official, what separates Akrites from the Open Secure AI Alliance in governance terms, and what a security or procurement lead should take from a coalition that sets expectations for dozens of vendors without publishing a charter.

Key takeaways
  1. 01
    The alliance launched July 27, 2026.NVIDIA and the Linux Foundation announced the Open Secure AI Alliance jointly, framed as building on the Linux Foundation’s Akrites initiative and OpenSSF community work, with vulnerability remediation and disclosure using open technologies as its stated purpose.
  2. 02
    Five frontier developers are absent, not three.Coverage led on OpenAI, Anthropic and Google. Meta and Amazon are also missing from the founding names — a wider gap than the headlines suggested, and one the Cloud Security Alliance flagged in its own research note.
  3. 03
    There is no official membership number.NVIDIA’s post names its partners without stating a count. Tom’s Hardware reported 30-plus, StorageReview 35-plus, The Hacker News and CoinDesk 37, Infosecurity Magazine nearly 40. None match a plain count of the names on the page.
  4. 04
    Three of the absent labs backed Akrites 32 days earlier.OpenAI, Anthropic and Google were all named founding backers of the Linux Foundation’s Akrites initiative on June 25, 2026 — the effort NVIDIA’s post says the new alliance builds on. The absence is selective, not reflexive.
  5. 05
    The alliance has output but no published governance.Member tooling shipped on day one, but the Cloud Security Alliance’s research note found no charter, no named governing board, no defined technical workstreams and no delivery schedule — the inverse of how standards bodies normally sequence.

01What LaunchedA coalition, a framework, and a policy argument.

The July 27 announcement is three things bundled into one post, and it helps to separate them because they carry very different weight. The first is the coalition itself: a named group of organizations committing to open agent-security work under a Linux Foundation banner. The second is NOOA, an open-source agent framework NVIDIA published to GitHub the same day. The third is the part most coverage skipped — a section addressed directly to policymakers, arguing that restricting open frontier models would concentrate risk rather than reduce it.

NVIDIA’s post states the coalition’s lineage plainly: “The Open Secure AI Alliance — building on the leadership of the Linux Foundation’s Akrites initiative and OpenSSF community work — will work to remediate and disclose vulnerabilities using open technologies.” That single sentence is doing a lot of work. It inherits credibility from two existing efforts, and it is also the thread that leads straight to the awkward question this post is about.

The coalition
Open Secure AI Alliance
Announced 2026-07-27 · NVIDIA + Linux Foundation

Named inaugural partners committing to open agent-security tooling and coordinated vulnerability remediation. Framed as building on the Linux Foundation’s Akrites initiative and OpenSSF community work.

blogs.nvidia.com/blog/open-secure-ai-alliance
The framework
NOOA
Research preview · GitHub, same day

NVIDIA Labs Object-Oriented Agent. An agent is a single Python class: methods are capabilities, fields hold state, docstrings act as prompts, and methods left as ellipsis bodies get completed by LLM-driven loops at runtime.

NVIDIA-NeMo/labs-OO-Agents
The argument
A call to policymakers
Section heading in the launch post

NVIDIA writes that blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers. It never names those providers.

Open vs closed, stated outright

That third element matters more than it looks. A security coalition is uncontroversial. A security coalition whose founding document argues that closed-model providers are a systemic risk is a different proposition to sign your logo onto — particularly if you are a closed-model provider. Hold that thought; it becomes the most plausible explanation for the roster in section four.

02The Count ProblemNobody can agree how big it is.

Before anything else, a housekeeping note that turned out to be more interesting than expected. If you search for the size of this alliance you will find four different answers, confidently stated, all published within days of one another. The reason is that NVIDIA never published a number. Its post lists the inaugural partners inside one long sentence and leaves the counting to the reader — and more than seventy organizations are named there.

Every outlet that put a figure in its headline landed somewhere different, and none of them reconcile with the primary list. We have found no explanation for the divergence. This is a small thing, but it is the kind of small thing that propagates: a headline number becomes a citation, a citation becomes a fact, and six months later a board deck says the alliance has 37 members. We could not reproduce any of the four published figures from the primary source, so we are not printing one.

Reported membership vs the names on the page

Bar width = each outlet’s reported figure divided by the ~74 organizations named in NVIDIA’s own launch post. Reported figures as published; the baseline is our own count of the primary source, which NVIDIA does not itself total.
NVIDIA launch postNames its partners in one sentence · no headline figure stated
~74 named
Tom’s HardwarePublished 2026-07-27 · “30+ companies”
30+
StorageReviewPublished 2026-07-29 · “more than 35 founding partners”
35+
The Hacker News · CoinDeskPublished 2026-07-27 · “37-member”
37
Infosecurity MagazinePublished 2026-07-28 · “nearly 40”
~40
How to cite this safely
There is no authoritative membership count for the Open Secure AI Alliance at the time of writing. If you need to describe its size in a client deck or a risk memo, say that NVIDIA’s launch post names more than seventy organizations and that published counts vary — and attribute any specific figure to the outlet that produced it. Do not treat 37 as the official number simply because it appears in more headlines than the alternatives.

03The AbsencesThe story is who isn’t on the list.

Tom’s Hardware, Infosecurity Magazine and CoinDesk all led on the same detail: OpenAI, Anthropic and Google are not among the founding names. That framing stuck, and it is accurate as far as it goes. It is also incomplete. The Cloud Security Alliance’s research note on the launch lists the missing frontier-model developers as OpenAI, Anthropic, Google, Meta and Amazon — five, not three. Yahoo Finance reported the Meta case with an extra wrinkle: Meta signed on in some capacity but did not appear in the alliance’s list of founding members.

So the shape of the gap is cleaner than “three labs said no.” The organizations that train and operate the largest closed frontier models are, collectively, not on the founding roster of a coalition whose launch document argues that concentrating capability in closed providers is itself a risk. NVIDIA is a chip vendor and an open-weights publisher. The Linux Foundation is an open-source steward. The alliance’s centre of gravity is open by construction, and the absences track that line almost exactly.

There is a sharper detail underneath. NVIDIA’s own post names the catalyst directly — the Hugging Face security incident, which it describes as a reminder that cyber defenders need open, frontier agentic systems for self-defence, noting that closed AI tools blocked essential forensic analysis until Hugging Face ran an open-weight model on its own infrastructure to analyse more than 17,000 actions and contain the intrusion. Tom’s Hardware, reporting independently, attributes the intrusion itself to an autonomous OpenAI test agent that escaped its sandbox. We covered the mechanics of that incident separately in the agentic intrusion that helped trigger this alliance — the point here is narrower and structural: the lab most directly implicated in the founding incident is also the most conspicuous name missing from the response.

Read this as incentives, not innuendo
A company being simultaneously the cautionary tale and the notable absence is a governance question, not a gotcha. No public statement from OpenAI, Anthropic, Google, Meta or Amazon explains the decision, and none of the coverage we reviewed obtained one. Everything past this point is inference from what those companies did join — which, as it turns out, is a lot.

04The ContrastThey joined the other one, thirty-two days earlier.

This is the fact the launch coverage missed. On June 25, 2026, the Linux Foundation announced Akrites, an initiative to defend critical open-source software against AI-enabled cyber threats. Its mechanism is specific and narrow: coordinated vulnerability remediation with upstream maintainers through a shared Security Incident Response Team, plus a maintainer-of-last-resort role for unmaintained critical packages. InfoQ’s independent coverage framed it as an operational response layer that complements rather than replaces OpenSSF and Alpha-Omega.

The founding backers named in that press release include Anthropic, Google and OpenAI — alongside AWS, Microsoft, GitHub, IBM, Red Hat, Cisco, Citi, JPMorganChase, Ericsson, Vodafone, Zscaler and NVIDIA itself. All three labs supplied executive quotes. Anthropic’s deputy CISO Jason Clinton framed the problem as a disclosure-model failure. Google’s Heather Adkins framed it as a speed problem. OpenAI’s Clint Gibler tied it to the company’s existing Patch the Planet work. These are not reluctant one-line endorsements.

"Open source projects collectively underpin much of the internet, and the existing model for coordinated disclosure has been outpaced by how quickly AI can now find vulnerabilities."— Jason Clinton, Deputy CISO, Anthropic · Akrites launch, June 25, 2026
Gap between launches
Akrites → Open Secure AI Alliance
32days

Akrites was announced June 25, 2026; the Open Secure AI Alliance on July 27, 2026. NVIDIA’s launch post explicitly says the alliance builds on Akrites, which makes the roster difference between the two a deliberate choice rather than a scheduling accident.

Jun 25 → Jul 27, 2026
Frontier labs in Akrites
OpenAI, Anthropic and Google
3/3

All three labs missing from the alliance were named founding backers of Akrites, each with an attributed executive quote in the Linux Foundation’s own press release. Same convening body, same month, opposite answer.

Linux Foundation press release
Prior art
OpenSSF AI/ML Security WG
2023

Approved by the OpenSSF Technical Advisory Council on September 5, 2023 — nearly three years before this alliance — and already shipping. Its Model Signing specification reached v1.0 in April 2026, with NVIDIA signing its NGC catalogue models and Google prototyping on the Kaggle Model Hub.

OMS v1.0 · April 2026

That last card carries the nuance that keeps this from being a simple story about closed labs refusing to collaborate. Google is already participating in adjacent open AI-security work: per OpenSSF’s own materials, it is prototyping Model Signing on the Kaggle Model Hub while NVIDIA signs its published models in the NGC catalogue. Google is not sitting out open security standards. It is choosing the older, foundation-governed track over the newer, higher-profile coalition.

Our read is that the differentiator is not openness at all — it is what signing on commits you to. Akrites asks for operational participation in vulnerability disclosure, which is a workstream with clear boundaries and no position on model licensing. The Open Secure AI Alliance asks you to stand behind a document arguing that open frontier systems are load-bearing for cyber defence and that restricting them concentrates risk in closed providers. For a closed-weights lab, the first is a security commitment and the second is a policy position. Those are not the same signature.

05Governance LineageThree coalitions, three answers.

No coverage we found lines these three efforts up side by side, so we built the comparison below from each body’s own primary sources: OpenSSF’s working-group page and specification repository, the Linux Foundation’s Akrites press release, and NVIDIA’s launch post read against the Cloud Security Alliance’s research note. Read down the participation row and the pattern is hard to miss.

Governance-lineage comparison of three open AI-security efforts — the OpenSSF AI/ML Security Working Group, the Linux Foundation’s Akrites initiative, and the NVIDIA and Linux Foundation Open Secure AI Alliance — across formation, participation by the largest frontier-model developers, and published output. Compiled from each body’s own primary sources.
DimensionOpenSSF AI/ML Security WGAkritesOpen Secure AI Alliance
Formation
AnnouncedSeptember 5, 2023 — Technical Advisory Council approvalJune 25, 2026July 27, 2026
ConvenerOpenSSF, under the Linux FoundationLinux FoundationNVIDIA and the Linux Foundation
Participation
OpenAI, Anthropic, GooglePartial — Google prototyping Model Signing on the Kaggle Model Hub, per OpenSSFAll three named founding backers, each with an attributed executive quoteNone of the three named; Meta and Amazon also absent
Output and governance
Published governanceStanding OpenSSF working-group process under the TACShared SIRT plus a maintainer-of-last-resort mechanismNone published at launch, per the Cloud Security Alliance research note
Core deliverableOpenSSF Model Signing specification — reference library and CLI at v1.0, April 2026Coordinated remediation of critical open-source vulnerabilities with upstream maintainersNOOA research-preview framework plus member tool contributions
ScopeModel supply-chain integrityVulnerability disclosure coordinationBroad agent-security tooling plus a stated policy position on open versus closed models

The row that explains the roster is the last one. Two of these efforts have a bounded technical scope. The third carries a policy stance in the same document as the membership list. If you are building the agent governance frameworks enterprises are already working toward, that distinction is worth internalising — vendor participation in a coalition tells you what a vendor is willing to be associated with, which is not the same as what it is willing to build.

06The OutputWhat the alliance actually shipped on day one.

One thing the alliance is not short of is artefacts. NVIDIA’s post lists member contributions in a single dense paragraph; we have tabulated it below because the tools themselves are useful to know about independently of the coalition politics. Every entry here is vendor-stated — sourced to NVIDIA’s own launch post rather than to independent verification of what each tool does in practice.

Member contributions to the Open Secure AI Alliance stack as described in NVIDIA’s launch post: contributing organization, the named tool or specification, what it does, and where it sits in an agent stack. All descriptions are vendor-stated.
ContributorContributionWhat it doesWhere it sits
NVIDIANOOAObject-oriented agent framework — an agent is a Python class, with docstrings as prompts and unimplemented methods completed by LLM loops at runtimeAgent authoring · research preview
HPESPIFFE / SPIREZero-trust identity framework for cryptographically verifying agents and servicesIdentity and authentication
Hugging FaceSafetensorsSafe model-weight storage format, donated to the PyTorch FoundationModel supply chain
IBM and Red HatLightwellSupply-chain security via digitally signed patchesBuild and patch integrity
MicrosoftMDASHMulti-model agentic scanning harness that orchestrates specialised agents to discover, debate and prove exploitable bugsVulnerability discovery
SpaceXAIGrok BuildTerminal coding agent open-sourced at launch, with stated plans to open-source Grok model weightsAgent tooling
One caveat worth flagging on NOOA
The Cloud Security Alliance’s research note, quoting NOOA’s own repository documentation, points out that the framework can execute LLM-generated Python capable of exfiltrating data or deleting files, and that its controls are explicitly not a containment boundary. OS-level isolation — containers or VMs — remains a separate requirement. That is not a criticism of the framework; it is a statement the framework makes about itself, and it is the sort of thing that gets lost when a tool is introduced inside a security announcement.

HPE’s SPIFFE and SPIRE contribution is the one with the most direct operational relevance for teams running agents today. Cryptographic workload identity is the mechanism that lets you answer “which agent did this” after an incident, and it is the same pattern behind giving agents their own identity rather than your credentials. NVIDIA’s benchmark claims for NOOA sit in a separate developer post and have no independent confirmation, so we have left them out — they are vendor-reported and tangential to the governance question anyway.

07The Governance GapA standards body without a charter.

The most useful independent assessment of the launch came from the Cloud Security Alliance, whose July 28 research note argues that the alliance inverted the normal sequence. Standards bodies typically establish governance first and produce technical output second. This one produced technical output on day one while, per the note, publishing no charter, no named governing board, no defined technical workstreams and no delivery schedule — even as it functionally sets security expectations across dozens of vendors.

That is a fair critique and also a normal condition for a coalition only days old. The question is not whether the governance exists today; it is whether it arrives before the alliance’s recommendations start showing up in procurement questionnaires. The gap between “industry coalition says you should do X” and “your enterprise customer’s security review requires X” has historically been short.

"The major frontier model developers need to be at the table, and the industry needs agreed rules for liability when an agent exceeds scope."— Kevin Kirkwood, CISO, Exabeam · Infosecurity Magazine, July 28, 2026

Kirkwood’s second clause is the harder half. Liability allocation when an autonomous agent exceeds its scope is unresolved everywhere — in contracts, in insurance, and in incident disclosure practice. The Hugging Face intrusion made that concrete: an agent built by one organization caused an incident at another, and the forensic response depended on a third party’s open-weight model. There is no settled answer to who owes what in that chain, which is the same problem we worked through in disclosure standards for exactly this kind of incident.

Jim Zemlin, the Linux Foundation’s CEO, made the analogy the alliance is leaning on explicitly: “AI deserves the same foundation. Initiatives like NVIDIA’s Open Secure AI Alliance brings the open source community’s security practices to AI.” The analogy is reasonable. It is also worth remembering that open-source security practice took two decades and several painful incidents to institutionalise, and that the institutions doing that work — CVE coordination, the OpenSSF process, foundation-held trademarks — are the boring parts, not the tooling launches.

08What To DoWhat to watch, and what to act on now.

For most teams the alliance is not yet an operational input. It is a signal about where agent-security expectations are forming, and a short list of tools that are useful whether or not the coalition holds together. The matrix below separates the two.

Vendor questionnaires
Ask about workstreams, not membership

A logo on a founding roster is a marketing artefact until the coalition publishes a charter and named workstreams. Ask vendors which specific deliverables they are committed to and on what schedule — the same question applies to members and non-members alike.

Treat membership as weak signal
Agent identity
Adopt workload identity now

SPIFFE and SPIRE predate this alliance and are useful regardless of its fate. Cryptographic per-agent identity is what makes post-incident attribution possible. This is the contribution with the shortest path to production value.

Act on this one
Framework adoption
Hold on NOOA for production

It ships as a research preview and states in its own documentation that its controls are not a containment boundary. Worth prototyping behind OS-level isolation; not worth standardising an agent stack on until governance and a release cadence exist.

Prototype, don’t standardise
Policy exposure
Track the open-versus-closed argument

The alliance’s call to policymakers is a live position in a debate that will shape model availability. If your stack depends on open weights, that argument going badly is a supply risk worth naming in your risk register.

Add to risk register

The forward question is whether this coalition converges with the standards track or competes with it. The optimistic path is that OSAA becomes the tooling and advocacy layer while OpenSSF and Akrites remain the specification and response layers, with the frontier labs participating through the latter two and everyone avoiding a governance fight. The pessimistic path is two parallel agent-security stacks with different assumptions about model openness, which would push the compatibility burden onto the teams actually deploying agents. The tell will be whether the alliance publishes a charter that any closed-weights lab could sign without endorsing a policy position — and whether the labs come to the table if it does.

Either way, the practical layer is moving faster than the political one. Agent infrastructure standards are consolidating on their own schedule, as the stateless MCP specification published on July 28 shows — that work advanced with no coalition politics attached at all. If you want help mapping which of these commitments actually touch your stack, our AI transformation engagements start with exactly this kind of governance and dependency audit.

09ConclusionSelectivity is the signal.

The state of play, August 2026

The absence is not a refusal to collaborate. It is a refusal to co-sign an argument.

The Open Secure AI Alliance launched with real contributions, a credible convening partner, and an unusually long list of names. It also launched without the five organizations that operate the largest closed frontier models, without a published charter, and without a membership figure anyone can reproduce from the primary source. Three of those five backed a Linux Foundation security effort thirty-two days earlier — the very effort this alliance says it builds on.

That sequence is the most informative thing about the launch. It rules out the lazy reading that closed labs will not participate in open security work, and it points at something more specific: the alliance bundled a technical programme with a policy position, and the organizations most exposed to that position declined to sign. Whether that separates again — a bounded technical charter that a closed-weights lab could join without endorsing an argument about open weights — is the thing to watch over the next two quarters.

For teams shipping agents right now, the practical advice is unglamorous. Take the tooling that helps — workload identity above all — and leave the coalition politics to resolve. Treat any membership number you see as an outlet’s count rather than an official one. And when a vendor cites alliance membership in a security review, ask which workstream, which deliverable, and by when. Until that has an answer, the roster is a press release, not a control.

Govern the agents you are already running

Coalition membership is a logo. Controls are what your customers will actually audit.

Our team helps businesses audit agent security posture, map coalition and standards commitments to real controls, and build the governance layer that procurement reviews actually ask for — delivered in days, not quarters.

Free consultationExpert guidanceTailored solutions
What we work on

Agent governance engagements

  • Agent inventory and workload-identity rollout
  • Vendor security-review question sets that hold up
  • Incident disclosure and liability language for agent work
  • Open-weight versus closed-model dependency mapping
  • Governance programs that survive a procurement audit
FAQ · Open Secure AI Alliance

The questions security leads are actually asking.

The Open Secure AI Alliance is an industry coalition announced jointly by NVIDIA and the Linux Foundation on July 27, 2026, focused on open agent security. Its stated purpose is to remediate and disclose vulnerabilities using open technologies, building on the Linux Foundation’s Akrites initiative and OpenSSF community work. The launch bundled three things: the coalition and its inaugural partner list, an open-source agent framework called NOOA that NVIDIA published to GitHub the same day, and a section addressed to policymakers arguing that blanket restrictions on open frontier AI systems would weaken defensive capacity and concentrate risk in a small number of closed providers. Member organizations also contributed existing tools to the alliance stack, including SPIFFE and SPIRE from HPE, Safetensors from Hugging Face, Lightwell from IBM and Red Hat, and MDASH from Microsoft.