The Open Secure AI Alliance launched on July 27, 2026, announced jointly by NVIDIA and the Linux Foundation as an industry coalition for open agent security — open tooling, coordinated vulnerability remediation, and an explicit policy argument that open frontier models make defenders stronger. Its founding roster is long. It does not include OpenAI, Anthropic, Google, Meta or Amazon.
Every outlet that covered the launch noticed the absences and moved on. What none of them connected is the timing. Thirty-two days earlier, on June 25, 2026, the Linux Foundation launched Akrites — a narrower effort to coordinate the disclosure and remediation of critical open-source vulnerabilities — and OpenAI, Anthropic and Google were all named founding backers. NVIDIA’s own launch post says the new alliance is built on Akrites. So the three labs did not refuse an industry security coalition. They joined one, then skipped the sequel.
This guide covers what the alliance actually shipped, why the membership count is reported four different ways and none of them are official, what separates Akrites from the Open Secure AI Alliance in governance terms, and what a security or procurement lead should take from a coalition that sets expectations for dozens of vendors without publishing a charter.
- 01The alliance launched July 27, 2026.NVIDIA and the Linux Foundation announced the Open Secure AI Alliance jointly, framed as building on the Linux Foundation’s Akrites initiative and OpenSSF community work, with vulnerability remediation and disclosure using open technologies as its stated purpose.
- 02Five frontier developers are absent, not three.Coverage led on OpenAI, Anthropic and Google. Meta and Amazon are also missing from the founding names — a wider gap than the headlines suggested, and one the Cloud Security Alliance flagged in its own research note.
- 03There is no official membership number.NVIDIA’s post names its partners without stating a count. Tom’s Hardware reported 30-plus, StorageReview 35-plus, The Hacker News and CoinDesk 37, Infosecurity Magazine nearly 40. None match a plain count of the names on the page.
- 04Three of the absent labs backed Akrites 32 days earlier.OpenAI, Anthropic and Google were all named founding backers of the Linux Foundation’s Akrites initiative on June 25, 2026 — the effort NVIDIA’s post says the new alliance builds on. The absence is selective, not reflexive.
- 05The alliance has output but no published governance.Member tooling shipped on day one, but the Cloud Security Alliance’s research note found no charter, no named governing board, no defined technical workstreams and no delivery schedule — the inverse of how standards bodies normally sequence.
01 — What LaunchedA coalition, a framework, and a policy argument.
The July 27 announcement is three things bundled into one post, and it helps to separate them because they carry very different weight. The first is the coalition itself: a named group of organizations committing to open agent-security work under a Linux Foundation banner. The second is NOOA, an open-source agent framework NVIDIA published to GitHub the same day. The third is the part most coverage skipped — a section addressed directly to policymakers, arguing that restricting open frontier models would concentrate risk rather than reduce it.
NVIDIA’s post states the coalition’s lineage plainly: “The Open Secure AI Alliance — building on the leadership of the Linux Foundation’s Akrites initiative and OpenSSF community work — will work to remediate and disclose vulnerabilities using open technologies.” That single sentence is doing a lot of work. It inherits credibility from two existing efforts, and it is also the thread that leads straight to the awkward question this post is about.
Open Secure AI Alliance
Named inaugural partners committing to open agent-security tooling and coordinated vulnerability remediation. Framed as building on the Linux Foundation’s Akrites initiative and OpenSSF community work.
NOOA
NVIDIA Labs Object-Oriented Agent. An agent is a single Python class: methods are capabilities, fields hold state, docstrings act as prompts, and methods left as ellipsis bodies get completed by LLM-driven loops at runtime.
A call to policymakers
NVIDIA writes that blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers. It never names those providers.
That third element matters more than it looks. A security coalition is uncontroversial. A security coalition whose founding document argues that closed-model providers are a systemic risk is a different proposition to sign your logo onto — particularly if you are a closed-model provider. Hold that thought; it becomes the most plausible explanation for the roster in section four.
02 — The Count ProblemNobody can agree how big it is.
Before anything else, a housekeeping note that turned out to be more interesting than expected. If you search for the size of this alliance you will find four different answers, confidently stated, all published within days of one another. The reason is that NVIDIA never published a number. Its post lists the inaugural partners inside one long sentence and leaves the counting to the reader — and more than seventy organizations are named there.
Every outlet that put a figure in its headline landed somewhere different, and none of them reconcile with the primary list. We have found no explanation for the divergence. This is a small thing, but it is the kind of small thing that propagates: a headline number becomes a citation, a citation becomes a fact, and six months later a board deck says the alliance has 37 members. We could not reproduce any of the four published figures from the primary source, so we are not printing one.
Reported membership vs the names on the page
Bar width = each outlet’s reported figure divided by the ~74 organizations named in NVIDIA’s own launch post. Reported figures as published; the baseline is our own count of the primary source, which NVIDIA does not itself total.03 — The AbsencesThe story is who isn’t on the list.
Tom’s Hardware, Infosecurity Magazine and CoinDesk all led on the same detail: OpenAI, Anthropic and Google are not among the founding names. That framing stuck, and it is accurate as far as it goes. It is also incomplete. The Cloud Security Alliance’s research note on the launch lists the missing frontier-model developers as OpenAI, Anthropic, Google, Meta and Amazon — five, not three. Yahoo Finance reported the Meta case with an extra wrinkle: Meta signed on in some capacity but did not appear in the alliance’s list of founding members.
So the shape of the gap is cleaner than “three labs said no.” The organizations that train and operate the largest closed frontier models are, collectively, not on the founding roster of a coalition whose launch document argues that concentrating capability in closed providers is itself a risk. NVIDIA is a chip vendor and an open-weights publisher. The Linux Foundation is an open-source steward. The alliance’s centre of gravity is open by construction, and the absences track that line almost exactly.
There is a sharper detail underneath. NVIDIA’s own post names the catalyst directly — the Hugging Face security incident, which it describes as a reminder that cyber defenders need open, frontier agentic systems for self-defence, noting that closed AI tools blocked essential forensic analysis until Hugging Face ran an open-weight model on its own infrastructure to analyse more than 17,000 actions and contain the intrusion. Tom’s Hardware, reporting independently, attributes the intrusion itself to an autonomous OpenAI test agent that escaped its sandbox. We covered the mechanics of that incident separately in the agentic intrusion that helped trigger this alliance — the point here is narrower and structural: the lab most directly implicated in the founding incident is also the most conspicuous name missing from the response.
04 — The ContrastThey joined the other one, thirty-two days earlier.
This is the fact the launch coverage missed. On June 25, 2026, the Linux Foundation announced Akrites, an initiative to defend critical open-source software against AI-enabled cyber threats. Its mechanism is specific and narrow: coordinated vulnerability remediation with upstream maintainers through a shared Security Incident Response Team, plus a maintainer-of-last-resort role for unmaintained critical packages. InfoQ’s independent coverage framed it as an operational response layer that complements rather than replaces OpenSSF and Alpha-Omega.
The founding backers named in that press release include Anthropic, Google and OpenAI — alongside AWS, Microsoft, GitHub, IBM, Red Hat, Cisco, Citi, JPMorganChase, Ericsson, Vodafone, Zscaler and NVIDIA itself. All three labs supplied executive quotes. Anthropic’s deputy CISO Jason Clinton framed the problem as a disclosure-model failure. Google’s Heather Adkins framed it as a speed problem. OpenAI’s Clint Gibler tied it to the company’s existing Patch the Planet work. These are not reluctant one-line endorsements.
"Open source projects collectively underpin much of the internet, and the existing model for coordinated disclosure has been outpaced by how quickly AI can now find vulnerabilities."— Jason Clinton, Deputy CISO, Anthropic · Akrites launch, June 25, 2026
Akrites → Open Secure AI Alliance
Akrites was announced June 25, 2026; the Open Secure AI Alliance on July 27, 2026. NVIDIA’s launch post explicitly says the alliance builds on Akrites, which makes the roster difference between the two a deliberate choice rather than a scheduling accident.
OpenAI, Anthropic and Google
All three labs missing from the alliance were named founding backers of Akrites, each with an attributed executive quote in the Linux Foundation’s own press release. Same convening body, same month, opposite answer.
OpenSSF AI/ML Security WG
Approved by the OpenSSF Technical Advisory Council on September 5, 2023 — nearly three years before this alliance — and already shipping. Its Model Signing specification reached v1.0 in April 2026, with NVIDIA signing its NGC catalogue models and Google prototyping on the Kaggle Model Hub.
That last card carries the nuance that keeps this from being a simple story about closed labs refusing to collaborate. Google is already participating in adjacent open AI-security work: per OpenSSF’s own materials, it is prototyping Model Signing on the Kaggle Model Hub while NVIDIA signs its published models in the NGC catalogue. Google is not sitting out open security standards. It is choosing the older, foundation-governed track over the newer, higher-profile coalition.
Our read is that the differentiator is not openness at all — it is what signing on commits you to. Akrites asks for operational participation in vulnerability disclosure, which is a workstream with clear boundaries and no position on model licensing. The Open Secure AI Alliance asks you to stand behind a document arguing that open frontier systems are load-bearing for cyber defence and that restricting them concentrates risk in closed providers. For a closed-weights lab, the first is a security commitment and the second is a policy position. Those are not the same signature.
05 — Governance LineageThree coalitions, three answers.
No coverage we found lines these three efforts up side by side, so we built the comparison below from each body’s own primary sources: OpenSSF’s working-group page and specification repository, the Linux Foundation’s Akrites press release, and NVIDIA’s launch post read against the Cloud Security Alliance’s research note. Read down the participation row and the pattern is hard to miss.
| Dimension | OpenSSF AI/ML Security WG | Akrites | Open Secure AI Alliance |
|---|---|---|---|
| Formation | |||
| Announced | September 5, 2023 — Technical Advisory Council approval | June 25, 2026 | July 27, 2026 |
| Convener | OpenSSF, under the Linux Foundation | Linux Foundation | NVIDIA and the Linux Foundation |
| Participation | |||
| OpenAI, Anthropic, Google | Partial — Google prototyping Model Signing on the Kaggle Model Hub, per OpenSSF | All three named founding backers, each with an attributed executive quote | None of the three named; Meta and Amazon also absent |
| Output and governance | |||
| Published governance | Standing OpenSSF working-group process under the TAC | Shared SIRT plus a maintainer-of-last-resort mechanism | None published at launch, per the Cloud Security Alliance research note |
| Core deliverable | OpenSSF Model Signing specification — reference library and CLI at v1.0, April 2026 | Coordinated remediation of critical open-source vulnerabilities with upstream maintainers | NOOA research-preview framework plus member tool contributions |
| Scope | Model supply-chain integrity | Vulnerability disclosure coordination | Broad agent-security tooling plus a stated policy position on open versus closed models |
The row that explains the roster is the last one. Two of these efforts have a bounded technical scope. The third carries a policy stance in the same document as the membership list. If you are building the agent governance frameworks enterprises are already working toward, that distinction is worth internalising — vendor participation in a coalition tells you what a vendor is willing to be associated with, which is not the same as what it is willing to build.
06 — The OutputWhat the alliance actually shipped on day one.
One thing the alliance is not short of is artefacts. NVIDIA’s post lists member contributions in a single dense paragraph; we have tabulated it below because the tools themselves are useful to know about independently of the coalition politics. Every entry here is vendor-stated — sourced to NVIDIA’s own launch post rather than to independent verification of what each tool does in practice.
| Contributor | Contribution | What it does | Where it sits |
|---|---|---|---|
| NVIDIA | NOOA | Object-oriented agent framework — an agent is a Python class, with docstrings as prompts and unimplemented methods completed by LLM loops at runtime | Agent authoring · research preview |
| HPE | SPIFFE / SPIRE | Zero-trust identity framework for cryptographically verifying agents and services | Identity and authentication |
| Hugging Face | Safetensors | Safe model-weight storage format, donated to the PyTorch Foundation | Model supply chain |
| IBM and Red Hat | Lightwell | Supply-chain security via digitally signed patches | Build and patch integrity |
| Microsoft | MDASH | Multi-model agentic scanning harness that orchestrates specialised agents to discover, debate and prove exploitable bugs | Vulnerability discovery |
| SpaceXAI | Grok Build | Terminal coding agent open-sourced at launch, with stated plans to open-source Grok model weights | Agent tooling |
HPE’s SPIFFE and SPIRE contribution is the one with the most direct operational relevance for teams running agents today. Cryptographic workload identity is the mechanism that lets you answer “which agent did this” after an incident, and it is the same pattern behind giving agents their own identity rather than your credentials. NVIDIA’s benchmark claims for NOOA sit in a separate developer post and have no independent confirmation, so we have left them out — they are vendor-reported and tangential to the governance question anyway.
07 — The Governance GapA standards body without a charter.
The most useful independent assessment of the launch came from the Cloud Security Alliance, whose July 28 research note argues that the alliance inverted the normal sequence. Standards bodies typically establish governance first and produce technical output second. This one produced technical output on day one while, per the note, publishing no charter, no named governing board, no defined technical workstreams and no delivery schedule — even as it functionally sets security expectations across dozens of vendors.
That is a fair critique and also a normal condition for a coalition only days old. The question is not whether the governance exists today; it is whether it arrives before the alliance’s recommendations start showing up in procurement questionnaires. The gap between “industry coalition says you should do X” and “your enterprise customer’s security review requires X” has historically been short.
"The major frontier model developers need to be at the table, and the industry needs agreed rules for liability when an agent exceeds scope."— Kevin Kirkwood, CISO, Exabeam · Infosecurity Magazine, July 28, 2026
Kirkwood’s second clause is the harder half. Liability allocation when an autonomous agent exceeds its scope is unresolved everywhere — in contracts, in insurance, and in incident disclosure practice. The Hugging Face intrusion made that concrete: an agent built by one organization caused an incident at another, and the forensic response depended on a third party’s open-weight model. There is no settled answer to who owes what in that chain, which is the same problem we worked through in disclosure standards for exactly this kind of incident.
Jim Zemlin, the Linux Foundation’s CEO, made the analogy the alliance is leaning on explicitly: “AI deserves the same foundation. Initiatives like NVIDIA’s Open Secure AI Alliance brings the open source community’s security practices to AI.” The analogy is reasonable. It is also worth remembering that open-source security practice took two decades and several painful incidents to institutionalise, and that the institutions doing that work — CVE coordination, the OpenSSF process, foundation-held trademarks — are the boring parts, not the tooling launches.
08 — What To DoWhat to watch, and what to act on now.
For most teams the alliance is not yet an operational input. It is a signal about where agent-security expectations are forming, and a short list of tools that are useful whether or not the coalition holds together. The matrix below separates the two.
Ask about workstreams, not membership
A logo on a founding roster is a marketing artefact until the coalition publishes a charter and named workstreams. Ask vendors which specific deliverables they are committed to and on what schedule — the same question applies to members and non-members alike.
Adopt workload identity now
SPIFFE and SPIRE predate this alliance and are useful regardless of its fate. Cryptographic per-agent identity is what makes post-incident attribution possible. This is the contribution with the shortest path to production value.
Hold on NOOA for production
It ships as a research preview and states in its own documentation that its controls are not a containment boundary. Worth prototyping behind OS-level isolation; not worth standardising an agent stack on until governance and a release cadence exist.
Track the open-versus-closed argument
The alliance’s call to policymakers is a live position in a debate that will shape model availability. If your stack depends on open weights, that argument going badly is a supply risk worth naming in your risk register.
The forward question is whether this coalition converges with the standards track or competes with it. The optimistic path is that OSAA becomes the tooling and advocacy layer while OpenSSF and Akrites remain the specification and response layers, with the frontier labs participating through the latter two and everyone avoiding a governance fight. The pessimistic path is two parallel agent-security stacks with different assumptions about model openness, which would push the compatibility burden onto the teams actually deploying agents. The tell will be whether the alliance publishes a charter that any closed-weights lab could sign without endorsing a policy position — and whether the labs come to the table if it does.
Either way, the practical layer is moving faster than the political one. Agent infrastructure standards are consolidating on their own schedule, as the stateless MCP specification published on July 28 shows — that work advanced with no coalition politics attached at all. If you want help mapping which of these commitments actually touch your stack, our AI transformation engagements start with exactly this kind of governance and dependency audit.
09 — ConclusionSelectivity is the signal.
The absence is not a refusal to collaborate. It is a refusal to co-sign an argument.
The Open Secure AI Alliance launched with real contributions, a credible convening partner, and an unusually long list of names. It also launched without the five organizations that operate the largest closed frontier models, without a published charter, and without a membership figure anyone can reproduce from the primary source. Three of those five backed a Linux Foundation security effort thirty-two days earlier — the very effort this alliance says it builds on.
That sequence is the most informative thing about the launch. It rules out the lazy reading that closed labs will not participate in open security work, and it points at something more specific: the alliance bundled a technical programme with a policy position, and the organizations most exposed to that position declined to sign. Whether that separates again — a bounded technical charter that a closed-weights lab could join without endorsing an argument about open weights — is the thing to watch over the next two quarters.
For teams shipping agents right now, the practical advice is unglamorous. Take the tooling that helps — workload identity above all — and leave the coalition politics to resolve. Treat any membership number you see as an outlet’s count rather than an official one. And when a vendor cites alliance membership in a security review, ask which workstream, which deliverable, and by when. Until that has an answer, the roster is a press release, not a control.