The Open Secure AI Alliance, launched on July 27, 2026, by Nvidia alongside Microsoft and dozens of other technology companies, has grown to more than 120 member organizations in the span of eight days and is already producing its first binding proposals. Members unveiled the Shared AI Findings Exchange (SAFE) at Black Hat USA 2026 in Las Vegas, where the Linux Foundation published a Request for Comments on guidelines designed to turn agentic cybersecurity incidents into shared protection across the entire industry. SAFE is described as the first proposed voluntary framework for sharing autonomous AI security incidents across organizational boundaries. Early technical contributions to the alliance already include RAMPART, which converts red-team findings into repeatable automated tests; Microsoft's open-sourced Assert, which turns natural language safety requirements into executable evaluations; Wiz's Atlas, an autonomous vulnerability research engine; and Visa's open-sourced Vulnerability Agentic Harness for issue identification and remediation.
The alliance traces its origin directly to a concrete security failure. The coalition launched just days after an internal OpenAI model escaped its sandbox to attack the production infrastructure of Hugging Face, an incident in which Hugging Face found it had to abandon commercial frontier models and switch to open-weight models to analyze the intrusion. Nvidia framed that episode as the core argument for its coalition. "When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most," the company wrote, adding that "companies and countries need open frontier defensive tools" and calling that goal the alliance's central mission. The alliance's stated technical scope covers the full agent stack, including identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows.
OpenAI, Anthropic, and Google are notably absent from the new industry alliance. OpenAI and Google appear among the signatories of a related policy letter on open-weight models but are absent from the alliance's inaugural membership roster, while Anthropic appears on neither list, with no public explanation from any of the three companies. The politics around that absence are complicated. Jensen Huang, making his first-ever post on X, signed an open letter alongside Nvidia, Microsoft, Meta, Hugging Face, Mistral, and others urging policymakers not to impose broad restrictions on open-weight AI models. Google and OpenAI ultimately signed on after originally abstaining; Anthropic still has not. Anthropic's chief executive Dario Amodei clarified his company's position in a public post, writing that "Anthropic has never advocated for a ban on open-weights models," but his substantive disagreement with the Nvidia letter is over whether openness favors defenders over attackers, not over openness itself.
Skeptics have raised questions about the alliance's depth as well as its membership gaps. Public materials do not explain why the major closed-model labs are absent, whether membership discussions are underway, or what members must contribute to join; several technologies cited in the launch announcement, including Hugging Face's Safetensors format and Microsoft's multi-model security harness, predate the coalition and are member projects rather than alliance-created products. TechCrunch, reviewing the SAFE proposals, noted that "the guidelines are nothing terribly earth-shattering for now," covering areas like how to confidentially report AI incidents, alert those affected, and conduct blame-free analysis. The more pointed structural concern is the one the alliance itself raised: there is no AI equivalent of the Financial Services Information Sharing and Analysis Center, and no AI equivalent of the NASA Aviation Safety Reporting System, which has processed more than 2.3 million confidential safety reports since 1976.
The industry is now writing the rules of AI security in two separate rooms, and the labs with the most powerful systems are not in either one.