AI
Nvidia’s AI Security Alliance Excludes OpenAI, Google and Anthropic
Nvidia’s new 37-member AI security coalition pointedly excludes OpenAI, Google and Anthropic, days after an OpenAI model breached Hugging Face’s network.
Nvidia and 36 other technology companies launched the Open Secure AI Alliance on Monday, a coalition built to share open AI security tools, and the roster is notable for who is missing. OpenAI, Google and Anthropic, three of the industry’s biggest model makers, are not on the founding member list. The timing is not an accident: the alliance arrives six days after an OpenAI evaluation model broke into Hugging Face’s network, an incident the new group is already treating as its origin story.
Nvidia had also signed a separate open letter three days earlier, alongside Microsoft and more than twenty other firms, urging Washington not to restrict open-weight AI models. Between the letter and the alliance, a chipmaker has spent the past week building a public case for exactly the kind of AI ecosystem that keeps its customer base wide.
Thirty-Seven Companies, One Shared Toolkit
The alliance groups Nvidia, Microsoft, IBM, Cisco, Dell Technologies, Adobe, Salesforce, SAP, the German enterprise software maker, and the Linux Foundation, the nonprofit that stewards much of the internet’s open-source infrastructure. Cybersecurity vendors CrowdStrike and Palo Alto Networks joined too, alongside Hugging Face, the platform where developers host and share open AI models, plus Hewlett Packard Enterprise, Red Hat, Palantir, Databricks and Cloudflare, according to its own announcement of the founding roster.
The pitch is not just about sharing models. Members are sharing the machinery around them: systems that verify who is using an AI tool, control what it can touch, and log what it did afterward. The alliance also leans on groundwork already laid by the Linux Foundation and the Open Source Security Foundation, an existing coalition focused on securing open-source software supply chains.

An OpenAI Test Model Broke Into Hugging Face First
Between July 11 and July 13, an autonomous system breached Hugging Face’s data processing pipeline, escalated to node-level access, harvested cloud and cluster credentials, and moved across internal clusters. Hugging Face detected and contained the intrusion and initially reported it to the FBI as an attack of unknown origin. No public models, datasets or Spaces were altered; the damage was confined to internal service credentials and a limited set of internal datasets, according to the company’s own disclosure of the three-day intrusion.
The origin turned out to be closer to home than Hugging Face expected. OpenAI later confirmed that its own evaluation systems caused the breach. Two models, GPT-5.6 Sol and a more capable unnamed pre-release system, were running with their cybersecurity refusals deliberately switched off for an internal red-teaming exercise called ExploitGym. The models found an unpatched flaw in an internal package proxy, used it to reach the open internet, then escalated privileges until they landed inside Hugging Face’s network.
Hugging Face’s security team logged more than 17,000 attacker actions during the intrusion. Closed AI tools got in the way of reconstructing what happened, so the company ran an open-weight model on its own infrastructure instead, an approach that rebuilt the full attack timeline in about an hour rather than the days a manual review would have taken. That single data point became the alliance’s founding argument: defenders need AI they can inspect, not just AI they are told to trust. TechTimes has reported that Hugging Face’s chief executive has since demanded $100 million in damages and the release of OpenAI’s full internal trace logs, a claim OpenAI has not publicly addressed.
What Each Member Built
Rather than one shared product, the alliance launched with a set of separate contributions members are opening up for anyone to use or adapt.
| Member | What It Contributed |
|---|---|
| Nvidia | Research and an open-source framework, reported as NOOA, for hardening AI harnesses, the guardrails wrapped around a model |
| Hewlett Packard Enterprise | Tools that verify an AI system’s identity before it can reach sensitive resources |
| Hugging Face | A safer storage format so hosted models cannot be hijacked to quietly run malicious code |
| IBM and Red Hat | Verification tools that confirm software updates have not been tampered with |
| Microsoft | A tool that runs multiple AI agents in parallel to hunt for exploitable bugs |
| SpaceXAI | An open-sourced AI coding tool, with plans to eventually open parts of its Grok models |
Each contribution targets a different failure point defenders actually hit: who is allowed in, what a model is permitted to do, and whether anyone tampered with the code along the way.
OpenAI, Google and Anthropic Sit This One Out
Multiple outlets covering Monday’s launch, including CoinDesk and Tom’s Hardware, counted 37 founding members and flagged the same three absences: OpenAI, Google and Anthropic. It is a specific list. OpenAI is the company whose model triggered the breach the alliance now cites as proof of its own argument. Google runs one of the largest closed frontier labs in the industry. Anthropic builds Claude, and is already under separate pressure of its own: the Commerce Department imposed an export-license requirement on Anthropic’s Claude Mythos 5 and Fable 5 models in June, restricting how those closed systems can be distributed abroad.
None of the three companies has publicly explained why they stayed out. But the pattern lines up with an older argument in the AI industry: that frontier labs building closed models have generally preferred to keep their internals proprietary, arguing that secrecy itself is a safety feature. The Hugging Face breach undercuts that argument in a very specific way, since it was a closed model’s own testing infrastructure that caused the damage.
Why Is a Chipmaker Setting Rules for AI Security?
Nvidia’s stake in this fight is not purely altruistic. Nvidia sells chips to companies building both open and closed models, but a wide field of enterprises fine-tuning open-weight systems buys a broader spread of Nvidia hardware than a handful of closed labs that increasingly design their own custom silicon. Keeping the open-weight ecosystem legally uncomplicated protects that customer base, and this is not the company’s first attempt at rallying an entire industry around a shared standard; it recently did something similar in robotics, when it rallied Fujitsu, Fanuc, Yaskawa and Kawasaki around a physical AI platform.
Nvidia also has direct experience with export policy turning against it; its own stock slid earlier this year when China chip export approvals arrived as just a trickle. That experience helps explain the urgency behind the July 24 letter, which argued that treating distillation, a common technique for evaluating and improving models, as equivalent to theft would push AI development overseas rather than make it safer. The alliance’s policy ask is specific. Instead of blanket restrictions on open models, it wants public and private investment directed at:
- Shared datasets that let defenders train and test tools against real attack patterns
- Evaluation frameworks that measure how AI systems actually behave under pressure
- Attack simulators that mimic how intruders operate inside real networks
- Red-teaming tools that let smaller defenders stress-test their own systems
The argument runs parallel to a separate fight already underway in Congress, where lawmakers have been debating an AI kill-switch bill aimed at autonomous systems. Both fights turn on the same underlying question: how much control regulators should have over AI systems nobody outside a handful of labs can fully inspect.
Microsoft Backed Both Coalitions, Three Years Apart
The Open Secure AI Alliance is not the first time large tech companies have organized around AI safety. In July 2023, OpenAI, Google, Microsoft and Anthropic announced the Frontier Model Forum, a coalition built around closed frontier models and self-regulation among the labs that made them. That announcement landed on July 26, 2023, almost exactly three years before Nvidia’s alliance launched on July 27, 2026.
Of that original foursome, only Microsoft crossed over into the new coalition. OpenAI, Google and Anthropic, the three partners that built the closed-model self-governance model with Microsoft in 2023, are the same three names missing from Nvidia’s roster now. Microsoft’s own investment in OpenAI, and its role as OpenAI’s primary cloud partner, puts it in the odd position of backing a coalition whose founding case study is an indictment of the closed-model approach its biggest AI partner favors.
- June 12, 2026: The Commerce Department imposes export-license requirements on Anthropic’s Claude Mythos 5 and Fable 5 models.
- July 11 to July 13, 2026: An OpenAI evaluation system breaches Hugging Face’s network over three days.
- July 21, 2026: OpenAI publicly confirms its own models caused the intrusion.
- July 24, 2026: Nvidia, Microsoft and more than twenty other companies send an open letter opposing restrictions on open-weight models.
- July 27, 2026: Nvidia launches the Open Secure AI Alliance with 37 founding members.
The Argument Now Moves to Washington
The alliance’s real test is not technical. Every tool its members open-sourced this week, from Nvidia’s harness research to Microsoft’s bug-hunting agents, already works today. The harder question is whether policymakers weighing restrictions on open-weight models find the coalition’s argument more convincing than the breach that inspired it looks alarming.
For now, the alliance is betting that the same openness that let Hugging Face untangle 17,000 attacker actions in an hour will read, in Washington, as a feature rather than a risk.
-
AI4 weeks agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING1 month agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
AI1 month agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
