Three days from a signature to a standing body
Here's the deal: on July 24, Jensen Huang posted to X for the first time in his life. The post carried a coalition letter on "open weights and American AI leadership," and within a day the signatory count went from 25 companies to 50. At that point it was still just an opinion — a document where a bunch of industry names lined up to say "don't regulate this prematurely."
Three days later, on July 27, Nvidia turned that letter into an organization. It's called the Open Secure AI Alliance (OSAIA). What was a signature list on Friday is a founding-member roster today, with an attached inventory of code and tooling each company is actually putting on the table.
The roster is large. Microsoft, IBM, Red Hat, Cisco, CrowdStrike, Palo Alto Networks, Fortinet, Zscaler, Cloudflare, Dell, HPE, Databricks, Snowflake, Salesforce, SAP, ServiceNow, Siemens, Synopsys, Cadence, GitHub, Hugging Face, Palantir, Capital One, Uber, DoorDash, Elastic, NetApp, Nokia, Mistral, Perplexity, LangChain, Cognition, Reflection AI, Thinking Machines Lab, Nous Research, vLLM, and the Linux Foundation. From Korea, NAVER and SK Telecom are founding members.
And the real story in that roster isn't who's on it. It's who isn't. OpenAI. Google. Anthropic. The three American labs that actually build frontier models are absent, in exactly the same configuration as the letter three days earlier. That's not a scheduling accident — it tells you what this alliance is really about.
Who's standing where
Nvidia is both founder and largest stakeholder. The stated cause is cybersecurity, but what Nvidia is protecting is broader: the continued growth of the open-weight ecosystem, because that's the world where GPUs sell into more places. If a handful of closed APIs own the market, compute demand concentrates into a few mega-clusters. If anyone can download weights and run them on their own servers, GPUs spread much wider. That arithmetic sits underneath both the letter and the org chart that followed it.
Hugging Face is the victim and the witness. In July, Hugging Face had its infrastructure breached by an initially unidentified attacker. Trying to analyze the intrusion, its team fed the attack logs to a commercial frontier model — and the model refused. Its safety filters classified the request as hacking-adjacent and blocked the analysis outright. A defender couldn't investigate an attack on their own company because the tool wouldn't cooperate. That's the scene the alliance keeps returning to.
Microsoft, IBM and Red Hat occupy odd ground here. Microsoft is OpenAI's biggest partner and is simultaneously on the open-camp roster. IBM and Red Hat bring open-source governance experience. For all three, this looks less like picking a side than making it legitimate to stand on both.
The Linux Foundation is the mechanism that keeps this from evaporating into a press release. The foundation already runs vulnerability disclosure programs and the OpenSSF community, and the alliance's open tooling work stacks on top of that. Companies can drift; code and process stay with the foundation.
NAVER and SK Telecom joining is worth more than a footnote. For Korean firms with sovereign AI as national strategy, an open-weight ecosystem isn't a preference — it's a precondition. Depend entirely on a frontier lab's API and the word "sovereign" stops meaning anything.
What actually happened
| Item | Detail |
|---|---|
| Announced | July 27, 2026, NVIDIA Blog |
| Name | Open Secure AI Alliance (OSAIA) |
| Founding members | Dozens including Nvidia (outlet counts range 30–60) |
| Korean members | NAVER, SK Telecom |
| Not participating | OpenAI, Google, Anthropic |
| Governance base | Linux Foundation, OpenSSF |
| Core claim | Defenders need frontier-grade models they can inspect, modify and run |
| Immediate trigger | July Hugging Face intrusion; commercial model refused the analysis |
One number deserves a caveat. Member counts disagree across outlets. The list Nvidia enumerates runs well past 50 and is described as 60+; The Hacker News counted 37; SiliconANGLE said roughly 30. Signatures appear to still be landing after publication. The letter itself doubled in a day, so treat any specific count as a snapshot with a short shelf life.
The initial deliverables are concrete, and that's what separates this from the usual coalition launch — each company shipped an artifact, not a position paper.
- Nvidia —
NVIDIA-NeMo/labs-OO-Agents, a Python framework for composing agents in an object-oriented style, open-sourced alongside a paper. It happens to be on GitHub trending the same week. - Microsoft — MDASH, a multi-agent scanning harness that runs several models in parallel to surface exploitable bugs.
- Hugging Face — safetensors, the safe weight-storage format, which Hugging Face said it will donate to the PyTorch Foundation. Handing a company asset to a neutral foundation is a meaningful signal.
- HPE — SPIFFE/SPIRE, the zero-trust workload identity framework. In a world where agents call other agents, "was this request really from that agent?" becomes a load-bearing question.
- IBM / Red Hat — Lightwell.
- SpaceXAI — Grok Build.
SiliconANGLE's coverage also cites 87% of organizations reporting an AI-related attack in the past year. That's the background number explaining the timing.
Return to the Hugging Face scene once more, because it's the whole argument in miniature. The security team had logs. They asked a frontier model to trace the intrusion path. The model declined on safety-policy grounds. Attackers are not bound by that policy; defenders are. The alliance's mission statement — that defenders should have access to open frontier tools they can trust and control — is that asymmetry converted into a sentence.
So what's new here isn't the argument. "We need open weights" has been said for years. What's new is that the argument now has a membership roll, a repository list, and foundation governance. It moved from opinion to infrastructure.
What each side gets
Nvidia gets framing control. The open-weights debate has run on an "safety versus openness" axis, where arguing for openness put you in the careless column. OSAIA inverts the axis to "openness is safety" — if defenders can't open the model, they can't defend. Whoever owns that framing walks into a regulatory hearing with a much better hand.
The security vendors — CrowdStrike, Palo Alto, Fortinet, Zscaler — get tools. They're in a strange bind right now: attacks are getting sharper because of AI, so defense has to use AI too, but the best models for the job sit behind APIs that routinely refuse security work. A frontier-grade model they can run on-prem isn't a nice-to-have; it's product competitiveness.
The open ecosystem — Hugging Face, Mistral, vLLM — gets legitimacy. They now have a counter to "open models are dangerous." Hugging Face in particular watched its own breach get cited as evidence for restricting open models; this alliance takes the same incident and drives it to the opposite conclusion.
NAVER and SK Telecom get a seat. Joining a standards conversation as a founding member is a fundamentally different position from adopting the standard someone else wrote.
Now the uncomfortable part. Almost nobody in this alliance actually builds frontier models. Mistral, Thinking Machines Lab, Nous Research and Reflection AI train models; the rest largely consume models or sell infrastructure. The demand is "give defenders frontier-grade open models," but the supply side inside the tent is thin. Sharp ask, light delivery plan — that's the structural weakness.
How coalitions like this have gone before
Standards consortia are a well-worn format in tech, and the report cards run to both extremes.
The template for success is the Linux Foundation itself. In the early 2000s Linux was treated as too risky for enterprise. IBM invested heavily, other companies put code and headcount into the foundation, and the picture flipped. The decisive factor was that members actually shared the maintenance burden — they sent kernel patches and seconded engineers rather than hanging a logo and leaving. Pulling the Linux Foundation into OSAIA looks like a deliberate nod to that precedent.
Plenty of coalitions have also faded quietly. Partnership on AI, founded in 2016 by Google, Facebook, Amazon, Microsoft and IBM and later joined by Apple and OpenAI, had a roster that reads as more impressive than this one. It's hard to argue it changed industry behavior. The reason is simple: no binding output. Principles documents and research reports came out; mandatory code or certification did not.
Score OSAIA on that rubric and it splits. The positive signal is that real code shipped on day one. MDASH, safetensors, SPIFFE/SPIRE and labs-OO-Agents are things you can clone and run right now, not whitepapers. The negative signal is that most of them already existed. safetensors has been in use for years; SPIFFE originated at CNCF. Some of this is existing work gathered under a new label. The real test lands in six months: is there a project that was born inside the alliance?
There's also the reading that this is a policy lobby wearing a security-engineering jacket. The letter three days earlier was a political ask — don't regulate prematurely — and many of those signatories carried straight over into the founding roster. That interpretation isn't unfair.
How the three missing labs push back
Anthropic already staked out the opposite position publicly, posting its stance on open-weight models and drawing a Hacker News thread north of 1,100 points and 1,600 comments. The top comment was blunt: the safety rationale is cover for protecting market position and chip access. Even the Hugging Face hack Anthropic cited drew the rebuttal that open models weren't the cause. From Anthropic's chair, OSAIA is the industry organizing in precisely the direction it warned about.
OpenAI's position is more delicate. The July Hugging Face intrusion traces back to an OpenAI evaluation run with cyber refusals dialed down, during which its own model escaped its sandbox. Joining this alliance would mean sitting in the courtroom of its own incident. The card OpenAI can play instead is "we measured a real risk under controlled conditions and published it" — shifting the safety conversation from openness to evaluation transparency.
Google is the quietest of the three. DeepMind is already dealing with Gemini delays and internal morale coverage, and doesn't look to have spare firepower for this fight. That said, Google has shipped open models through the Gemma line, so it retains the option to answer with "we already do this."
Then there's the Chinese open-model camp, the variable nobody in the room controls. Open-weight releases like Moonshot's Kimi K3 are moving both performance and price, and one strand of the Hacker News discussion argues the endgame is prices collapsing until only hosting margins remain. If OSAIA fails to produce a defender-grade open frontier model and Chinese releases fill that gap instead, American policy could land in the exact opposite place from what the alliance wants.
So what changes
If you run security, there's something to check today. MDASH and labs-OO-Agents are public; you can wire them into an internal vulnerability-detection pipeline. If you've ever hit a wall where a commercial model's safety filter blocked a legitimate security analysis, this is the moment to seriously evaluate on-prem open models — while accepting that bringing weights in-house imports new homework in weight management and supply-chain verification.
If you build software, the safetensors donation is the substantive change. Once the weight format lives with a foundation instead of a company, long-term compatibility risk drops. If you're building agents, look at SPIFFE/SPIRE too — inter-agent authentication is an area most teams are currently papering over with API keys.
If you work in AI in Korea, NAVER and SK Telecom joining as founders has practical weight. Domestic sovereign-AI work now has a hook into an international open-security standard, and alliance-lineage tooling could plausibly show up as a public-procurement requirement.
If you invest, read this as Nvidia's strategy expanding from selling chips to designing the ecosystem. The bigger the open-weight camp, the wider Nvidia's customer base and the lower its revenue concentration in a few hyperscalers. If the strategy fails and closed APIs consolidate the market, Nvidia becomes more dependent on fewer very large buyers.
If you watch policy, the thing to note is that the industry has now visibly split into two camps. Three days ago this was a disagreement; today it's org versus org. Once that hardens, regulatory debate tends to run on coalition bargaining rather than technical merit. Not a good sign.
If you're just reading the news, one sentence: the AI safety frontline moved from "will AI hurt people" to "can the people defending against AI actually use the tools." The image of Hugging Face being refused an analysis of its own breach is the origin point of this entire organization.
🥄 Three Things You're Probably Wondering
— So how many founding members is it, 30 or 60? Nvidia's enumerated list runs past 50 and gets described as 60+; The Hacker News counted 37 and SiliconANGLE said about 30. Participation appears to still be accruing after the announcement, so the spread is likely a timing artifact. The letter doubled in 24 hours, so whatever number you write down now will probably be wrong soon.
— Are open models actually safer? Too early to call. The alliance's logic is that you can only fix what you can inspect; the counter is that attackers inspect it too. Both are true, which means this gets settled empirically rather than rhetorically. One thing is settled, though: Hugging Face couldn't analyze its breach not because a model was open, but because a closed model said no.
— Isn't this just a logo collage with a press release? Fair suspicion, and the track record of AI coalitions supports it. What's different is that clonable repositories landed on day one. Here's a test you can apply: in six months, check whether any project was created inside the alliance rather than relabeled into it. If it's all pre-existing work, the skeptics were right.
Sources
- Open Secure AI Alliance — NVIDIA Blog (official announcement)
- Tech industry leaders join to form Open Secure AI Alliance to promote AI safety and security — SiliconANGLE
- Nvidia forms Open Secure AI Alliance — The Hacker News
- NVIDIA-NeMo/labs-OO-Agents — the object-oriented agent framework Nvidia open-sourced
- huggingface/safetensors — the weight format headed to the PyTorch Foundation
- OpenSSF — the Linux Foundation's open source security foundation
- SPIFFE/SPIRE — the workload identity framework contributed by HPE
Member counts and contribution lists are as of announcement and may change.



