Nvidia-led Open Secure AI Alliance scales to 120 members to standardize agent security
The new industry coalition is deploying open-source vulnerability scanners and governance tools to protect autonomous AI agents.
Nvidia has spearheaded the launch of the Open Secure AI Alliance (OSAA), a massive industry coalition dedicated to securing the next generation of artificial intelligence. Within its first week, the group has expanded to more than 120 member companies, signaling an urgent corporate push to standardize AI safety before autonomous agents are deployed at scale.
The alliance includes a heavy roster of global infrastructure and software giants, including Microsoft, Intel, Cisco, Adobe, Visa, and BlackRock. To move beyond theoretical safety, the OSAA has already established the Shared AI Findings Exchange (SAFE), a working group tasked with creating guidelines for the confidential reporting and blame-free analysis of AI cybersecurity incidents. According to the group's founding letter, the alliance operates on the principle that "openness may be one of the most important paths to AI safety and security."
The shift toward open-source safety
The formation of the OSAA follows a coordinated effort by over 200 companies that signed an open letter urging the White House to support open-source AI development. This movement emerges amid a tense climate where national security concerns—particularly regarding open-weight models from China—clash with the industry's desire for transparency. While the alliance has attracted a vast array of enterprise players, major frontier labs such as OpenAI, Google, and Anthropic have not yet officially joined the coalition, despite some of their involvement in the initial open letter.
Securing the autonomous agent surface
As AI evolves from static chatbots into autonomous agents capable of executing business processes and accessing APIs, the potential attack surface for hackers expands exponentially. The OSAA is attempting to prevent a fragmented security landscape by contributing a suite of shared, open-source defensive tools.
Confirmed contributions already include Nvidia’s Garak, an LLM vulnerability scanner, and Amazon’s Cedar authorization language and Strands Agents. Additionally, Okta is providing agent identity technology, while Red Hat is contributing frameworks for agent governance. By standardizing these layers—identity, governance, and scanning—the alliance aims to ensure that the keys to AI safety are not held exclusively by a few closed-source laboratories.
What to watch
The immediate focus for the OSAA remains the operationalization of the SAFE working group and the integration of its member tools into a cohesive security stack. Industry observers will be watching to see if the remaining frontier labs join the alliance, which would unify the world's most powerful AI developers under a single set of security reporting standards. For now, the rapid growth of the OSAA suggests that the enterprise sector views open-source collaboration as the only viable way to defend against the emerging threat of rogue AI attackers.