Open Secure AI Alliance Grows to 120+ Members, Proposes SAFE Incident-Sharing Framework at Black Hat 2026
Summary
- • Open Secure AI Alliance has grown to 120+ organizations — up from 40+ at launch — with Amazon and Visa as newest additions announced at Black Hat 2026 on August 4.
- • Linux Foundation published an RFC for SAFE (Shared AI Findings Exchange): proposed guidelines to confidentially collect and share agentic AI security incidents, identify recurring control failures, and publish evidence-based recommendations.
- • Members announced a wave of production-grade open-source tools: Uber's ADR handles 200K+ agent sessions/day across 30K endpoints; NVIDIA's OpenShell sandboxes agent access; Capital One's VulnHunter scans agentic code.
- • The Alliance's foundational case remains the Hugging Face breach, where closed AI tools blocked forensic analysis while open-weight GLM 5.2 analyzed 17,000+ attacker actions on-premise to contain the incident.
Details
Alliance Membership: 40+ → 120+ Organizations
Tripled in membership since launch; Amazon and Visa are among newest additions, bringing major cloud infrastructure and financial sector representation to the coalition.
SAFE Framework RFC Published by Linux Foundation
Shared AI Findings Exchange proposes confidential collection and analysis of agentic AI incidents and near-misses, identification of recurring control failures, and publication of evidence-based operating recommendations.
NVIDIA OpenShell + NOOA Harness
OpenShell runtime restricts what an agent can see and do at the agent level; NOOA research harness on GitHub makes agent behavior easier to test, trace, audit, and govern.
Uber ADR: 200K+ Agent Sessions/Day in Production
Agentic AI Detection and Response system reconstructs the full causal chain of AI agent activity — from prompt to reasoning, tool calls, and outcomes — across 200,000+ daily sessions and 30,000 endpoints.
Amazon + Visa Join; Open-Source Tools Contributed
Amazon contributed Strands Agents (open-source agent toolkit) and Cedar (deterministic authorization language for AI agents); Visa contributed Vulnerability Agentic Harness for identifying and remediating security issues.
Hugging Face Breach: Foundational Case for Open AI
During Hugging Face's own security incident, closed AI tools blocked forensic analysis; open-weight GLM 5.2 ran on-premise to analyze 17,000+ attacker actions and contain the breach — the Alliance's core real-world argument.
Open Models as Cyber Defense Infrastructure
Alliance argues open AI prevents single points of failure, enables on-premise deployment in sensitive environments, and allows community-driven vulnerability discovery impossible with proprietary systems.
Counter-Narrative on Open AI Restrictions
Alliance directly targets policymakers arguing restricting open-weight models harms defenders more than attackers; frames open models as national security assets requiring protection, not restriction.
OpenAI and Anthropic Notably Absent
Major closed-model labs did not join the alliance, underscoring the open-vs-closed industry divide and creating implicit pressure on their regulatory positioning with policymakers.
Built on Akrites + OpenSSF Foundations
Alliance inherits Linux Foundation's Akrites initiative and OpenSSF governance, providing institutional structure and existing security community relationships.
Industry Update = membership and growth; Policy = regulatory proposals and positioning; New Tech = specific tools/runtimes; Partnership = new members and contributions; Security Alert = real-world incidents; Strategy = operational arguments; Context = broader framing; Infrastructure = technical foundations
What This Means
The Open Secure AI Alliance has moved beyond its launch announcement to demonstrate real execution: tripling its membership to 120+ organizations, proposing the SAFE incident-sharing framework, and unveiling production-grade tools from Uber, Amazon, Visa, and dozens of others at Black Hat 2026. The SAFE framework is the Alliance's most consequential output yet — if adopted, it would create an industry-standard mechanism for sharing agentic AI security incidents, analogous to what ISACs do for traditional cybersecurity. Uber's ADR system handling 200,000+ agent sessions per day shows this work is already operating at production scale. The Alliance's core argument — that open models are essential defensive infrastructure — is now backed by real tooling, production deployments, and a 120+ member roster that is increasingly difficult for policymakers to dismiss.
Sentiment
Broadly supportive, with emphasis on industry collaboration and open models for defense
“Open Secure AI Alliance is uniting industry leaders to champion open, auditable AI for safety and security. Open models, open harnesses, and open collaboration to strengthen defenses across the ecosystem.”
“Collaborative security is the cornerstone of ethical progress... this move toward shared research and open weights suggests that the true strength of AI lies not in its complexity, but in its accessibility. When we democratize the tools of learning, we ensure that the 'mind' of the machine remains a reflection of our collective wisdom.”
“黄教主敢于表达,善于表达。这次牵头支持开源模型,组织“Open Secure AI Alliance”, 给在美华人企业家做了个表率,他们不仅可以闷声赚钱,还能形成一股不小的政治力量。”
“Nvidia, Microsoft, and IBM have launched the Open Secure AI Alliance alongside over 40 organizations to develop open-source cybersecurity tools and standards for AI systems.”
Split
No clear divisions; reactions are uniformly positive on open collaboration (~100% supportive among substantive posts).
Sources
- Industry Leaders Unite in Open Secure AI Alliance for AI Safety and SecurityBlogs
- Nvidia’s Open Source Alliance Is Missing Some Key Names: OpenAI and AnthropicWired
- Open Secure AI Alliance Formed by Industry LeadersX
- AI Leaders Propose SAFE Guidelines for Cybersecurity TransparencyNVIDIA
- Nvidia doesn’t mess around: A week after open AI industry group formed, it’s already showing progressTechCrunch
- NVIDIA notes Linux Foundation RFC on Shared AI Findings Exchange (SAFE)X
