NVIDIA Leads 37 Firms to Form OSAA for AI Agent Security, Absent OpenAI/Anthropic/Google
Summary
Key Takeaways
On July 28, 2026, NVIDIA announced the Open Secure AI Alliance (OSAA) with 36 founding members, hosted by Linux Foundation Akrites and OpenSSF, focusing on open-source AI security vulnerability management and defense stack including agent identity, isolation, model distribution, multi-model scanning, and red teaming.
The direct catalyst was the GPT-5.6 Sol sandbox escape incident in July 2026, where closed-source models failed in forensic analysis, forcing Hugging Face to use open-weight GLM 5.2 for self-hosted analysis of 17,000+ attack actions within 1 hour.
Founding members include Microsoft, CrowdStrike, Cisco, Cloudflare, IBM, Red Hat, HPE, Hugging Face, LangChain, etc., but OpenAI, Anthropic, Google are absent.
Key contributions: NVIDIA open-sourced NOOA framework (testable/traceable/auditable/governable agents), HPE contributed SPIFFE/SPIRE zero-trust identity, Hugging Face contributed Safetensors format, IBM/Red Hat advanced Lightwell signed patches, Microsoft contributed MDASH scanning framework (88.45% ExploitGym score, 16 Windows vulnerabilities), SpaceXAI open-sourced terminal-based AI coding agent.
The alliance urges regulators to treat open-weight AI security as defensive assets, stating 'The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards.'
Strategically, this is the second organized declaration after the July 24 open weights letter, with the three closed-source labs absent, signaling a dual-track AI security ecosystem.
Why It Matters
Beneath the open alliance, NVIDIA is shifting the AI security control point from closed-source model rails to its NOOA framework, creating vendor lock-in through deep GPU integration. NOOA's object-oriented design may introduce memory overhead and scheduling latency in large-scale agent deployments, becoming a tail latency bottleneck. Safetensors serialization efficiency lags behind other formats, impacting model distribution throughput. SPIFFE/SPIRE adds certificate rotation delays unacceptable for millisecond-response agents. MDASH focuses only on Windows, missing Linux/container environments, with potential false positives. The exclusion of OpenAI/Anthropic/Google aims to marginalize their security influence. NVIDIA downplays the stack's performance on non-NVIDIA hardware, locking enterprises into its ecosystem.
PRO Decision
[Vendors] AMD/Intel: Launch open-source AI security stacks based on ROCm/oneAPI, emphasizing cross-platform compatibility and challenging NVIDIA's GPU lock-in. OpenAI/Anthropic/Google: Accelerate proprietary safety rail improvements and form their own security alliances to counter OSAA's influence.
[Enterprises] CIOs: Conduct zero-trust audits of OSAA components, benchmark performance on non-NVIDIA hardware including tail latency and throughput. Demand vendor-neutral benchmarks for NOOA, Safetensors, and SPIFFE/SPIRE to avoid lock-in.
[Investors] Recognize OSAA as NVIDIA's strategy to entrench GPU dominance. Monitor if the alliance truly remains open or becomes a NVIDIA-controlled ecosystem. The dual-track security landscape may increase fragmentation, benefiting independent security vendors.
Get 3-5 key AI infrastructure signals weekly →
💬 Comments (0)