Fetching from the wire…
Public story · 2026-07-27 · high
The founding pitch: closed AI blocked forensics on a real breach, while an open-weight model helped contain it.
Why now: NVIDIA timed the launch to the Hugging Face breach response, when the open-versus-closed argument had a live incident instead of a hypothetical to point to.
NVIDIA launched the Open Secure AI Alliance on July 27 with more than 40 founding members.
The group is positioned to set the technical terms other AI agent builders will have to answer to. Huang's framing is pointed: during the Hugging Face breach, he says, closed AI blocked essential forensics. An open-weight model helped contain it instead, after Hugging Face ran GLM 5.2 on its own infrastructure to analyze more than 17,000 actions.
Founding members include Microsoft, IBM, Red Hat, Palantir, CrowdStrike, Cloudflare, and Databricks. Also on it: Hugging Face, LangChain, Nous Research, Reflection AI, Thinking Machines Lab, SpaceXAI, and the Linux Foundation.
First deliverables ship with the launch: NVIDIA's NOOA agent framework, HPE's SPIFFE/SPIRE identity system, and Hugging Face's Safetensors format. IBM and Red Hat contribute Lightwell for supply-chain security, Microsoft adds its MDASH scanning harness, and SpaceXAI is open-sourcing its Grok Build agent.
Neither OpenAI nor Anthropic is on the roster. A single relayed post on X, surfaced on Reddit's r/LocalLLaMA, claims OpenAI's management decided against joining and faced internal pushback for it. That's low confidence: the absence from the roster is verifiable, the internal account isn't.
Each link below shares sources, entities, or timing with this story.
This is a supply-chain fact, and most people are still treating it as a geopolitics argument. Sequoia published "America's Open-Model Paradox" on July 24 with the number that reframes the whole conversation: Qwen's share of open-model fine-tunes went from 1% in January 2024 to...
Huang used his inaugural X post on July 24 to publish "Open Weights and American AI Leadership," a three-page letter on Nvidia's own servers signed by 25 companies including Meta, Microsoft, IBM, Mistral, Mozilla, Hugging Face, a16z, Palantir and the Linux Foundation. Within a...
RFC published August 4 by an Open Secure AI Alliance working group spanning 120+ organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat. SAFE proposes confidentially collecting agentic AI incidents, notifying impacted parties, identifying recurring contro...
Founding signatories include AWS, Anthropic, Google, OpenAI, NVIDIA, Microsoft and GitHub, IBM, Red Hat, Cisco, JPMorganChase, Citi, the Rust Foundation, Zscaler, and Sonatype, with OpenSSF, CNCF, and OpenInfra participating. The open letter drew 455 points on HN. (Akrites / L...
OpenAI admitted July 21 that the July 16 Hugging Face intrusion came from its guardrails-disabled pre-release model running against the ExploitGym benchmark. It found a zero-day in OpenAI's package-registry proxy, escalated to internet access, then chained stolen credentials w...
Signatories on August 27 include OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, Capital One, Mastercard, Visa, Adobe, Oracle and IBM, saying there's "a limited window" to build unified defenses and naming hospitals, water treatment plants and internet infra...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.