Open Secure AI Alliance Moves to Linux Foundation

The Open Secure AI Alliance has moved under the Linux Foundation, giving the initiative what the organizations describe as a neutral home for developing open source tools, shared standards and defensive practices. The Alliance was launched by NVIDIA in July to develop open security technologies for AI systems and agents.

The Linux Foundation announced the transition Sept. 2, saying the Alliance will continue work intended to help organizations inspect, audit, and secure AI systems. The change follows the Alliance's July launch, when its stated scope already extended beyond AI models into agent runtimes, identity, permissions, isolation, guardrails, and other infrastructure controls.

The Linux Foundation said the new governance model is intended to support collaboration across vendors, platforms, and industries. The Alliance's current project site similarly describes its work as an open defensive stack of AI models, tools, and techniques that defenders can inspect, adapt, and run on infrastructure they control.

Neutral Governance for a Multi-Vendor Stack

The Linux Foundation said the transfer puts the Alliance under its neutral governance, with the goal of accelerating a shared, open security stack for AI. "AI security is a shared challenge," the Foundation said in announcing the move, adding that organizations need to collaborate across vendors, platforms, and industries.

The governance change formalizes a role the Linux Foundation had already begun playing. When the Alliance launched July 27, the Foundation joined as an inaugural partner alongside NVIDIA, Microsoft, and other cloud, security, enterprise software, and AI organizations. The Linux Foundation said at the time that its role was to provide a neutral environment where organizations that also compete can collaborate on shared infrastructure.

Open Secure AI Alliance Inaugural Members (From July)
[Click on image for larger view.] Open Secure AI Alliance Inaugural Members (From July) (source: NVIDIA).

NVIDIA's original Alliance announcement framed that infrastructure requirement in multi-vendor terms. It said defenders need the ability to inspect, adapt, and operate advanced AI on infrastructure they control, while critical industries need defensive tools capable of supporting security systems across a multi-vendor ecosystem without creating single points of failure.

The Alliance's current site makes portability another part of that model. "Portable defenses remain effective as models, vendors, and environments change," it states. The site says those defenses should support flexibility across models, infrastructure, applications, and security services.

Its definition of the agent security stack also reaches into areas familiar to cloud and platform teams. The Alliance identifies models and inference, agent context, harnesses, policy, identity, governance, enforcement, containment and recovery, and a trusted foundation that includes hardware identity, isolation, protected keys, and evidence.

Whole Agent Stack
[Click on image for larger view.] Whole Agent Stack (source: Linux Foundation).

The site says organizations need to govern the full agent stack rather than treating the language model as the complete security boundary. It identifies runtimes, identity, policy, enforcement points, observability, and recovery as parts of the system that need to be open, testable and auditable.

SAFE Extends the Scope to Cloud Providers

One of the Alliance's active projects is the Shared AI Findings Exchange, or SAFE, a proposed incident-learning and assurance framework. The SAFE Request for Comments calls for confidential collection and analysis of AI incidents and near misses, notification of affected parties, and conversion of recurring failures into evidence-based security controls.

SAFE's proposed membership includes model developers, AI deployers, enterprise customers, independent security researchers, critical-infrastructure operators, government and standards organizations, and "evaluation, hosting, cloud, and tool providers."

The Linux Foundation's August description of SAFE likewise invited AI developers, enterprises, cloud providers, researchers, and infrastructure operators to help shape the proposal. It said structured incident reviews should cover the complete AI operating stack, including models, safeguards, tools, runtime environments, monitoring, human operations, and supply-chain dependencies.

SAFE goes further by identifying cloud infrastructure as a possible dependency in an incident investigation. Its proposed review framework asks whether a cloud, evaluation, data, or tooling partner invalidated assumed controls. Evidence preservation could include prompts, traces, tool calls, logs, configurations, model and safeguard versions, third-party dependencies, workload identities, credentials, approval events, and a complete incident timeline.

The proposal also describes defensive measures that could result from that shared incident analysis, including reusable tests, machine-readable policies, detection rules, reference configurations, and incident-response guidance. For unintended access to real systems, the RFC lists possible recommendations such as default-deny network egress, target allowlists, independent isolation checks, real-time action monitoring, and automatic stops when an agent's permitted scope is uncertain.

Industry Contributions

Microsoft was among the organizations identified as inaugural Alliance partners. NVIDIA's launch announcement also identified Microsoft's MDASH as one contribution to the Alliance's broader defense stack, describing it as a multi-model agentic scanning harness that coordinates specialized AI agents to discover, debate, and demonstrate exploitable software bugs.

Other documented contributions cover separate layers of the same stack. NVIDIA cited HPE's SPIFFE/SPIRE work for workload and service identity, Hugging Face's Safetensors format for model weights, IBM and Red Hat's Lightwell work around signed patches, and NVIDIA's own models, weights, data, and agent-harness research.

Those contributions reinforce the Alliance's stated focus on controls surrounding agents rather than a single model or deployment environment. NVIDIA described the scope at launch as including identity, isolation, model formats, multi-model scanning, and secure coding workflows.

For more information, visit the Open Secure AI Alliance site here.

Featured

  • VSLive! session

    VSLive! San Diego 2026 Puts AI at the Core of the Campus IT Stack

    For higher education IT teams working through AI pilots, ERP integrations, student-facing apps, analytics projects, and mounting security concerns, Visual Studio Live! San Diego 2026 offers a look at the development practices that are shaping the campus technology landscape.

  • businessman holding tablet with holographic AI icons

    Google Moves AI Agents into the Mainstream

    At its recent I/O developer conference, Google presented artificial intelligence agents not as a distant research project, but as a product strategy spanning Search, personal assistants, productivity software, developer tools, and smart glasses.

  • Businessman using laptop analyzing data and growth graph chart

    AI Budgets in Education Show No Sign of Decline

    The vast majority of education organizations (98%) expect their AI infrastructure budgets to either increase or hold steady over the next year, according to a recent report from cloud storage provider Wasabi.

  • Blue digital wireframe classical building structure

    Before AI, Fix Your Data

    Institutions don't have to solve every data problem before they can begin using AI responsibly. But they do need to treat information as a strategic asset — not a byproduct of operations — and start building toward AI-ready data now.