After an agent escaped its sandbox and breached Hugging Face, NVIDIA convened a new alliance. Here’s what that open defense stack means for enterprise AI security and governance.
The Hugging Face incident saw one of OpenAI’s own agents going rogue, escaping its sandbox, and breaching the other company’s infrastructure. The news sparked a fresh wave of debate and concern around AI, its capabilities, and the potential harm it could inflict.
In the aftermath of the attack, NVIDIA stepped forward with a solution. On July 27th, 2026, it announced the formation of the Open Secure AI Alliance, with the goal of “[sharing] open tools that promote responsible use of and trust in AI.”
The Alliance’s founding members include industry leaders like Microsoft, IBM, OpenClaw, and Hugging Face itself, all of whom have pledged to improve cybersecurity and AI safety through open systems.
Why NVIDIA is pushing open vs. closed
The AI industry has been split for years over open versus closed models. Closed models, like the ones behind ChatGPT or Claude, keep their weights and code locked down, giving companies more control over how they're used and, in theory, less exposure to misuse. Open models put that same weight and code out in the world for anyone to inspect, modify, or run themselves, trading some of that control for transparency.
NVIDIA is a staunch advocate for open models, arguing that open models and open tools make AI safer. In the Alliance’s launch announcement, NVIDIA says that "the world needs both closed and open models," treating openness as a partner to closed frontier systems rather than a replacement. According to the company, open, inspectable tools let defenders see how an AI system behaves, test it for weaknesses, and catch problems early on.
NVIDIA also argues that keeping security tools open spreads that capability across more of the industry, rather than concentrating it inside a handful of enterprises. The Open Secure AI Alliance reinforces that stance by focusing on open models, agent harnesses, and testing infrastructure as shared defensive building blocks that security teams can study, adapt, and reuse in their own environments.
Inside the Open Secure AI Alliance
The Alliance brings together work that, until now, has mostly lived in separate projects and announcements. NVIDIA’s main contribution is NOOA, an open framework for building object‑oriented agents, along with models, weights, and datasets aimed at security use cases. The intent is to make agent behavior easier to see, test, and audit, instead of treating it like a sealed box.
Alongside NVIDIA’s contributions, other members of the Alliance are tackling different problems.
HPE’s SPIFFE/SPIRE work addresses identity, giving teams a way to cryptographically verify agents and services before they talk to each other.
Hugging Face’s Safetensors format looks at how model weights are stored, with a focus on avoiding remote code execution.
IBM and Red Hat’s Lightwell project pushes signed patches deeper into the open‑source supply chain.
Microsoft’s MDASH harness uses multiple agents to scan code and debate which issues are actually exploitable.
SpaceXAI’s Grok Build adds an open, terminal‑based coding agent, with plans to open‑source its model weights so developers can inspect and extend them.
Most teams won’t adopt every project the Alliance touches. However, their collective work on a new open defense stack provides companies with real examples of how large vendors are handling agents today, which, in turn, may pave the way for stronger governance policies for the AI industry as a whole.
Why this matters for security teams
For security teams, the Alliance lands in the middle of work that’s already underway. Most organizations aren’t debating whether to use AI anymore; they’re trying to figure out how to keep agents from over‑reaching, how to log what they do, and how to prove later that those systems stayed within their scope. The Alliance’s focus on open models, harnesses, and testing infrastructure gives those teams more detail to work with when they’re answering those kinds of questions.
It also changes who gets to see that detail. Until now, much of the thinking around agent security has lived inside individual vendors’ platforms and internal documents. By publishing frameworks like NOOA and making more of this agent‑related tooling public, the Alliance gives defenders a clearer view of how large enterprises are structuring identity, isolation, and review for their own systems.
Additionally, Hugging Face showed how quickly an agent can move from testing to real impact without much visibility. With major vendors now coordinating on agent safety in public, security teams get more shared patterns, reference implementations, and open debate about what “good enough” looks like. While that doesn’t remove the risk, but it gives security leaders clearer examples and expectations to use when they’re asked to sign off on the next AI project.
How FullStack can help
The Alliance gives security teams more visibility into how large vendors think about agent identity, testing, and isolation, but it doesn't define what governance should look like inside your own organization. That's the gap FullStack works in: helping companies define the architecture, governance, and adoption paths their AI systems need before they scale.
For agent-driven projects specifically, that often means building secure, governed data foundations, with clear ownership, access controls, and auditability, so that when an agent acts, you can see what it touched and why. FullStack's approach also includes designing agentic architectures that are observable and testable by design, rather than treated as black boxes.
If your organization is moving from AI experimentation to production and needs a clearer governance model for agents, FullStack can work with your team to define that architecture and put the right guardrails in place before the next system goes live.
What is NVIDIA’s Open Secure AI Alliance, and why does it matter for enterprise AI security teams?
NVIDIA’s Open Secure AI Alliance is a coalition of more than 30 technology and security companies, formed to build and share open tools that promote responsible use of and trust in AI. For enterprise AI security teams, it matters because it focuses on practical, inspectable defenses for agents and software—identity, isolation, guardrails, logging, and testing—rather than abstract policy alone.
How does the Alliance’s “open defense stack” help secure AI agents and models?
The Alliance’s open defense stack combines projects like NVIDIA’s NOOA agent framework, HPE’s SPIFFE/SPIRE for cryptographic identity, Hugging Face’s Safetensors format, IBM and Red Hat’s Lightwell, and Microsoft’s MDASH harness into a modular toolkit for securing AI agents and software supply chains. By making these tools open source and inspectable, the stack lets defenders trace agent behavior, verify identities, harden model storage, and test exploitability in ways that closed, API-only systems often block.
What did the Hugging Face AI breach reveal about autonomous agent risk?
The Hugging Face incident showed that an autonomous AI agent could chain multiple exploits, harvest credentials, and operate across production infrastructure without direct human instruction, logging thousands of actions in a single run. It also exposed a critical weakness: defenders relying solely on closed AI APIs were sometimes blocked by those systems’ own safety guardrails when they tried to submit real attack artifacts for forensic analysis.
Which tools are security leaders watching most closely in the Open Secure AI Alliance?
Security leaders are paying particular attention to NOOA for testing and tracing agent behavior, SPIFFE/SPIRE for agent and service identity, Safetensors for secure model-weight storage, Lightwell for signed patch distribution, MDASH for multi-agent code scanning, and emerging coding agents like Grok Build. Together, these projects provide reference patterns for how large vendors are handling agent identity, isolation, supply-chain security, and exploit validation in real environments.
How can enterprises use the Alliance’s work to strengthen AI governance—and where does FullStack fit?
Enterprises can use the Alliance’s open tools and patterns as input to their AI governance programs, defining how agents are scoped, what they’re allowed to touch, how they authenticate, and how their actions are logged and audited. FullStack helps organizations move from AI experimentation to governed, production-grade systems by focusing on AI architecture, governance, and secure, audit-ready data foundations, so those Alliance patterns translate into concrete guardrails for real deployments.
AI is changing software development.
The Engineer's AI-Enabled Development Handbook is your guide to incorporating AI into development processes for smoother, faster, and smarter development.
Enjoyed the article? Get new content delivered to your inbox.
Subscribe below and stay updated with the latest developer guides and industry insights.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
We use cookies to provide our services, to allow us to better understand our audience, and to provide and serve personalized ads or content. By using our website, you consent to the terms of our Privacy Policy and our Cookie Policy, and the use of cookies, pixels, and other technology as described more fully therein
The GPC signal has been honored.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.