Skip to content
feed: live
>_ 0dayNews
threat intel
Analysis

NVIDIA Launches 37-Member Open AI Security Alliance

NVIDIA and 36 partners formed the Open Secure AI Alliance and open-sourced the NOOA Framework. What the member list signals about where this is headed.

NVIDIA Launches 37-Member Open AI Security Alliance
Photo: Coolcaesar / Wikimedia Commons · CC BY-SA 4.0
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

NVIDIA and 36 other organizations announced the Open Secure AI Alliance on July 27, releasing a framework called NOOA as its first open-source deliverable. Members include Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and others spanning cloud, security, enterprise software, and AI infrastructure.

The member list is the most informative piece of the announcement. An alliance whose founding members all have competing commercial interests in AI security tooling could just as easily produce three years of working-group documents nobody ships. This one is structured differently: the major vendors whose products and services will need to interoperate on AI security are at the table from day one. CrowdStrike, Palo Alto Networks, and IBM sell security products that will need to reason about AI agents. Hugging Face and NVIDIA build and distribute AI infrastructure those products will have to protect. Cisco and Red Hat own the network and platform layer between them. That composition is not an accident of invitation — it looks like a deliberate attempt to get the whole stack in the same room before the specifications get written.

NOOA being released as an open-source framework on launch day is what makes this a concrete commitment rather than a press release. There’s now something to evaluate, contribute to, and adopt — or reject — rather than a roadmap that obligates nobody to build anything. What NOOA specifically addresses in AI agent security architecture isn’t fully detailed in early reporting; the launch composition and the mandate (“develop and share open technologies, techniques, and tools for securing software and artificial intelligence agents”) are the stated starting points.

The timing is pointed. Hugging Face disclosed a breach of internal AI infrastructure last week, and that same platform is now a founding member of this consortium. That is not contradiction — it is the realistic picture of the moment. The organizations closest to AI security problems are also the ones with the highest exposure to them. AI coding tools have been failing to contain execution within their intended sandbox boundaries, and ransomware operators have begun targeting AI model weights and vector databases as assets worth encrypting. The threat surface for AI systems is materializing faster than the frameworks for defending it.

That gap is what makes the Alliance’s mandate worth taking seriously as a structural problem. Existing threat models — CVSS, ATT&CK, the established vulnerability classification hierarchy — were not built with AI agents in mind. A prompt injection attack that manipulates an autonomous agent’s reasoning does not map cleanly onto the concepts those frameworks use to categorize impact and exploitability. The industry is inventing the security primitives for AI in real time, and a 37-member consortium with an open-sourced framework is the right shape of attempt to get ahead of that, even if it is still catching up.

The precedent worth watching here is MITRE ATT&CK — a framework that became genuine infrastructure by earning adoption, not announcing it. Practitioners tagged behaviors to it, vendors referenced it in their detection products, and defenders used it to measure coverage gaps. That uptake happened over years, not quarters. NOOA’s trajectory will look similar. Twelve months from now, the question is whether it appears in CI/CD pipeline security tooling, whether the member vendors are actually referencing it in their AI product lines, and whether practitioners outside the founding group are filing issues and contributing. The launch is table stakes.

The founding composition gives it a credible shot. That is an honest read, not a promotional one.

Found this useful? Share it.