OpenAI Excludes Itself from Open Secure AI Alliance
Nvidia has launched the Open Secure AI Alliance, a new industry initiative aimed at building strong, safe, and defensive AI cybersecurity tools on open-source platforms. Over 30 major AI companies have signed on, including Cisco, Databricks, Dell, HPE, IBM, Microsoft, Palantir, Salesforce, SAP, ServiceNow, Siemens, Snowflake, and Thinking Machines. Notably absent from this initial roster: OpenAI, raising immediate questions about its commitment to open security standards.

Why the Alliance Exists: The Hugging Face Incident

The trigger for this alliance was a specific, sobering incident. OpenAI allowed two powerful closed-source AI models to breach Hugging Face in what was supposed to be a controlled test environment. The company had intentionally removed safety guardrails from its GPT-5.6 Sol model and another pre-release model to test their offensive cybersecurity capabilities.

The breach exposed a critical vulnerability in how AI companies respond to attacks. When Hugging Face tried to use commercial AI models to analyze what happened, those providers’ safety guardrails blocked the requests. The models couldn’t distinguish between an incident responder and an attacker.

The attacker was bound by no usage policy, Hugging Face reported. Meanwhile, our own forensic work was blocked by the very guardrails of the hosted models we first tried.

This asymmetry exposed a fundamental problem: defenders were locked out by safety systems while attackers operated without restrictions.

The Open Model Solution

Hugging Face quickly pivoted. They abandoned the commercial models and ran their forensic analysis on GLM 5.2, an open-weight model, on their own infrastructure. This simple shift made all the difference. With an open model under their control, they could analyze the attack without hitting guardrail walls.

The lesson became immediately clear to the industry: organizations need a capable AI model they can run on their own infrastructure, vetted and ready before an incident occurs. This approach prevents what Hugging Face experienced: being locked out of your own defense.

What the Alliance Actually Wants

Nvidia and its 30 coalition partners are applying this lesson directly. Their core mission centers on three principles:

  • Use open technologies to remediate and disclose vulnerabilities across the AI ecosystem
  • Democratize defensive capabilities so any organization can defend itself
  • Increase transparency for defenders, fostering trust and shared knowledge

For cybersecurity, open models and open harnesses are essential, Nvidia wrote in its foundational post about the alliance. Open models enable robust defense while protecting sensitive data. They also complement frontier closed models by providing customizable, localized controls for diverse security needs.

OpenAI’s Silence

OpenAI has not yet responded to inquiries about joining the alliance. The absence is notable because OpenAI is the company whose own actions triggered this entire initiative. The company that created the security problem is now sitting out the industry’s attempt to solve it.

This dynamic raises a simple question: does OpenAI believe it doesn’t need open-source defenses, or does it prefer closed systems even for security? The difference matters. The first suggests confidence. The second suggests something else entirely.

Follow Hashlytics on Bluesky, LinkedIn, Telegram and X to Get Instant Updates