Within a week of its formation, Nvidia’s Open Secure AI Alliance had grown to more than 120 organizations and launched SAFE, a Linux Foundation managed request for comments on confidential AI incident reporting. Members are contributing tools for agent identity, permissions, governance, runtime controls, vulnerabili...
Research answer

Create a landscape editorial hero image for this Studio Global article: What progress has Nvidia’s week-old Open Secure AI Alliance (OSAA)—formed after an open letter urging the White House to support rather than. Article summary: Within a week, Nvidia’s OSAA turned its policy coalition into an initial security workstream at Black Hat: more than 120 organizations backed a Linux Foundation–managed request for comments on SAFE, rather than merely is. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
Nvidia’s Open Secure AI Alliance (OSAA) produced its first concrete security initiative at Black Hat: the Shared AI Findings Exchange, or SAFE. The working group has published draft guidelines for public comment, with the Linux Foundation managing the proposal process. That is a faster move than simply issuing a policy statement, but SAFE is still an early framework rather than a demonstrated incident-sharing system.
SAFE addresses a recurring problem in AI security: organizations may discover attacks, failures, or near misses independently, while other companies face similar risks without access to the lessons already learned.
The draft proposal focuses on four related practices:
The intended result is shared defensive intelligence. Instead of treating every prompt-injection, data-leakage, or rogue-agent incident as an isolated event, participants would have a process for turning individual failures into broader safeguards.
SAFE is only one part of OSAA’s approach. The alliance is also bringing together open-source and inspectable technologies intended to address different layers of agent security.
Reported contributions include:
Taken together, these projects cover identity, permissions, agent harnesses, runtime behavior, evaluation, data, governance, and resilience. They could eventually give enterprises a common set of controls for constraining and monitoring AI agents, including agents that behave maliciously or operate outside their intended scope. But that outcome remains a possibility, not an established result.
Reports describe OSAA as having more than 120 organizations within its first week. Major participants cited include Nvidia, Adobe, BlackRock, Cisco, CrowdStrike, Hugging Face, Intel, Microsoft, Red Hat, and Visa; Amazon was described as a newer member.
The alliance followed a July 24 open letter urging U.S. policymakers to avoid broad or premature restrictions on open-weight AI models. The letter was initially backed by 25 companies, including Nvidia, Microsoft, Meta, IBM, Dell, Palantir, and Hugging Face. It argued that restricting downloadable models could undermine competition and push users toward Chinese AI systems as Washington considered its national-security response.
At the time of the Black Hat reporting, Anthropic, OpenAI, and Google were notable absences from OSAA. The relationship with the policy letter is more complicated: reporting differs on the later signatory list, with some accounts saying OpenAI and Google were subsequently added, while other reports describe them as absent from the original group.
The available sources do not explain why those companies had not joined OSAA, so their absence should not be assigned a motive.
OSAA’s central proposition is that openness and security do not have to be opposites. Open models, tools, evaluations, and incident lessons can give more defenders the ability to inspect failures, reproduce vulnerabilities, and adapt fixes. SAFE attempts to balance that transparency with confidentiality during incident collection and analysis, while sharing generalized lessons more broadly.
The alliance’s cross-industry composition could also help establish common interfaces and practices across model developers, cloud and infrastructure providers, identity specialists, security companies, and enterprise users. If those efforts mature, open AI systems may become easier for organizations to evaluate, control, and deploy responsibly.
That could support the broader policy case for open-weight AI as an American competitiveness issue, particularly as U.S. policymakers debate how to respond to Chinese AI labs. But OSAA has not yet demonstrated that it has improved U.S. competitiveness or reduced systemic AI risk. So far, its measurable achievement is narrower and more concrete: a 120-plus-member coalition has moved from open-AI advocacy to a public draft for coordinated AI security reporting, while members contribute tools that could form a more interoperable defense layer over time.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
Within a week of its formation, Nvidia’s Open Secure AI Alliance had grown to more than 120 organizations and launched SAFE, a Linux Foundation managed request for comments on confidential AI incident reporting.
Within a week of its formation, Nvidia’s Open Secure AI Alliance had grown to more than 120 organizations and launched SAFE, a Linux Foundation managed request for comments on confidential AI incident reporting. Members are contributing tools for agent identity, permissions, governance, runtime controls, vulnerability scanning, evaluation, and authorization.
The alliance supports the argument that open AI can improve security by making models, tools, failures, and defensive fixes easier for more organizations to inspect—but its competitive impact remains unproven.