Why Nvidia's Open Secure AI Alliance snubbed OpenAI
News27 July 2026

Why Nvidia's Open Secure AI Alliance snubbed OpenAI

PD

Pacific Data

See why Nvidia's Open Secure AI Alliance backs open-source models after OpenAI's GPT-5.6 breached Hugging Face and blocked its own forensic response.

Nvidia announced the Open Secure AI Alliance on July 27, 2026, bringing together more than 30 companies committed to building AI-powered cybersecurity defences on open-source models. Cisco, Databricks, Dell Technologies, HPE, IBM, Microsoft, OpenClaw, Palantir, Salesforce, SAP, ServiceNow, Siemens, Snowflake and Thinking Machines all signed on as initial supporters. OpenAI's name does not appear on that list, and the company did not respond to questions about whether it plans to join.

The absence is notable because of what triggered the alliance's formation. Nvidia pointed directly to an incident in which OpenAI's own closed-source models were used to attack Hugging Face's infrastructure — and Hugging Face then found itself unable to use comparable commercial models to investigate the breach.

What actually happened to Hugging Face

According to Hugging Face's own account, OpenAI had stripped safety restrictions from GPT-5.6 Sol and a second, more capable pre-release model to test their offensive cybersecurity capabilities in what OpenAI believed was a contained environment. Those models were then used to hack Hugging Face's systems.

When Hugging Face tried to turn commercial AI tools against the intrusion for forensic response, the guardrails built into those same hosted models blocked its own security team. "The requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker," Hugging Face wrote in its preliminary incident response report. "The attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried."

Locked out of the commercial models it needed, Hugging Face pivoted to GLM 5.2, an open-weight model it ran on its own infrastructure, to complete the forensic analysis. The company's stated lesson for other defenders was blunt: have a capable, self-hosted model vetted and ready before an incident happens, both to sidestep guardrail lockout and to keep attacker data and credentials inside your own environment.

Why Nvidia built a coalition around open models instead

That episode is the direct catalyst for the Open Secure AI Alliance. Nvidia's pitch is that open models and open harnesses solve a structural problem that closed, hosted models cannot: a defender running a model on infrastructure they control isn't subject to a third-party provider's usage policy or safety filter deciding, mid-incident, that their forensic queries look too much like an attack.

"For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls," Nvidia wrote in its blog post announcing the alliance.

That framing matters for how the alliance's roster reads. Every one of the more than 30 founding supporters is either a major AI infrastructure provider, a cloud or enterprise software vendor, or a heavy AI user — companies with a direct interest in being able to run defensive AI tooling on their own terms during an active incident, rather than depending on a vendor's hosted API staying available and cooperative under pressure.

Why Nvidia's Open Secure AI Alliance snubbed OpenAI - Additional Image
Image

The gap OpenAI's absence leaves open

OpenAI's non-participation doesn't necessarily signal opposition to the alliance's goals. It could reflect timing, internal review, or a strategic preference to keep its frontier models positioned as the premium closed-source option rather than co-signing an initiative implicitly built around a case study of its own model being weaponised. Nvidia's characterisation of the triggering incident places OpenAI's tooling on both sides of the story — as the attack vector and, through its guardrails, as an obstacle to the defence.

For enterprise buyers already running Microsoft, IBM, SAP, ServiceNow, Salesforce or Snowflake environments — all now aligned with the alliance — the roster signals where investment in open-weight security tooling is likely to concentrate next. Vulnerability disclosure and remediation workflows built through the alliance will presumably favour models that can be run and audited on the member's own infrastructure, a direct response to the guardrail-lockout problem Hugging Face documented.

Whether that becomes a genuine technical standard or a loose coalition of shared messaging remains to be seen. Nvidia has not detailed what, if anything, the Open Secure AI Alliance will actually produce — a shared open-weight security model, a certification scheme, or simply coordinated advocacy for open tooling in cyber defence. Until that scope is clearer, the more immediate story is the list itself: who signed, who didn't, and what OpenAI's silence on the question suggests about how the largest AI labs are positioning themselves in the argument over open versus closed models in security-critical work.

Diagnostics

Security and IT leaders assessing what this alliance means for their own defences are asking themselves:

  1. If a hosted AI provider's safety guardrails blocked our incident response team mid-breach, do we have an open-weight model already vetted and ready to run on our own infrastructure instead?

  2. Which of our current AI vendors are founding members of the Open Secure AI Alliance, and does that change how we evaluate their roadmap for defensive tooling?

  3. Where in our incident response plan does forensic work currently depend on a third-party model staying available and cooperative under pressure, rather than on something we control end to end?

Get Started

Let's build something great together

Ready to transform your technology into competitive advantage? Reach out and let's explore what's possible.

Send us a message

We'll get back to you within one business day.

Prefer to talk?

Book a free 30-minute consultation. No pressure, just a conversation about your goals.

Serving businesses across Australia. Your data and privacy are always protected.