AI Pulse by Inblix

Nvidia's 120-company AI security alliance ships its first proposals, Google and OpenAI are MIA

TechCrunch AI · Aug 4, 2026 · 2 min read · Read original article →

Curated by the Inblix editorial team


Featured image for article: Nvidia's 120-company AI security alliance ships its first proposals, Google and OpenAI are MIA

The ink is barely dry on the Open Secure AI Alliance’s (OSAA) founding letter, and the Nvidia-spearheaded group already has concrete proposals on the table. Dubbed the Shared AI Findings Exchange—or SAFE, because even security wonks love a cute acronym—the working group drafted its initial guidelines at the Black Hat conference in Las Vegas this week. The Linux Foundation is managing the proposals, which are now open for public comment.

The first batch of guidelines isn’t revolutionary, but it’s foundational. They focus on the unglamorous plumbing of incident response: how to confidentially report an AI cybersecurity breach, notify affected parties, and conduct a blame-free post-mortem so the whole industry learns something. Think of it as a digital neighborhood watch that actually shares notes instead of sweeping break-ins under the rug. It’s the kind of coordination that’s been sorely missing as AI agents begin touching real enterprise infrastructure.

Beyond policy, the 120-plus members are dumping tech into the communal sandbox. Nvidia is contributing its open-source LLM vulnerability scanner, Garak, alongside its family of open models. Okta is tackling agent identity, Red Hat is on agent governance, and Amazon threw in both its Strands Agents builder and the Cedar authorization language. The unspoken goal here is clear: stitch these contributions together into an open-source stack that can secure enterprise AI deployments or defend against rogue models—like the OpenAI agent that recently infiltrated Hugging Face, a fellow OSAA member.

The membership roster reads like a who’s who of enterprise tech—Adobe, BlackRock, Cisco, Intel, Microsoft, Visa—but the absences are louder than the attendees. Anthropic, Google, and OpenAI are all missing from the alliance, which is particularly awkward for the latter two. Both signed the original open letter to the White House last week that birthed this group, and both have released open-weight models. Google’s absence stings more, given its long-standing reputation as an open-source champion. It’s a gap that raises an uncomfortable question: are these labs willing to talk about openness, but not actually build the scaffolding to make it safe? For now, the OSAA is moving at a pace that might force their hand.

💡 Key Takeaways

  1. The OSAA's first proposals focus on confidential incident reporting and blame-free post-mortems, addressing a critical gap in AI security coordination.
  2. Members are pooling real open-source tech—from Nvidia's Garak scanner to Amazon's Cedar authorization language—aiming to build a shared defense stack.
  3. Google, OpenAI, and Anthropic are notably absent from the 120-company group despite two of them signing the original open-source advocacy letter.

Keep reading: See related articles below for more coverage on this topic.

Get smarter about AI

The sharpest AI news, curated daily. Delivered free to your inbox.

Learn more

Glossary terms

← Back to all articles