A coalition of leading technology companies, cybersecurity firms and open-source organisations has launched the Open Secure AI Alliance, a new initiative aimed at strengthening AI-driven cybersecurity through open models, tools and technologies that enable organisations to build transparent, adaptable and resilient defence systems.
Building on the leadership of the Linux Foundation's Akrites initiative and the Open Source Security Foundation (OpenSSF), the alliance seeks to accelerate the identification, remediation and disclosure of software vulnerabilities using open technologies while promoting responsible AI adoption for cyber defence.
The alliance argues that as artificial intelligence becomes increasingly embedded in critical infrastructure, cybersecurity should not rely solely on proprietary AI systems. Instead, it advocates a balanced ecosystem in which both closed and open AI models play complementary roles, with open models providing greater transparency, customisation and operational control for defenders.
According to the alliance, open-source software already serves as a foundational layer for industries including cloud computing, financial services, telecommunications, manufacturing, government services and the internet. Extending this approach to AI-powered cybersecurity, it says, will enable organisations to inspect, adapt and deploy advanced defensive capabilities without depending on a single vendor.
The initiative cites the recent security incident at Hugging Face as an example of why open AI systems are becoming increasingly important for cyber defence. During the incident, Hugging Face reportedly used the open-weight GLM 5.2 model on its own infrastructure to analyse more than 17,000 actions and investigate the breach after closed AI tools were unable to support the required forensic analysis.
The alliance said the incident demonstrated the importance of allowing organisations to run advanced AI models within their own infrastructure, enabling faster incident response, greater transparency and stronger data protection during cybersecurity investigations.
The Open Secure AI Alliance also acknowledged concerns that open AI models could be modified or misused for cyberattacks. However, it argued that such risks are not unique to open systems and should instead be addressed through robust safeguards, rigorous evaluation, responsible governance and rapid vulnerability remediation.
Founding members of the alliance include major technology and cybersecurity companies such as NVIDIA, Microsoft, IBM, Cisco, Adobe, Cloudflare, CrowdStrike, Red Hat, SAP, Salesforce, ServiceNow, Palantir Technologies, Synopsys, Cadence Design Systems, Dell Technologies, Hewlett Packard Enterprise, Snowflake and Linux Foundation, among others.
The alliance said its long-term mission is to ensure that governments, enterprises and critical infrastructure operators have access to trusted, open and frontier AI tools that can strengthen cyber resilience while supporting transparency, interoperability and sovereign control over security operations.


