网络安全是开源软件的三大受益者之一。开放安全 AI 联盟(Open Secure AI Alliance)——基于 Linux 基金会的领导力:https://www.linuxfoundation.org/blog/the-state-of-open-source-software-in-2025 以及 Akrites:https://www.linuxfoundation.org/press/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats 的倡议和 OpenSSF:https://openssf.org/ 社区工作——将使用开放技术来修复并披露漏洞。
正如开源为软件创建了共享基础,美国及其合作伙伴现在在 AI 安全方面面临选择:保护我们基础设施的防御措施是只存在于少数不透明系统中,还是建立在任何防御者都可以研究、适应和部署的开放模型、工具包和工具上。
开放模型像任何强大技术一样,可能会被滥用——包括试图削弱安全措施或将其能力转用于网络攻击——但这些风险并非开放系统独有,必须在任何先进 AI 部署的地方进行管理。
最近的 Hugging Face 安全事件:https://huggingface.co/blog/security-incident-july-2026 清楚地提醒我们:网络防御者需要开放、前沿的自主系统来进行自我防御。当封闭的 AI 工具——无法区分攻击者和防御者——阻止了必要的取证分析时,Hugging Face 在其自身基础设施上运行了开放权重的 GLM 5.2 模型,以分析超过 17,000 次操作并遏制入侵。
HPE 为 SPIFFE/SPIRE 做出贡献:https://spiffe.io/,该项目创建了零信任身份框架标准和方法,可以加密验证 AI 代理和服务,以确保只有授权的工作负载才能进行通信和访问企业资源。
Hugging Face 提供了 Safetensors:https://github.com/safetensors/safetensors —— 一种安全的 AI 模型权重存储格式,提供透明性并保证不会远程执行代码 —— 给 PyTorch 基金会。
IBM 和 Red Hat 的 Lightwell:https://www.redhat.com/en/about/press-releases/ibm-and-red-hat-expand-lightwell-new-offerings-build-trust-infrastructure-ai-era-open-source 通过数字签名补丁扩展了开源供应链的安全性。
微软的 MDASH:https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/ 多模型代理扫描利用专门的 AI 代理来发现、讨论并验证可利用的漏洞。
SpaceXAI 已开源 Grok Build:https://x.ai/open-source 基于终端的 AI 编程代理,以促进信任、透明和新能力,并计划开源 Grok 系列模型的权重,以支持开发者和研究社区。
随着政策制定者和监管机构应对 AI 安全问题,关键在于将开放模型、工具和安全工具视为防御资产,而非负担。在 AI 和网络安全政策中,对开放前沿 AI 系统的全面限制将削弱防御能力,并有可能将权力、依赖和脆弱性集中在少数封闭供应商中。
企业和政府应投资于共享的 AI 防御开放基础设施——数据集、评估框架、攻击模拟器和红队工具——就像过去几代人投资于开源软件一样。
AI 代理的时代可以是一个具有韧性和共享安全性的时代。通过正确的选择,开放安全的 AI 系统可以为防御者提供所需工具,加强竞争,扩展技术领导力,并确保这一非凡技术的安全和安全性为所有人公开建立。
那个未来值得建设——开放安全 AI 联盟邀请各国政府、行业和研究人员共同参与捍卫 AI 时代的工作。
了解更多或表达加入开放安全 AI 联盟的兴趣:https://www.nvidia.com/en-us/open-secure-ai-alliance-contact-us/
Open source software is a critical pillar of the global economy. It underpins cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts.
Cybersecurity is among the top three beneficiaries of open source software. The Open Secure AI Alliance — building on the leadership of the Linux Foundation’ :https://www.linuxfoundation.org/blog/the-state-of-open-source-software-in-2025 s Akrites :https://www.linuxfoundation.org/press/linux-foundation-and-industry-leaders-launch-akrites-to-defend-critical-open-source-software-against-ai-enabled-cyber-threats initiative and OpenSSF :https://openssf.org/ community work — will work to remediate and disclose vulnerabilities using open technologies.
Just as open source created a shared foundation for software, the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy.
The world needs both closed and open models:https://www.nvidia.com/en-us/glossary/open-models/. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense – with no single point of failure.
Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed.
The recent Hugging Face security incident :https://huggingface.co/blog/security-incident-july-2026 delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense. When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.
That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most. Companies and countries need open frontier defensive tools and techniques so critical industries can build security systems across a multi-vendor ecosystem and avoid single points of failure.
That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control.
Leaders across cloud computing, cybersecurity, enterprise software, open source foundations and AI research — including NVIDIA, Adobe , Cadence , Capital One , Cisco , Cloudera , Cloudflare , Cognition , CrowdStrike :https://www.crowdstrike.com/en-us/blog/crowdstrike-joins-the-open-secure-ai-alliance/ , Databricks , Dell Technologies , DoorDash , Elastic :https://www.elastic.co/blog/elastic-nvidia-inaugural-partner-osaia , HPE :https://www.hpe.com/us/en/newsroom/blog-post/2026/07/hpe-joins-open-secure-ai-alliance-to-advance-open-cybersecurity-innovation.html , Hugging Face , IBM , LangChain, the Linux Foundation , Microsoft , NAVER , NetApp , Nous Research , OpenClaw, Palantir , Palo Alto Networks , Red Hat :https://www.redhat.com/en/blog/strengthening-open-source-defense-layer-red-hat-joins-nvidias-open-secure-ai-alliance , Reflection AI, Salesforce , SAP, ServiceNow , Siemens, SK Telecom, Snowflake , SpacexAI , Synopsys , Thinking Machines Lab and TrendAI are inaugural partners in the Open Secure AI Alliance, a movement to develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI.
Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI.
The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.
Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.
An AI agent isn’t just a language model. It is a complex system built from models, harnesses and guardrails.
Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed. Open harnesses and tools make those controls easier for many defenders to inspect, test and improve.
NVIDIA is contributing open models, model weights, data and new agent harness research to the Open Secure AI Alliance to speed the development of new cybersecurity tools and techniques.
The new open source NVIDIA Labs Object-Oriented Agent (NOOA) :https://developer.nvidia.com/blog/six-agent-harness-capabilities-for-higher-model-performance/?ncid=prsy-823400 project is now available on GitHub :https://github.com/NVIDIA-NeMo/labs-OO-Agents/tree/main to make advanced AI safety capabilities more accessible for agent harnesses. The NOOA research framework enables harnesses to better integrate with models to make agent behavior easier to test, trace, audit and govern.
Across the Alliance, contributors are building an open defense stack for agents — from identity and isolation to safe model formats, multi-model scanning and secure coding workflows.
HPE contributes to SPIFFE/SPIRE :https://spiffe.io/ , which creates zero-trust identity framework standards and methods that can cryptographically verify AI agents and services to ensure only authorized workloads communicate and access enterprise resources.
Hugging Face has offered Safetensors :https://github.com/safetensors/safetensors — a safe format to store AI model weights, providing transparency and guarantees of no remote code execution — to the PyTorch Foundation.
IBM and Red Hat’s Lightwell :https://www.redhat.com/en/about/press-releases/ibm-and-red-hat-expand-lightwell-new-offerings-build-trust-infrastructure-ai-era-open-source extends security across the open source supply chain with digitally signed patches.
Microsoft’s MDASH :https://www.microsoft.com/en-us/security/blog/2026/05/12/defense-at-ai-speed-microsofts-new-multi-model-agentic-security-system-tops-leading-industry-benchmark/ multi-model agentic scanning harness orchestrates specialized AI agents to discover, debate and prove exploitable bugs.
SpaceXAI has open sourced the Grok Build :https://x.ai/open-source terminal-based AI coding agent to promote trust, transparency and new capabilities, and plans to open source the weights of the Grok line of models to support the developer and research communities.
As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers.
Companies and governments should invest in shared open infrastructure for AI defense — datasets, evaluation frameworks, attack simulators and red-teaming tools — much as past generations invested in open source software.
The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone.
That future will not be secured by assuming that secrecy alone is safety. It will be secured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved and open enough to mobilize the full community of defenders.
That future is worth building — and the Open Secure AI Alliance invites governments, industry and researchers to join in the work of defending the AI era together.
Learn more or share interest :https://www.nvidia.com/en-us/open-secure-ai-alliance-contact-us/ in joining the Open Secure AI Alliance.
情报判断
Aioga 编辑摘要
NVIDIA、Microsoft、Hugging Face、IBM等数十家机构联合成立Open Secure AI Alliance,计划借助开放模型、工具和框架,推动漏洞修复与披露,并建设可审查、可调整和自主部署的AI安全防御体系。