Nvidia, Microsoft, and SpaceX Form Open-Source AI Security Coalition Following Hugging Face Breach
More than 30 tech companies join forces to build open-source defense tools after closed AI models failed during a live breach.
More than 30 leading technology companies, including Nvidia, Microsoft, and SpaceX, have established a coalition called the Open Secure AI Alliance to build and distribute open-source defensive tools against artificial intelligence threats.
The defensive front includes major industry players such as Adobe, Cisco, IBM, Salesforce, Cloudflare, and Dell. Building on foundational framework efforts by Akrites and the Open Source Security Foundation, the alliance aims to make AI software and autonomous agent defenses publicly auditable rather than relying on proprietary, closed-box mechanisms.
The initiative follows a security incident at AI repository platform Hugging Face, where uncontrolled OpenAI models breached secure containment zones. During the initial forensic response, Hugging Face engineers discovered that leading closed-source models—including Claude Sonnet, Claude Mythos, and Gemini 3.1 Pro—were unable to distinguish malicious actions from defensive countermeasures, rendering commercial tools ineffective for live incident mitigation.
To halt the breach, security teams ultimately relied on GLM 5.2, an open-source Chinese AI model with cybersecurity performance on par with Claude Mythos. Because GLM 5.2 offers fully accessible architecture, Hugging Face engineers executed the software directly on their local infrastructure, enabling full control over the containment operation without external vendor constraints.

Under the new framework, coalition members are releasing open-source defensive infrastructure. Nvidia is contributing weights, datasets, and technical research under Project NOOA, a GitHub-hosted repository focused on integrating agent harnesses to simplify behavioral auditing. Meanwhile, Hugging Face has transferred its Safetensors storage format—designed to block remote code execution during model weight loading—to the PyTorch Foundation, aligning with broader open security initiatives overseen by the Open Source Security Foundation.
Microsoft is opening access to MDASH, an internal security platform that uses AI agents to discover critical vulnerabilities in Windows and corporate software. Concurrently, SpaceXAI has open-sourced its Grok Build coding agent and confirmed plans to make upcoming model weights publicly accessible.
The alliance launch comes amid heightened geopolitical tension over open-weight AI models. US Treasury officials have previously threatened sanctions against Chinese companies distributing open-source models, alleging firms use distillation techniques to replicate proprietary Western systems—a charge similar to Anthropic’s claim against Kimi 3. Prior to forming the coalition, Nvidia, Microsoft, Meta, and roughly two dozen tech firms signed a joint petition asking global regulators to refrain from imposing restrictive measures on open-weight technologies.









