Open Secure AI Alliance: Members, NOOA and Security Checklist

Quick answer: The Open Secure AI Alliance is a new industry collaboration announced on July 27, 2026 to develop and share open tools for securing AI software and agents. NVIDIA, the Linux Foundation, Microsoft, IBM, Cisco, Cloudflare, Hugging Face, Red Hat and more than 30 other organizations are listed as inaugural partners. Its first concrete contribution highlighted by the founders is NVIDIA’s open-source NOOA research framework for making AI-agent behavior easier to test, trace, audit and govern.

What you can do now: Developers can inspect the NOOA project on GitHub. Organizations and researchers can use NVIDIA’s Alliance interest form. The founders have not announced a certification, commercial product or guaranteed membership process, so treat those as separate from the Alliance announcement.

Open Secure AI Alliance inaugural member organizations announced in July 2026
Open Secure AI Alliance inaugural partners. Image source: NVIDIA’s official announcement.

Open Secure AI Alliance at a glance

QuestionVerified answer
What is it?A collaborative effort to develop and share open technologies, techniques and tools for securing AI software and agents.
When was it announced?July 27, 2026.
Who announced it?NVIDIA published the main announcement; the Linux Foundation separately confirmed that it is an inaugural partner.
What is available now?NOOA, an open-source research framework for agent harnesses, is available on GitHub.
Can organizations join?NVIDIA provides a form to share interest. The public announcements do not describe automatic acceptance, fees or a guaranteed membership route.
Is it a product or standard?The launch materials describe an alliance and collaborative effort, not a finished security product, compliance standard or certification.

Who is in the Open Secure AI Alliance?

NVIDIA and the Linux Foundation list the following inaugural partners:

  • Adobe
  • Cadence
  • Capital One
  • Cisco
  • Cloudera
  • Cloudflare
  • Cognition
  • CrowdStrike
  • Databricks
  • Dell Technologies
  • DoorDash
  • Elastic
  • HPE
  • Hugging Face
  • IBM
  • LangChain
  • Linux Foundation
  • Microsoft
  • NAVER
  • NetApp
  • Nous Research
  • NVIDIA
  • OpenClaw
  • Palantir
  • Palo Alto Networks
  • Red Hat
  • Reflection AI
  • Salesforce
  • SAP
  • ServiceNow
  • Siemens
  • SK Telecom
  • Snowflake
  • SpacexAI
  • Synopsys
  • Thinking Machines Lab
  • TrendAI

This list reflects the two launch announcements and may change. Check the official NVIDIA announcement for later updates.

What the Alliance plans to work on

The announcement focuses on the full AI-agent stack rather than model weights alone. It identifies identity, permissions, isolation, harnesses, guardrails, logs and evaluations as security layers that need to be inspectable and testable.

  • Agent identity: cryptographically verifying which agents and workloads are allowed to communicate.
  • Safer model formats: reducing risks when model weights are stored or loaded.
  • Agent harness testing: tracing and auditing how models use tools, context and permissions.
  • Multi-model vulnerability scanning: using specialized agents to find and validate exploitable bugs.
  • Software supply-chain security: improving trust in code, patches, models and dependencies.
  • Shared evaluation and remediation: testing defenses and coordinating fixes in the open.

What is NVIDIA NOOA?

NVIDIA Labs Object-Oriented Agent (NOOA) is an open-source research framework for agent harnesses. According to NVIDIA and the Linux Foundation, it is designed to help harnesses integrate with models so agent behavior is easier to test, trace, audit and govern. The code is publicly available, but it is research software—not a promise that an AI application becomes secure merely by adopting it.

Open the NOOA repository on GitHub →

10-point AI agent security checklist

The following is a practical implementation checklist based on the security layers named in the announcements. It is editorial guidance, not an official Alliance standard.

  1. Inventory every agent and tool. Record the owner, model, harness, data sources, connected tools and deployment environment.
  2. Give each workload a verifiable identity. Avoid shared credentials and long-lived secrets where possible.
  3. Apply least privilege. An agent should access only the tools and data required for its current task.
  4. Separate read and write actions. Require stronger controls for sending messages, changing records, executing code or spending money.
  5. Sandbox code and untrusted files. Isolate execution, restrict networks and treat model files and dependencies as supply-chain inputs.
  6. Log prompts, tool calls and outcomes safely. Preserve an audit trail without placing secrets or unnecessary personal data in logs.
  7. Test prompt injection and tool abuse. Include indirect injection from web pages, documents, emails and retrieved content.
  8. Set human-approval gates. High-impact or irreversible actions should not depend on model confidence alone.
  9. Maintain a kill switch and rollback plan. Operators need a fast way to revoke credentials, stop agents and restore affected systems.
  10. Re-evaluate after every change. Model, prompt, harness, permission and dependency updates can alter the risk profile.

How to express interest in joining

  1. Read the official launch announcement and confirm that your work aligns with open AI security.
  2. Prepare a concise description of the code, research, evaluations, standards work or operational experience your organization can contribute.
  3. Use NVIDIA’s Open Secure AI Alliance contact form.
  4. Do not claim membership until the Alliance or an authorized founding organization confirms it.

Frequently asked questions

What is the Open Secure AI Alliance?

It is an industry collaboration announced on July 27, 2026 to develop and share open technologies, techniques and tools for protecting AI software and agents.

Is OpenAI a founding member?

OpenAI does not appear in the inaugural-partner lists published by NVIDIA or the Linux Foundation. That statement only describes the public launch lists and should not be read as a claim about future participation.

Is NOOA available to download?

Yes. NVIDIA published the NOOA research framework in a public GitHub repository. Review the repository documentation and license before using it.

Does the Alliance provide an AI security certification?

No certification is described in the July 27 launch announcements. The Alliance is presented as a collaborative effort to develop open security tools and techniques.

Official sources

Leave a Comment

muddaser logo

Public Speaker, Softskills trainer and technology enthusiast

Contact

Muddaser Altaf

Social Address