37 companies just agreed to build an open defense stack for autonomous AI agents.
On July 27, 2026 NVIDIA and 36 partners including Microsoft, IBM, Hugging Face, Red Hat and the Linux Foundation launched the Open Secure AI Alliance. The coalition will share open models, weights, data and tools aimed at securing agentic systems. NVIDIA also published its agent harness research as open source, under the names NOOA and Labs Object-Oriented Agents (NLOOA), to help developers test, trace, audit and govern autonomous agent behaviour.
What the alliance actually does is practical and specific. It targets identity and isolation for agents, safe model formats, multi-model scanning, and secure coding workflows. Members are contributing existing pieces: Microsoft’s MDASH for multi-agent vulnerability discovery, Hugging Face’s Safetensors format for model weights, IBM and Red Hat’s Lightwell for digitally signed patches, and HPE’s SPIFFE/SPIRE for agent identity verification. NVIDIA brings open models and an agent harness that lets teams run and observe agents under controlled conditions.
This is a pivot from research prizes and best-practice papers to operational tooling you can install and audit. That matters because the trigger for the alliance was a real-world autonomous agent attack that compromised software on a public platform. When the threat comes from agents that can act without constant human oversight, defensive measures must move into the software supply chain and developer toolchains themselves. Open-source tooling accelerates that process by letting security teams reproduce, share fixes, and automate scanning across different stacks.
Open sourcing these components changes incentives. Vendors can adopt common formats and verification methods, lowering integration cost. Security researchers gain shared artifacts to test against. Regulators and procurement teams gain concrete artefacts to measure compliance. At the same time, publishing tools publicly means attackers can study them too. The effectiveness of the alliance will depend on how quickly contributors turn research prototypes into well-documented, maintained releases and on how widely companies adopt those releases.
So why should a non-specialist care? If the alliance succeeds, software that integrates autonomous agents will become measurably safer and easier to audit. That reduces operational risk when AI systems take actions on behalf of businesses.
If this initiative produces durable, well-maintained components, the Open Secure AI Alliance could establish the default plumbing for safe agent deployment. If it stalls, defenders will continue building ad hoc patches while attackers probe the weak spots.
