As AI Agents Spread, an Industry Alliance Forms to Secure Them
The NVIDIA-led Open Secure AI Alliance has drawn more than 120 companies to build shared defenses for AI systems. What enterprise tech leaders should know.
As enterprises rush to deploy AI agents that can act on their behalf, a new question is moving to the center of the technology agenda: how do you secure software that thinks and acts on its own? In mid-2026, a large slice of the industry decided to answer that question together.
An alliance forms fast
The Open Secure AI Alliance, an industry group spearheaded by NVIDIA, formed and grew to more than 120 member companies within weeks. Its roster reads like a cross-section of the corporate technology world, including Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, Okta, Red Hat, Amazon, and Hugging Face. Notably absent from the founding membership are the frontier AI labs Anthropic, OpenAI, and Google, though OpenAI and Google both signed the original open letter that led to the group’s creation.
What it is actually building
The alliance moved quickly from mission statement to working product. A group called the Shared AI Findings Exchange, or SAFE, has already put proposals out for public comment, with the Linux Foundation managing the process, and members gathered to advance the work at the Black Hat security conference in Las Vegas. The early proposals are practical rather than dramatic: how to confidentially report an AI cybersecurity incident, how to alert the parties affected, and how to conduct a blame-free analysis afterward so the whole industry can learn from it.
Members are also contributing open-source tools. NVIDIA has pointed to its open LLM vulnerability scanner, Okta is working on identity for AI agents, Red Hat on agent governance, and Amazon has contributed an agent-building tool and an authorization language. The through-line is a recognition that AI agents create new attack surfaces, from rogue agents to the question of how one system proves its identity to another.
Why enterprise leaders should care
The pattern here is familiar to anyone who watched cybersecurity mature. Shared standards, confidential incident reporting, and blameless post-incident reviews are the same mechanisms that made traditional security more resilient over the past two decades, now being adapted for AI. For organizations deploying agents, the practical takeaway is that AI security is becoming a discipline with its own emerging playbook, and it maps closely onto the incident-response practices covered in our guide to a cybersecurity incident response plan. It also runs alongside the physical AI infrastructure buildout, since the systems filling those new data centers are exactly what the alliance aims to protect.
More coverage is in our Technology and Innovation section.
Frequently asked questions
What is the Open Secure AI Alliance?
It is an industry group spearheaded by NVIDIA and formed in 2026 to develop shared security practices for AI systems. It grew to more than 120 member companies within weeks of launching.
What is the Shared AI Findings Exchange?
Known as SAFE, it is a working group within the alliance, with proposals managed by the Linux Foundation, focused on how companies can confidentially report AI security incidents, alert affected parties, and run blame-free analyses.
Which companies are involved?
Members include Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, Okta, Red Hat, Amazon, and Hugging Face, among others. Anthropic, OpenAI, and Google were not among the founding members, though OpenAI and Google signed the original open letter behind the effort.