Security Leaders Weigh in on Open Secure AI Alliance
.webp?t=1785249752)
Recently, a number of organizations announced the establishment of an open secure AI alliance. The alliance is designed to ensure access to necessary cybersecurity defenses as AI continues to evolve. This comes after the Open AI incident, where AI models independently accessed Hugging Face data. The alliance's goal is to "develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI."
Inaugural organizations include: NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab and TrendAI.
Security leaders share thoughts on the alliance below:
Chuck Sobey, General Chair and Co-founder, Chiplet Summit
“As the Open Secure AI Alliance focuses on securing the AI ecosystem, one area that deserves greater attention is the security of the underlying hardware powering AI infrastructure. Software security assumes you can trust the silicon it runs on. The coming wave of chiplet-based systems, especially AI accelerators, raises the stakes: more suppliers, more integration points, more attack surfaces. Hardware security has to be part of this conversation from the beginning.”
Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs
"Organizations built identity and access management for people running predictable software. AI agents are neither, and they skip the entire stack. Most security teams can't tell you how many agents are running in their environment right now, or what those agents can access. Developers launch them, ops teams wire them into workflows, and SaaS vendors embed them in products without security ever seeing a ticket. Each agent holds credentials to production systems and behaves non-deterministically, meaning the same agent running the same task can take a different path every time.
The Open Secure AI Alliance is right that defenders need open, inspectable models they can run on their own infrastructure. HPE's SPIFFE/SPIRE contribution to the alliance addresses agent identity directly, giving agents cryptographically verifiable identities. Security leaders should be watching that work. Identity for agents is what makes the rest of the defensive stack enforceable."
Seemant Sehgal, BreachLock
"The gap in most AI deployments right now is not in the model itself. Organizations are running AI agents with access to internal data, external APIs, and automated decision-making workflows, and they have not mapped what those agents can reach or how an adversary would move through that access. Alliance frameworks that standardize how AI systems are evaluated for risk are useful, but the organizations that will benefit from them are the ones that already know what their agents are doing at runtime. Most do not. The strategic question for security leadership is whether their visibility into AI behavior is anywhere close to their confidence in AI capability, and for most enterprises, those two things are not in the same conversation yet."
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







