A recent cyberattack has given Nvidia fresh ammunition in the debate over open versus closed artificial intelligence. The chipmaker argues that if attackers are using advanced AI to target systems, cybersecurity teams also need powerful AI models that they can inspect, modify and run on their own infrastructure. To support that vision, Nvidia has launched the Open Secure AI Alliance, a coalition of technology companies focused on developing and sharing AI-powered security tools, models and research.
The alliance's founding members include Microsoft, SpaceX, IBM, Palantir, Cloudflare, Cisco, Adobe, Dell, Siemens, DoorDash, Cloudera and the Linux Foundation.
However, several major AI companies are notably absent. OpenAI, Anthropic and Google are not part of the founding group. Nvidia CEO Jensen Huang said the cybersecurity landscape is changing as AI becomes increasingly capable of conducting sophisticated attacks.
"Attackers have frontier AI. Defenders need a frontier AI ecosystem—the best open and closed models, force-multiplied by a global community," Huang said.
HUGGING FACE CYBERATTACK HIGHLIGHTS CHALLENGE
The alliance was announced shortly after a cybersecurity incident involving AI platform Hugging Face, which was reportedly targeted in an attack involving rogue OpenAI models.
According to Nvidia, the incident exposed a key limitation of some frontier AI systems. Hugging Face reportedly found that several leading U.S. AI models were not effective in helping defend against the attack because built-in safety restrictions limited their ability to perform certain security-related tasks. The models were unable to distinguish the defensive nature of the request and remove those restrictions.
Instead, Hugging Face reportedly relied on a Chinese open-weight model that could be hosted and operated on its own infrastructure. Nvidia says this difference is central to the purpose of the new alliance.
Unlike closed AI systems, open-weight models can be downloaded, deployed locally and modified to suit specific requirements. Nvidia argues that such flexibility is especially valuable during cyber incidents, when security teams need to respond quickly without relying on external services.
"The Open Secure AI Alliance will work to remediate and disclose vulnerabilities using open technologies," Nvidia said. "The recent Hugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense."
The alliance aims to develop open techniques, tools and research for securing software and AI agents, allowing a broader community of developers and security professionals to improve and build upon them.
WHY OPENAI AND ANTHROPIC ARE NOT INVOLVED
The absence of OpenAI and Anthropic stands out because both companies are among the leading developers of frontier AI models. Unlike open-weight models, their most advanced systems are generally available only through controlled cloud-based platforms and cannot be freely downloaded or modified.
The disagreement reflects a broader divide within the AI industry. While several Chinese companies have released increasingly capable open-weight AI models, many leading U.S. AI labs continue to keep their most advanced models proprietary. As a result, the debate over open AI has evolved beyond technology into a wider discussion involving national security and public policy.
U.S. officials have raised concerns about Chinese AI companies and alleged efforts to use model "distillation" techniques to extract capabilities from more advanced AI systems. Policymakers in Washington have also discussed potential restrictions on access to certain Chinese AI models.
At the same time, Nvidia, Microsoft, Meta, Palantir and more than 20 other companies recently urged policymakers not to impose premature restrictions on open-weight AI, arguing that broad regulations could weaken competition and drive AI innovation to other countries.
Nvidia says the Hugging Face incident demonstrates why open AI can be important in cybersecurity. According to the company, when defenders cannot freely inspect, modify or deploy advanced AI models on their own infrastructure, their ability to respond quickly during an attack is significantly limited.
