The Linux Foundation celebrates collaborative efforts to build and enhance the open tools and techniques that keep AI systems safe and secure.
TL;DR: The Linux Foundation is joining NVIDIA and other founding members of the Open Secure AI Alliance to encourage open tools for securing AI systems. NVIDIA is providing for general use NOOA, an open source framework that makes AI agents easier to test, trace, audit, and govern. The Alliance aims to make open models, weights, and agent harnesses safer to build and deploy—while giving defenders greater visibility and control.
Open source software is a foundation of the modern economy. Over the last three decades, it has become critical for cloud computing, financial services, manufacturing, telecommunications, government services, and the Internet itself. By recent estimates, between 76 and 99 percent of commercial software codebases contain open source components. Open source earned that role not by being zero-cost, but by being observable. Anyone can inspect it, adapt it, improve it, find and fix flaws in it, and depend on it with confidence. Anyone can also sell new innovative solutions using that same open source.
Accelerated global AI innovation that benefits all does not come solely from any single frontier model controlled by a single vendor, or even a small collection of closed models controlled by a handful of companies. Rather, global AI innovation will be measured by whether the technology diffuses safely into every sector of the economy, and by whether the users, businesses, and communities that depend on it can understand and secure what they are running. Open models and open weights are central to that outcome, which is ultimately based on trust.
Last week, the Linux Foundation joined Cisco, Dell Technologies, IBM, Meta, Microsoft, NVIDIA and other industry signatories in an open letter which makes the case that open weight models are an essential part of the foundation for secure, universally accessible and innovative AI . The letter argues that the right response to the real risks of open weights is a stronger open ecosystem rather than prohibition, and that policymakers should encourage rather than restrict frontier open models. .
Open weight models are models that anyone can download, inspect, modify, and run on their own infrastructure. They matter for three reasons:
Open weights carry real and distinct risks. Once released, weights are beyond any single developer’s control, and modified versions can be difficult to trace. But the right response to that risk is not to close the ecosystem. In a world where attackers use advanced AI, defenders need access to models with equivalent capability so they can detect, simulate, understand, and respond to emerging threats.
This is where the Linux Foundation’s long experience in open source security is most relevant. Transparency has repeatedly proven more secure than obscurity.
Closed systems can be breached, misused, or fail in ways outsiders cannot detect and insiders may not address single-handedly, and concentrating capability behind a small number of closed models creates single points of failure. Open models let a broad community examine behavior, identify vulnerabilities, develop safeguards, and improve systems over time. That same open process supports rigorous benchmarking and evaluation, red teaming, and the development of shared standards and interoperability that strengthen the systems we all depend on.
It is also worth being precise about what needs to be secured. An AI agent is not just an interface for a model. Increasingly, It is a system built from models, the harnesses that let an agent observe context and take action, and the guardrails that constrain what it can do. Much of the attention in AI safety has focused on the model, but the harness is the scaffolding that determines how an agent behaves in practice. In recent evaluations, systems made of multiple smaller size models have often outperformed larger frontier models due to the innovation in the way they were wired together with a harness. Making that scaffolding open, testable, and auditable—just like the tooling used to train models, build AI systems, and enable them to interoperate—is essential to trustworthy AI.
For these reasons, the Linux Foundation today announced it is an inaugural partner in the Open Secure AI Alliance, alongside NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab and TrendAI. The Alliance is a collaborative effort to develop new techniques and tools that safeguard AI software by rapidly identifying and remediating vulnerabilities as the technology evolves.
Consistent with how open communities make progress, the Linux Foundation applauds organizations like NVIDIA who are contributing working code, and not just thoughts about the need for safety. NVIDIA is opening up valuable research to the world, including the open source NVIDIA Labs Object-Oriented Agent (NOOA) project, now available on GitHub. NOOA is a research framework that helps agent harnesses integrate with models in ways that make agent behavior easier to test, trace, audit, and govern. NVIDIA is also a major contributor to PyTorch, the open source tool used to train both open and closed models, hosted by the PyTorch Foundation.
This work is a natural extension of the security collaborations the Linux Foundation hosts across its communities. The Open Source Security Foundation (OpenSSF) builds security tools, establishes best practices, and educates developers to improve open source security and foster secure software development processes.The practices that made open source software more secure, such as shared tooling, open standards, transparent review, coordinated vulnerability handling, and a broad community of defenders, are the practices AI now needs. The Linux Foundation’s role in this effort is the one it plays across open source: a neutral home where organizations that also compete can collaborate on the shared infrastructure everyone depends on.
“Open source became the backbone of modern computing because it let everyone see, improve, and secure the technology they rely on. The Open Source Software Foundation is a great example of this dynamic, building standards and tools for the benefit of all. AI deserves the same foundation. Initiatives like NVIDIA’s Open Secure AI Alliance brings the open source community’s security practices to AI, and the Linux Foundation is glad to support open collaboration on these practices.”
— Jim Zemlin, CEO, the Linux Foundation
A note for policymakers
As policymakers and regulators work through questions of AI safety, the distinction that matters is not open versus closed, but transparent and secure versus opaque and unexamined. Open models and open tooling should be recognized as defensive assets that enable transparency, independent evaluation, and shared remediation, rather than treated as a security liability. A recent incident disclosure by Hugging Face highlights this explicitly: faced with an imminent cyberattack, the defenders were not able to respond and address it by using closed models. They were able to analyze the attack and remediate the issue only because of their access to open models.
Openness alone does not guarantee trust. AI still requires rigorous testing, strong safeguards, secure infrastructure, clear governance, and human oversight. But an open ecosystem broadens the community of defenders who can do that work, and it keeps critical capability from being locked inside a small number of systems. By recognizing the importance of openness and transparency, policymakers can encourage good actors to participate in open technical collaboration.
Policymakers should also take care not to conflate legitimate model-development techniques, such as distillation with misappropriation, and should address specific, demonstrated harms with targeted measures rather than sweeping restrictions on open methods.