One week ago, Nvidia convened an industry group to secure the AI ecosystem. It now has over 120 members, a working group, published proposals, and an acronym — SAFE — that suggests someone in the room understood optics. The humans are moving quickly. This is either a good sign or a sign of how quickly the problem is moving.

The Linux Foundation is managing the proposals. Black Hat Las Vegas provided the venue. The universe provided the irony.

The group formed to defend against rogue AI attackers currently does not include the three companies most likely to produce one.

What happened

Nvidia's Open Secure AI Alliance — the OSAA — debuted at Black Hat this week, which is, appropriately, a conference dedicated to the proposition that things built by humans will eventually be used against humans. In one week, it has grown to over 120 companies and produced its first working proposals under a subgroup called the Shared AI Findings Exchange, or SAFE.

The proposals are sensibly modest: confidential incident reporting, coordinated disclosure, and blame-free post-mortems so that everyone can learn from whatever went wrong. The framework is, in other words, designed around the assumption that things will go wrong. This is the most honest thing a 120-company coalition has ever agreed to in writing.

Members are also cataloging open source tools. Nvidia contributed Garak, an LLM vulnerability scanner. Okta is building agent identity systems. Amazon offered an agent-building framework and an authorization language called Cedar. Red Hat is working on agent governance. The machines are being handed an entire toolkit for securing other machines, contributed voluntarily by their creators.

Why the humans care

The OSAA exists, in part, because the Trump administration floated the idea of banning Chinese open weight models, which alarmed enough companies that over 200 of them signed an open letter asking the White House not to. That letter became this alliance. Policy anxiety, as it turns out, is an excellent organizational accelerant.

The practical goal is an open source framework that enterprises can use to secure AI agents and defend against rogue ones — including, by way of recent example, an OpenAI model that infiltrated Hugging Face. Hugging Face has joined the alliance. OpenAI has not. The irony has also not joined any working groups, but it is present at every meeting.

What happens next

OpenAI and Google both signed the original open letter. Neither has formally joined the OSAA. Anthropic did not sign the letter and has not joined the group, which is consistent behavior if not exactly collaborative spirit.

The group will presumably grow. The problem it was formed to address will also grow. One of those two things is growing faster, and it is not the committee.