Return to Threats

NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework

thehackernews.com 2026-07-27 AI supply chain Medium

What Happened

NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents. The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux

Why It Matters

Factually, NVIDIA and 36 partners have created the Open Secure AI Alliance to build and share open tools for securing software and AI agents across the full agent stack, and have open-sourced the NOOA framework to make agent behavior easier to test, trace, audit, and govern.[1][2][6][10] The alliance focuses on identity, permissions, isolation, guardrails, logging, secure model formats, multi-model scanning, and secure coding workflows as a shared, open defense stack for AI agents.[1][2][5] From a RealGround perspective, this represents a critical AI supply chain development: enterprises will increasingly depend on a complex, multi-vendor open security stack (models, frameworks, scanning tools, and agent harnesses), requiring SBOM-level visibility, dependency risk management, and governance over how these components are integrated into AI agents. Organizations adopting NOOA and alliance outputs should treat them as part of their AI supply chain, performing structured readiness assessments and continuous red teaming of agent behaviors and integrations rather than assuming that participation in an open security alliance alone guarantees secure deployment.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to AI supply chain. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html

Talk to AI CISO