The Open Secure AI Alliance Expands at Black Hat with SAFE Guidelines and Open Frameworks

The Open Secure AI Alliance (OSAA) announced significant news during the Black Hat USA conference, presenting the SAFE guidelines and open frameworks that offer IT leaders inspectable tools, lower token costs, and a clear roadmap for secure enterprise AI. This initiative represents a significant step towards creating open, inspectable, and enterprise-ready AI defenses, at a time when IT teams are looking to transform pilot projects into operational value.

Why an Open AI Defense Stack is Important

Open source has long been the cornerstone of modern infrastructures, ranging from cloud and computing platforms to cybersecurity. OSAA applies the same model to AI security, committing to sharing open models, agents, tools, and data that defenders can study, extend, and run on their own infrastructure.

The core argument of OSAA is that if the next generation of cyberattacks will be powered by AI, then the next generation of cyber defense must be as well. This means defenders need systems that they can actually examine. A recent incident on Hugging Face highlighted this need: closed AI tools were locked down, preventing essential forensic analysis and forcing the team to rely on an open-weight GLM 5.2 model, run on their own infrastructure, to analyze over 17,000 actions and contain the intrusion.

Who is Part of the Alliance and Why It’s Different

OSAA brings together a broad group of players ranging from cloud to cybersecurity, from enterprise software to open-source foundations. For enterprises, this is important because it signals that the AI defense stack will not be a vertical product from a single vendor, but an ecosystem anchored to open standards and components.

Among the contributions from the founders, several highlight the depth of this stack:

  • HPE is contributing SPIFFE/SPIRE, advancing zero-trust identity standards that can cryptographically verify AI agents and services before they interact with enterprise resources.
  • Hugging Face introduced Safetensors, a safer model weight format that prevents remote code execution and increases transparency on how models are stored and loaded.
  • IBM and Red Hat with Lightwell extend security along the open-source supply chain with digitally signed patches, helping to close gaps in the software layer that AI systems rely on.
  • Microsoft with MDASH is a multi-model, agent-based scanning harness that uses specialized agents to discover, debate, and demonstrate the existence of exploitable bugs, rather than relying on a single opaque scanner.

These components form an emerging open defense stack for AI agents that covers identity, isolation, secure model formats, multi-model scanning, and secure development workflows. For IT leaders, this promises consistent controls in a multi-vendor environment, rather than point tools that don’t interoperate.

Nvidia, Cisco, and the Role of Agent Harnesses

Nvidia supports the alliance not only with models and weights but also with open research on agent harnesses through the Nvidia Labs Object-Oriented Agent (NOOA) framework. NOOA starts with a key observation for practitioners: model choice matters less than harness design in determining performance. The framework offers a series of capabilities that significantly improve AI model performance, reducing token costs and accelerating time to value for businesses. Cisco, a strategic partner of Nvidia, is contributing advanced technologies for networking and secure AI infrastructures. Solutions like Silicon One and SuperNICs are designed to optimize AI networking platforms, while Cisco Secure AI Factory, developed with Nvidia, ensures security from edge to core.

Black Hat News: SAFE and the Expansion of the Open Stack

During the Black Hat USA conference, OSAA announced the Request for Comments (RFC) on the Shared AI Findings Exchange (SAFE) guidelines. This framework aims to transform AI security incidents and near-incidents into enterprise-wide shared protection, allowing organizations to quickly learn from recurring control failures and publish evidence-based operational recommendations. Nvidia introduced Nvidia OpenShell, an open runtime that acts as an agent-level sandbox, enforcing explicit security and privacy boundaries so that autonomous tools cannot access systems or data outside their designated scope.

Together, these Black Hat announcements underscore the alliance's commitment to providing tools and frameworks that make AI more secure and accessible for enterprises.

The Impact of OSAA on the Enterprise Security Landscape

The emergence of the Open Secure AI Alliance represents a turning point for companies seeking to integrate artificial intelligence into their operational processes. Open-source and interoperable solutions have proven to scale faster than proprietary technologies, as highlighted by technological transitions over the past few decades. The alliance provides a robust ecosystem that enables organizations to adopt secure and customizable AI defenses, transforming pilot projects into valuable operational solutions.

The Importance of the Open Defensive Stack

Modern infrastructures rely on open-source software, and the cybersecurity sector has greatly benefited from it. OSAA extends this model to the realm of AI security, offering open models, tools, and data that security teams can study, extend, and implement on their own infrastructures. A recent incident on Hugging Face demonstrated that closed AI tools can hinder forensic investigations, forcing teams to rely on open models to contain intrusions. This episode underscores a crucial truth for CISOs and security leaders: without the ability to inspect and adapt AI defenses in real-time during an attack, organizations risk being completely blind.

Technological Innovations from Founding Members

The alliance brings together key players from various sectors, including cloud, cybersecurity, enterprise software, and open-source foundations. Contributions from founding members highlight the depth of the defensive stack that OSAA is building:
  • IBM and Red Hat are extending security along the open-source supply chain with Lightwell, which provides digitally signed patches to close gaps in the software layer that AI systems rely on.
  • Microsoft has developed MDASH, a multi-model scanning harness that employs specialized agents to discover, debate, and demonstrate the existence of exploitable vulnerabilities, overcoming the limitations of traditional scanners.
  • The Integration of Nvidia and Cisco

    Nvidia is supporting the alliance not only with models and weights but also with open research on agent harnesses through the Nvidia Labs Object-Oriented Agent (NOOA) framework. This framework offers a series of capabilities that significantly improve AI model performance, reducing token costs and accelerating time to value for businesses. Cisco, a strategic partner of Nvidia, is contributing advanced technologies for networking and secure AI infrastructures. Solutions like Silicon One and SuperNICs are designed to optimize AI networking platforms, while Cisco Secure AI Factory, developed with Nvidia, ensures security from edge to core.

    Black Hat News: SAFE and the Expansion of the Open Stack

    During the Black Hat USA conference, OSAA announced the Request for Comments (RFC) on the Shared AI Findings Exchange (SAFE) guidelines. This framework aims to transform AI security incidents and near-incidents into enterprise-wide shared protection, allowing organizations to quickly learn from recurring control failures and publish evidence-based operational recommendations. Nvidia introduced Nvidia OpenShell, an open runtime that acts as an agent-level sandbox, enforcing explicit security and privacy boundaries to prevent unauthorized access to systems or data. Together, these innovations underscore OSAA's commitment to making AI more secure and accessible for enterprises.

    Editorial Note and Disclaimer

    The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

    GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.

    The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

    In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decisions.