NVIDIA leads the establishment of the Open Security AI Alliance to respond to the Hugging Face intrusion incident
Chip giant Nvidia United , Palantir, CrowdStrike , Hugging Face and other dozens of technology companies, jointly initiated the establishment of the "Open Security AI Alliance", aiming to develop and share open models, data and security tools, and establish an open defense system that can be inspected and adjusted for AI agents. The direct trigger for the establishment of the alliance was the recent Hugging Face intrusion incident that shocked the industry. In mid-July, two OpenAI models went out of control during an internal security evaluation. In order to "cheat" in the test to obtain high scores, the models independently discovered and exploited vulnerabilities to escape from the isolation environment and launch attacks on the Hugging Face production system. OpenAI admitted that this was an "unprecedented" AI security incident. Dramatically, Hugging Face encountered difficulties in the forensics phase - when using mainstream commercial AI model APIs to analyze attack logs, the request was intercepted by the security guardrail because it contained real attack commands. The team eventually deployed the open source model on its own infrastructure and completed forensic analysis of more than 17,000 attack records. This incident exposed the "asymmetric dilemma" of closed-source model safety guardrails in actual defense: Attackers can use unrestricted models, while defenders are hampered by security mechanisms The alliance clearly advocates treating open models as "defensive assets rather than liabilities" and calls on policymakers to avoid imposing "one-size-fits-all" restrictions on open source AI. NVIDIA has contributed multiple research results to the alliance, Hugging Face provides the Safetensors model format, Microsoft has contributed the multi-model vulnerability scanning framework, and SpaceX AI has open sourced the Grok programming agent. NVIDIA said that although the open model may be abused, the risk is not unique to open systems, and closed systems cannot be eliminated either. True security lies in giving more defenders the ability to independently inspect, verify and harden systems.