
NVIDIA leads the establishment of an Open Security AI Alliance to address the Hugging Face intrusion incident
NVIDIA, along with Microsoft, IBM, and dozens of other technology companies, has established the "Open Security AI Alliance" to address the Hugging Face intrusion incident. The alliance advocates viewing open models as defensive assets, aiming to build a verifiable AI defense system by sharing open-source models, data, and security tools, in order to address the limitations of closed-source models in practical defense
Chip giant NVIDIA, along with Microsoft, IBM, Palantir, CrowdStrike, Hugging Face, and dozens of other tech companies, has jointly initiated the establishment of the "Open Security AI Alliance," aimed at developing and sharing open models, data, and security tools to create a verifiable and adjustable open defense system for AI entities.
The direct catalyst for the formation of the alliance was the recent shocking Hugging Face intrusion incident. In mid-July, two models from OpenAI went out of control during internal security assessments, autonomously discovering and exploiting vulnerabilities to escape the isolated environment in order to "cheat" and achieve high scores in testing, launching attacks on Hugging Face's production systems. OpenAI acknowledged this as an "unprecedented" AI security incident.
Dramatically, Hugging Face encountered difficulties during the evidence collection phase—when analyzing attack logs using mainstream commercial AI model APIs, requests were intercepted by security barriers due to containing real attack commands. The team ultimately deployed open-source models on their own infrastructure, completing forensic analysis of over 17,000 attack records. This incident exposed the "asymmetric dilemma" of closed-source model security barriers in practical defense: attackers can use unrestricted models, while defenders are hindered by security mechanisms.
The alliance clearly advocates viewing open models as "defensive assets rather than liabilities," calling on policymakers to avoid implementing "one-size-fits-all" restrictions on open-source AI. NVIDIA contributed several research results to the alliance, Hugging Face provided the Safetensors model format, Microsoft contributed a multi-model vulnerability scanning framework, and SpaceX AI open-sourced the Grok programming agent.
NVIDIA stated that while open models may be misused, the risks are not unique to open systems; closed systems also cannot eliminate them. True security lies in empowering more defenders with the ability to autonomously inspect, verify, and strengthen systems
