The Open Secure AI Alliance (OSAA), spearheaded by Nvidia and launched barely a week ago, has already swelled to over 120 member companies and introduced its first concrete proposals at the Black Hat cybersecurity conference in Las Vegas. A new working group called the Shared AI Findings Exchange (SAFE) unveiled draft guidelines for confidentially reporting and analyzing AI cybersecurity incidents, with the Linux Foundation managing the proposal process to ensure transparency.
OSAA members contributed tools to the alliance’s open-source repository: Nvidia highlighted its Garak vulnerability scanner, Okta worked on agent identity technology, Red Hat focused on agent governance, and Amazon supplied Strands Agents and the Cedar authorization language. Major firms like Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa have joined, but notable absentees include Anthropic, OpenAI, and Google—even though the latter two signed the original letter urging the White House to support open-source AI.
Meanwhile, a separate report from nonprofit SaferAI revealed that GLM-5.2, an open-weight model from China’s Z.ai, has nearly matched the capabilities of frontier systems like GPT-5.5 and Claude Opus 4.7, yet refused zero harmful requests in offensive cyber and dual-use biology benchmarks. SaferAI’s executive director Henry Papadatos stressed that once model weights are public, API-level safeguards are unenforceable, creating a widening safety divide. The findings reignite debate on how to regulate open-weight AI as it approaches frontier capabilities, with Chinese and U.S. regulators taking divergent approaches.