An industry coalition spearheaded by Nvidia has grown to more than 120 member companies in its first week and has already launched a new working group focused on AI security incident response, just days after the alliance was formed.

The Open Secure AI Alliance, or OSAA, is designed to build and share open tools that promote responsible and trustworthy use of AI. Its newest initiative, called the Shared AI Findings Exchange, or SAFE, is focused on developing guidelines for AI security, including confidential incident reporting, alerting affected parties when something goes wrong, and conducting blame-free analysis after AI security incidents occur.
The SAFE proposals were developed as OSAA members gathered at the Black Hat cybersecurity conference in Las Vegas, one of the industry’s most closely watched annual security gatherings. The rapid formation of a dedicated working group within days of the alliance’s launch reflects the pace at which Nvidia and its partners are trying to move on AI security standards.
As part of its work, OSAA is cataloging open source security tools contributed by member companies. That includes Nvidia’s own large language model vulnerability scanner, called Garak, along with agent identity tooling contributed by Okta, agent governance work from Red Hat, and open source contributions from Amazon, including its Strands Agents framework and its Cedar authorization language.
The alliance’s rapid growth, from its founding to more than 120 members and a functioning working group within a single week, underscores how urgently large technology companies are treating the challenge of securing AI agents and systems as they become more deeply embedded in enterprise software and infrastructure. With AI agents increasingly granted access to sensitive systems and data, the industry has faced growing pressure to establish shared norms around incident disclosure and response, rather than leaving each company to handle security failures independently. OSAA’s early moves suggest Nvidia is positioning itself as a central coordinator for that effort, leveraging its dominant position in AI hardware to also shape the security practices that govern how AI systems are deployed and monitored across the industry.



