NVIDIA and 36 Partners Form Open Secure AI Alliance, Release NOOA Security Framework

A broad coalition of cloud, security, and AI vendors is pooling resources to build open tooling for securing AI agents and the software that runs them.

AI-generated illustration depicting ai security for the story: NVIDIA and 36 Partners Form Open Secure AI Alliance, Release NOOA Security Framework

Summary

  • NVIDIA has co-founded the Open Secure AI Alliance alongside 36 other organisations, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, and the Linux Foundation.
  • The alliance aims to develop and share open technologies, techniques, and tools specifically focused on securing AI agents and the software pipelines supporting them.
  • NVIDIA has open-sourced its NOOA framework as part of the initiative.
  • Membership spans cloud providers, enterprise software vendors, security specialists, and AI-focused companies, signalling broad industry acknowledgement that AI security requires coordinated effort.
  • No corroborating independent sources were available at time of publication; details beyond the announcement summary are not confirmed.

What has been announced

NVIDIA has joined with 36 other organisations to establish the Open Secure AI Alliance, a coalition dedicated to building and sharing open resources for securing AI agents and the software that underpins them. The founding membership is notable for its breadth: it includes major cloud and infrastructure players such as Microsoft and Red Hat, security vendors including Cisco, Cloudflare, CrowdStrike, and Palo Alto Networks, AI platform companies such as Hugging Face, enterprise technology firms including IBM, and open-source stewards such as the Linux Foundation.

The NOOA framework

Alongside the alliance’s formation, NVIDIA has open-sourced the NOOA framework, described as part of the group’s shared technical contribution. The source material does not provide granular detail about NOOA’s architecture, specific capabilities, or the threat models it addresses, so organisations should treat public documentation as the authoritative reference for technical evaluation.

Why this coalition has formed

The alliance’s stated purpose is to develop technologies, techniques, and tools for securing software and AI agents. The formation reflects a growing consensus among major vendors that AI security challenges — particularly those involving autonomous agents operating across complex software environments — are not problems any single organisation can resolve in isolation. Pooling expertise across cloud, security, and AI disciplines is the approach this group has chosen.

What remains unknown

The source material is limited to the announcement summary, and no corroborating sources were available at the time of writing. Key details — including governance structure, how contributions will be managed, the specific threat categories NOOA addresses, release cadence, and how organisations can formally participate — are not confirmed here. Security teams should monitor the alliance’s own communications for those specifics before drawing conclusions about utility.

Context: industry momentum around AI security standards

This announcement adds to a pattern of industry-level attempts to standardise AI security practice. The involvement of security-focused vendors alongside AI and cloud companies suggests the alliance intends to bridge communities that have historically developed their own tooling independently. Whether open-source frameworks produced by vendor consortia achieve meaningful adoption outside their founding members is a practical question that will take time to answer.

Why it matters

For CISOs, the formation of this alliance is relevant on two levels. First, the open-sourcing of NOOA means your teams may soon encounter it in vendor products or internal proposals — understanding it before it arrives is preferable to evaluating it under pressure. Second, the composition of the membership signals where significant portions of the security vendor market believe AI agent security is heading: toward shared, open frameworks rather than proprietary, siloed tools. Organisations already building or deploying AI agents should track the alliance’s output as a potential source of reference architectures and tooling. Those procuring security products from member vendors should expect to hear NOOA referenced in future product discussions and should be prepared to ask pointed questions about how it is actually implemented rather than simply cited.

What to do now

  • Review the NOOA open-source framework directly from NVIDIA’s published repository to assess whether it addresses threat models relevant to your AI agent deployments.
  • Monitor the Open Secure AI Alliance’s official communications for governance details, contribution processes, and technical roadmap before making adoption decisions.
  • If your organisation uses products from founding members — including Microsoft, Cisco, Cloudflare, CrowdStrike, IBM, or Palo Alto Networks — engage your vendor contacts to understand how NOOA may be incorporated into existing product lines.
  • Include awareness of this alliance in your AI security programme’s vendor landscape review, noting that the initiative is at an early stage and technical details remain limited.

Sources