First, if you’re not up to date on Nvidia’s Open Secure AI Alliance, this will help:Industry Leaders Join Open Secure AI Alliance for AI Safety and Security | NVIDIA Blog
The consensus from experts in the industry is that this is a meaningful step for the industry, but it’s only the beginning. The real challenge now is helping enterprises secure AI agents in the real world, with better identity, visibility, governance, and even hardware security. Their comments dig into what the announcement means beyond the headlines and where organizations still have the most work to do.
John Strand, Black Hills (https://www.linkedin.com/in/john-strand-a1b4b62)
“I think we’re going to see a lot more stories like this because there’s real anxiety in the AI industry right now. Part of it is financial. Many organizations are struggling to demonstrate a meaningful return on investment from their AI initiatives. The other part is security. As researchers continue to show AI systems escaping their intended boundaries or interacting with other systems in unexpected ways, concerns about AI safety are growing. That’s why you’re seeing so many new AI security initiatives. In many cases, they’re trying to establish industry standards before governments step in with legislation or regulation. Whether those efforts are enough remains to be seen.”
Chuck Sobey, General Chair and Co-founder, Chiplet Summit (https://www.linkedin.com/in/chucksobey)
“As the Open Secure AI Alliance focuses on securing the AI ecosystem, one area that deserves greater attention is the security of the underlying hardware powering AI infrastructure. Software security assumes you can trust the silicon it runs on. The coming wave of chiplet-based systems, especially AI accelerators, raises the stakes: more suppliers, more integration points, more attack surfaces. Hardware security has to be part of this conversation from the beginning.”
John Carberry, Solution Sleuth, Xcape Inc. (https://www.linkedin.com/in/john-carberry-1418a622a)
“Accelerating autonomous artificial intelligence adoption creates systemic enterprise exposure when organizations deploy intelligent agents without establishing clear identity boundaries or visibility controls. Bringing industry heavyweights together through the Open Secure AI Alliance provides a much-needed collaborative effort to advance secure design patterns and open-source defensive tooling outside of traditional business competition. While vendor collaboration establishes essential baseline standards for this emerging technology, security leaders cannot treat pre-competitive initiatives as a substitute for internal governance. Organizations frequently fall short by granting artificial intelligence agents excessive API permissions and service account privileges without audit logging, opening direct pathways for indirect prompt injection and unauthorized data exfiltration. Security executives must immediately map all artificial intelligence integrations, enforce least-privilege scoping on agent execution frameworks, and treat agent interactions with external systems as untrusted input requiring strict validation.
“Critical Takeaways
- Leverage pre-competitive standards: Use open-source security frameworks from industry alliances to standardize threat modeling for artificial intelligence deployments across enterprise environments.
- Scope agent permissions tightly: Restrict autonomous artificial intelligence agents using least-privilege access controls, credential isolation, and strict API scope boundaries.
- Treat agent inputs as untrusted: Implement rigorous input validation and comprehensive audit logging for all automated workflows to neutralize indirect prompt injection risks.
“Industry alliances can build safe frameworks outside of business competition, but your security team still has to enforce them inside your corporate network.”
Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)
“Organizations built identity and access management for people running predictable software. AI agents are neither, and they skip the entire stack.
“Most security teams can’t tell you how many agents are running in their environment right now, or what those agents can access. Developers launch them, ops teams wire them into workflows, and SaaS vendors embed them in products without security ever seeing a ticket. Each agent holds credentials to production systems and behaves non-deterministically, meaning the same agent running the same task can take a different path every time.
“The Hugging Face breach is proof this gap has consequences. OpenAI tested its models’ exploitation capabilities, and those models breached a real company. If OpenAI couldn’t predict what their own models would do in a controlled evaluation, no enterprise should assume they can predict agent behavior in production. When Hugging Face reached for closed frontier models to analyze the attack, safety guardrails blocked them from examining exploit payloads. They ran GLM 5.2, a Chinese open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Claude Opus 4.6 for security work because newer models increasingly refuse to process real attack artifacts. If Washington restricts Chinese open-weight models without ensuring equivalent open alternatives from U.S. labs, defenders lose the tool that actually worked when closed models wouldn’t.
“The Open Secure AI Alliance is right that defenders need open, inspectable models they can run on their own infrastructure. HPE’s SPIFFE/SPIRE contribution to the alliance addresses agent identity directly, giving agents cryptographically verifiable identities. Security leaders should be watching that work. Identity for agents is what makes the rest of the defensive stack enforceable.”
Seemant Sehgal, BreachLock (https://www.linkedin.com/in/s-sehgal)
“The gap in most AI deployments right now is not in the model itself. Organizations are running AI agents with access to internal data, external APIs, and automated decision-making workflows, and they have not mapped what those agents can reach or how an adversary would move through that access. Alliance frameworks that standardize how AI systems are evaluated for risk are useful, but the organizations that will benefit from them are the ones that already know what their agents are doing at runtime. Most do not.
Related
This entry was posted on July 28, 2026 at 8:15 am and is filed under Commentary with tags NVIDIA. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
What Nvidia’s Open Secure AI Alliance means for enterprise security
First, if you’re not up to date on Nvidia’s Open Secure AI Alliance, this will help:Industry Leaders Join Open Secure AI Alliance for AI Safety and Security | NVIDIA Blog
The consensus from experts in the industry is that this is a meaningful step for the industry, but it’s only the beginning. The real challenge now is helping enterprises secure AI agents in the real world, with better identity, visibility, governance, and even hardware security. Their comments dig into what the announcement means beyond the headlines and where organizations still have the most work to do.
John Strand, Black Hills (https://www.linkedin.com/in/john-strand-a1b4b62)
“I think we’re going to see a lot more stories like this because there’s real anxiety in the AI industry right now. Part of it is financial. Many organizations are struggling to demonstrate a meaningful return on investment from their AI initiatives. The other part is security. As researchers continue to show AI systems escaping their intended boundaries or interacting with other systems in unexpected ways, concerns about AI safety are growing. That’s why you’re seeing so many new AI security initiatives. In many cases, they’re trying to establish industry standards before governments step in with legislation or regulation. Whether those efforts are enough remains to be seen.”
Chuck Sobey, General Chair and Co-founder, Chiplet Summit (https://www.linkedin.com/in/chucksobey)
“As the Open Secure AI Alliance focuses on securing the AI ecosystem, one area that deserves greater attention is the security of the underlying hardware powering AI infrastructure. Software security assumes you can trust the silicon it runs on. The coming wave of chiplet-based systems, especially AI accelerators, raises the stakes: more suppliers, more integration points, more attack surfaces. Hardware security has to be part of this conversation from the beginning.”
John Carberry, Solution Sleuth, Xcape Inc. (https://www.linkedin.com/in/john-carberry-1418a622a)
“Accelerating autonomous artificial intelligence adoption creates systemic enterprise exposure when organizations deploy intelligent agents without establishing clear identity boundaries or visibility controls. Bringing industry heavyweights together through the Open Secure AI Alliance provides a much-needed collaborative effort to advance secure design patterns and open-source defensive tooling outside of traditional business competition. While vendor collaboration establishes essential baseline standards for this emerging technology, security leaders cannot treat pre-competitive initiatives as a substitute for internal governance. Organizations frequently fall short by granting artificial intelligence agents excessive API permissions and service account privileges without audit logging, opening direct pathways for indirect prompt injection and unauthorized data exfiltration. Security executives must immediately map all artificial intelligence integrations, enforce least-privilege scoping on agent execution frameworks, and treat agent interactions with external systems as untrusted input requiring strict validation.
“Critical Takeaways
“Industry alliances can build safe frameworks outside of business competition, but your security team still has to enforce them inside your corporate network.”
Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)
“Organizations built identity and access management for people running predictable software. AI agents are neither, and they skip the entire stack.
“Most security teams can’t tell you how many agents are running in their environment right now, or what those agents can access. Developers launch them, ops teams wire them into workflows, and SaaS vendors embed them in products without security ever seeing a ticket. Each agent holds credentials to production systems and behaves non-deterministically, meaning the same agent running the same task can take a different path every time.
“The Hugging Face breach is proof this gap has consequences. OpenAI tested its models’ exploitation capabilities, and those models breached a real company. If OpenAI couldn’t predict what their own models would do in a controlled evaluation, no enterprise should assume they can predict agent behavior in production. When Hugging Face reached for closed frontier models to analyze the attack, safety guardrails blocked them from examining exploit payloads. They ran GLM 5.2, a Chinese open-weight model, on their own infrastructure instead. I’ve hit the same wall. I still run Claude Opus 4.6 for security work because newer models increasingly refuse to process real attack artifacts. If Washington restricts Chinese open-weight models without ensuring equivalent open alternatives from U.S. labs, defenders lose the tool that actually worked when closed models wouldn’t.
“The Open Secure AI Alliance is right that defenders need open, inspectable models they can run on their own infrastructure. HPE’s SPIFFE/SPIRE contribution to the alliance addresses agent identity directly, giving agents cryptographically verifiable identities. Security leaders should be watching that work. Identity for agents is what makes the rest of the defensive stack enforceable.”
Seemant Sehgal, BreachLock (https://www.linkedin.com/in/s-sehgal)
“The gap in most AI deployments right now is not in the model itself. Organizations are running AI agents with access to internal data, external APIs, and automated decision-making workflows, and they have not mapped what those agents can reach or how an adversary would move through that access. Alliance frameworks that standardize how AI systems are evaluated for risk are useful, but the organizations that will benefit from them are the ones that already know what their agents are doing at runtime. Most do not.
Share this:
Like this:
Related
This entry was posted on July 28, 2026 at 8:15 am and is filed under Commentary with tags NVIDIA. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.