Loading market data...
Tuesday, July 28, 2026
Back to HomeNews

Nvidia (NVDA), Microsoft Lead 37-Member AI Security Alliance

By MinJeKim0 views
Share
Nvidia (NVDA), Microsoft Lead 37-Member AI Security Alliance

Nvidia (NASDAQ: NVDA) and Microsoft (NASDAQ: MSFT) on Monday, July 27, helped launch the Open Secure AI Alliance, a 37-member group that will build and share open-source tooling for AI-era cyber defense. Nvidia's announcement blog states the group's purpose as ensuring "defenders everywhere have open, frontier tools they can trust and control." Business Standard and Nvidia's blog both put the founding roster at 37 organizations.

The absentees define the story. OpenAI, Anthropic, Google (NASDAQ: GOOGL) and Meta (NASDAQ: META) are all missing from the founding list, per Engadget's account and Business Standard. The four best-known U.S. frontier-model labs are sitting this one out.

The incident that supplies the argument

This is not an abstract open-versus-closed manifesto. There is a specific operational grievance behind it, documented by the company that was attacked.

On July 16, Hugging Face — a New York- and Paris-based hosting platform for open AI models and datasets, and itself a founding member of the alliance — published a disclosure of an intrusion into part of its production infrastructure. "This one was different from anything we had handled before in one important way: it was driven, end to end, by an autonomous AI agent system — and we detected and dissected it largely with AI of our own," the company wrote. Entry came through the data pipeline: "A malicious dataset abused two code-execution paths in our dataset processing... to run code on a processing worker."

The forensic step is the part the alliance's argument leans on. Hugging Face said it first tried commercial frontier models to analyze the attacker's log. "This did not work: the analysis requires submitting large volumes of real attack commands, exploit payloads, and C2 artifacts, and these requests were blocked by the providers' safety guardrails, which cannot distinguish an incident responder from an attacker." The company instead ran the analysis "on GLM 5.2, an open-weight model, on our own infrastructure," covering "more than 17,000 recorded events."

Its stated lesson reads like a procurement instruction: "have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment."

Nvidia's framing echoes it. Per Business Standard's account of the announcement: "The world needs both closed and open models. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities."

Help Net Security and Engadget both report that the alliance builds on the Linux Foundation's Akrites initiative and on the Open Source Security Foundation, the Linux Foundation's body for open-source software security work. Nvidia's blog lists the seed contributions: Nvidia's NOOA agent framework, HPE's SPIFFE/SPIRE identity standards, Hugging Face's Safetensors weight format, a supply-chain project called Lightwell from IBM (NYSE: IBM) and its enterprise open-source unit Red Hat, an open coding agent from xAI, and Microsoft's MDASH scanning harness.

Microsoft is standing on both sides of the trade

On the same day it joined a consortium premised on defenders needing models they can run themselves, Microsoft shipped a closed one.

Microsoft launched MAI-1 Cyber Flash, its first cybersecurity-specific model, built to find vulnerabilities in complex codebases, plus Project Perception, an agentic security platform that coordinates red-team agents that map paths to compromise, blue-team agents that triage risk, and green-team agents that remediate. Perception enters public preview on Aug. 3.

The claimed numbers, all from Microsoft: Microsoft AI CEO Mustafa Suleyman, quoted by TechCrunch, described the configuration as "MAI-1 Cyber Flash binded with GPT 5.4 inside of the MDASH harness — which beats out Gemini, GPT 5.5 Cyber, GPT 5.6 Sol, and Mythos 5 on Cyber Gym." That combination scored 96% on Cyber Gym, a vulnerability-discovery benchmark, which The Next Web reports is "12 points above Anthropic's Mythos 5, currently the most capable frontier model for cybersecurity tasks," with "nearly 50% cost savings versus the prior model configuration within the MDASH harness in production." None of those benchmark results have been independently verified. Microsoft's Dave Weston told TechCrunch that "in minutes, we have a fix for all of this... we have detection, posture fixing, and even a code fix."

Note the architecture of the business, not just the software. Microsoft donates MDASH — the harness — to the alliance, and sells MAI-1 Cyber Flash, the model that runs inside it. Open harness, paid engine. That is a materially different bet from Hugging Face's, and it is worth watching whether both bets can sit inside the same alliance.

Sizing it against Microsoft's actual P&L

Microsoft does not break out security revenue as a line item; its FY26 Q3 release (quarter ended March 31, 2026) reports only three segments — Productivity and Business Processes at $35.01 billion, Intelligent Cloud at $34.68 billion, More Personal Computing at $13.19 billion — on total revenue of $82.9 billion, up 18%.

The nearest disclosed proxy is the AI business, which that release says "surpassed an annual revenue run rate of $37 billion, up 123% year-over-year." Annualizing the March quarter's $82.9 billion gives roughly $332 billion, so the entire AI business is on the order of 11% of company revenue on a rough mixed-basis approximation — the $37 billion is a forward-looking run rate while the $332 billion annualizes a single reported quarter — and a new cyber model is a fraction of that fraction. Perception will not move the July 29 print. What it moves is the competitive framing of who supplies AI security to enterprises, a question that sits between Microsoft and fellow alliance members Palo Alto Networks (NASDAQ: PANW) and CrowdStrike (NASDAQ: CRWD), both established security vendors that also signed on.

The precedent, and how it turned out

Industry alliances organized around openness have a track record. In December 2023, IBM and Meta launched the AI Alliance with more than 50 founding members and, as TechXplore reported at the time, without OpenAI or Google. The outcome: it grew. In March 2025, Forbes published analysis from the technology research firm Moor Insights & Strategy putting the group at more than 140 members across 23 countries. What it did not do was close the open-versus-closed split it was formed to argue about — that split is the same one on display today.

The inversion is the interesting part. Nvidia and Microsoft were not on that 2023 founding roster; they anchor this one. Meta, the 2023 co-founder and the most vocal open-weights advocate among U.S. mega-caps, is absent from this one.

Two Korean names also appear on the founding list: NAVER (KRX: 035420), the search portal that develops its own sovereign-AI models, and SK Telecom (NYSE: SKM), a Korean mobile carrier building Korean-language models of its own — a signal that the "run your own model" argument travels to jurisdictions with data-residency rules.

What would confirm or refute the thesis

Three dated checkpoints, in order:

  • July 29 — Microsoft reports fiscal 2026 fourth-quarter results after the close, per its own announcement. Whether management quantifies security or Perception on the call, rather than leaving it inside "AI business," is the tell on how commercially serious this is.
  • Aug. 3 — Perception's public preview. Pricing and whether MAI-1 Cyber Flash is licensed for on-premises execution will show whether Microsoft is genuinely aligned with the alliance's own stated requirement.
  • Late August — Nvidia's fiscal Q2 2027 report. The alliance's premise is that enterprises will run open-weight models on their own infrastructure, which is a demand argument for Nvidia silicon; commentary on enterprise on-prem inference would be the first place that shows up.

The refutation condition is equally clear: if OpenAI, Google or Anthropic relax incident-response guardrails or ship defender-verified API paths, the alliance's founding grievance loses its force.


This article is journalism, not investment advice. LineVest is not a registered investment adviser. Figures are as reported by the cited sources on the dates noted.

NewsFinanceMarkets

Go deeper than the headline

You just read what happened. Here's how to read what it means.

Free daily briefing

The U.S. market, every morning — free

LineVest Daily lands in your inbox before every opening bell: the key U.S. markets stories, earnings, disclosures and foreign flows — in plain English. Free, no card required.

Get LineVest Daily — free →
This filing

Full report on this filing

We read this company's latest SEC filing in full — financials under US GAAP, governance, and what it means for the stock. PDF in your inbox within 3 hours.

$12 · one-time

Get the full report
Every name you watch

Follow the whole market

Reading several U.S. stocks a week? Read every analysis article the moment it publishes — full daily U.S. market coverage plus the 90-day archive.

$9.99 · monthly

Subscribe

Independent journalism based on primary SEC filings — not investment advice. No brokerage affiliation.

Nvidia (NVDA), Microsoft Lead 37-Member AI Security Alliance