```

A new coalition of 37 technology companies, led by NVIDIA, has formed the Open Secure AI Alliance to create shared, open-source defenses for autonomous AI agent systems. The initiative, announced alongside the release of its foundational NOOA framework, aims to address security risks that have outpaced traditional software protection models.

The alliance's membership spans cloud providers, cybersecurity firms, and enterprise AI developers, including Microsoft, Cisco, CrowdStrike, and Red Hat. This broad coalition underscores a growing industry consensus: securing agentic AI requires collective, transparent effort rather than proprietary solutions.

Modern AI agents, which can autonomously invoke tools and chain actions across multiple services, introduce novel vulnerabilities like prompt injection and privilege escalation. Conventional security stacks are ill-equipped to handle these threats, which span API boundaries and third-party ecosystems. The alliance positions open tooling as a necessary response to this new attack surface.

NOOA is the group's first public deliverable, providing an open-source baseline for evaluating agent isolation, tool-calling controls, and runtime monitoring. By releasing the framework under community review, the alliance hopes to accelerate defense development through broad scrutiny—a model successfully used in cloud-native and open-source security.

For development teams, the framework offers a practical starting point for auditing AI pipelines. Early alignment with its controls may become a benchmark as customers, insurers, and regulators begin demanding evidence of robust agent security. Smaller organizations and academic researchers can contribute without licensing barriers, potentially widening the field of discovery.

The move arrives as global AI governance takes shape. A demonstrable, industry-backed security standard could influence future compliance frameworks, moving beyond theoretical guidelines to concrete technical requirements. However, the alliance's long-term impact hinges on transparent governance and a clear technical roadmap beyond the initial release.

Adoption is not mandatory, but the coalition's weight and open posture are likely to set expectations. Development teams building with AI agents will increasingly need to justify their security postures, making early engagement with NOOA a strategic consideration.

Ultimately, the Open Secure AI Alliance frames agent security as shared infrastructure—a collective challenge to be solved in the open. The maturation and adoption of its tools will signal whether the industry can secure its most autonomous and capable software creations.


由 NVIDIA 牽頭的37家科技公司組成新聯盟「開放安全人工智能聯盟」,旨在為自主型人工智能代理系統建立共享的開源防禦體系。該計劃在發布基礎框架 NOOA 的同時宣佈,旨在應對已超越傳統軟件保護模式的安全風險。

聯盟成員涵蓋雲端服務供應商、網絡安全公司及企業人工智能開發商,包括微軟、思科、CrowdStrike 和 Red Hat。如此廣泛的聯盟結構反映業界日益形成的共識:保障自主型人工智能安全需要集體、透明的努力,而非專屬解決方案。

現代人工智能代理能夠自主調用工具並在多項服務間串聯行動,因而帶來提示注入、權限提升等新型安全漏洞。傳統安全架構難以應對這些跨越 API 邊界及第三方生態系統的威脅。聯盟認為,開源工具是對抗此類新型攻擊面的必要措施。

NOOA 是聯盟的首項公開成果,提供評估代理隔離、工具調用控制及運行時監控的開源基準。透過將框架置於社群審視下發布,聯盟希望借助廣泛檢驗來加速防禦體系發展——這是雲原生及開源安全領域已成功應用的模式。

對開發團隊而言,該框架為人工智能管線審計提供了實用起點。隨著客戶、保險公司及監管機構開始要求證明代理安全性,提早遵循其控制基準或將成為重要指標。中小型機構及學術研究者無需受許可證限制即可貢獻力量,有望拓寬研究探索領域。

此舉正值全球人工智能治理體系成形之際。一個獲得產業支持、可實證的安全標準,可能影響未來合規框架的制定,從理論指導轉向具體技術要求。然而,聯盟的長期影響力,取決於透明治理機制及首發版本後的清晰技術路線圖。

採納並非強制要求,但聯盟的行業分量與開放姿態,很可能確立市場預期。開發使用人工智能代理的團隊將日益需要證明其安全準備,這使得及早接觸 NOOA 成為策略性考量。

歸根究底,「開放安全人工智能聯盟」將代理安全定位為共享基礎設施——一項必須公開解決的集體挑戰。其工具的成熟度與採用率,將標誌著產業能否保障其最自主、最強大的軟件創造物的安全。

新聞來源 / Original News Source