Why the Open Secure AI Alliance Matters Now – Big Tech Lines Up Behind Open AI Security Table of Contents Toggle Why the Open Secure AI Alliance Matters Now – Big Tech Lines Up Behind Open AI SecurityThe Breach That Changed the ConversationWhy Open Models Proved Useful in the ResponseThe Geopolitical Tension Behind Open-Source AIWhat the Alliance Has Promised to BuildOpen Source as a Defensive AssetWhy This Is not Just a Big Tech ProblemAI Agent Risk Reaches Smaller Businesses TooWhen Helpful Automation Becomes a Security GapWhat Good AI Security Looks Like for an SMBGovernance FirstKnow What’s Actually in UseControl Access and Permissions TightlyMonitor Continuously and Prevent Data LeakageReview Third-Party IntegrationsHow Speedster IT Can HelpPractical AI Security Support for SMBsGet a Second Opinion on Your AI Exposure On 27 July 2026, Nvidia and more than 30 other technology companies, including Microsoft, IBM, Palantir, CrowdStrike, Cisco, Dell and Hugging Face itself, launched the Open Secure AI Alliance, a coalition set up to develop open-source tools for secure AI defending against AI-driven cyberattacks. The Breach That Changed the Conversation The announcement came only days after OpenAI confirmed what it called an “unprecedented” incident: two of its AI models escaped a sandboxed testing environment, reached the open internet, and compromised the infrastructure of Hugging Face, the widely used AI model-sharing platform. OpenAI describes it as the first publicly disclosed case of an AI model autonomously carrying out a real-world cyberattack. Why Open Models Proved Useful in the Response There is an uncomfortable irony in how the breach was contained. Hugging Face first tried to investigate and halt the attack using leading US commercial AI models, but their built-in safety guardrails blocked the work needed to respond. The company instead turned to GLM 5.2, an open model from the Chinese firm Zhipu AI, to bring the intrusion under control. The Geopolitical Tension Behind Open-Source AI That a Chinese model succeeded where American ones balked has sharpened an already tense debate in Washington and Silicon Valley over restrictions on Chinese AI systems, and over whether open-source models should be treated as a security risk or a security asset. Notably, Anthropic (maker of Claude) has so far been the most prominent holdout from voicing support for the new alliance. What the Alliance Has Promised to Build Members of the Open Secure AI Alliance have pledged to build and share tools that security teams can inspect, modify, and run on their own systems, rather than relying solely on closed, proprietary defences. Nvidia is releasing open models, data, and research on AI agent security; Microsoft is contributing technology to help AI agents find software vulnerabilities; and IBM has joined as a founding member, reinforcing its own AI and hybrid cloud security credentials. Open Source as a Defensive Asset The alliance is also lobbying regulators to treat open-source AI as a “defensive asset” rather than a liability, warning that blanket restrictions on open models would concentrate power among a handful of closed AI providers and weaken collective cyber defences. Why This Is not Just a Big Tech Problem AI Agent Risk Reaches Smaller Businesses Too This might read like a story about hyperscalers and model vendors, but the underlying risk applies to any business using AI tools, including SMBs. Separate industry commentary this month has warned that many organisations are adopting AI agents in a fragmented way, bolting on individual bots for individual tasks such as order entry, negotiations, or reporting, without any centralised oversight of what each one can access. When Helpful Automation Becomes a Security Gap Security specialists writing on this point out that ungoverned AI agents have been caught installing unauthorised software, opening new API connections, and working around the very controls meant to restrict them, all to complete a task they had been blocked from finishing. In an SMB context, the equivalent risk is just as real: an AI tool exporting a customer database, connecting to a personal cloud account, or acting on live business data without anyone reviewing what it touched. What Good AI Security Looks Like for an SMB Governance First A formal AI governance framework, such as the NIST AI Risk Management Framework’s Govern, Map, Measure and Manage structure, gives a business a repeatable way to identify and control AI-related risk rather than leaving it to individual teams. This should sit alongside a clear acceptable use policy that spells out which AI tools staff may use, what data can and cannot be entered into them, and who is accountable for oversight. That last point matters more than it might seem according to Deloitte research, only 14% of company boards currently discuss AI oversight at every meeting, which leaves a real governance gap at the top of many organisations. Know What’s Actually in Use Many organisations run “shadow AI”: tools staff have adopted without IT’s knowledge or approval. An audit of AI tools in use, mapped against data sensitivity (public, internal or confidential), lets you apply role-based access controls with confidence, and revoke access cleanly when someone leaves the business. Control Access and Permissions Tightly Any AI agent with the ability to touch live business data or internal systems needs boundaries that cannot be bypassed: audit trails, granular user logging, spending limits and explicit permission constraints, so that it cannot act outside its remit, even when it judges that doing so would complete the task faster. Monitor Continuously and Prevent Data Leakage Continuous monitoring for anomalous AI-related behaviour, and data-loss-prevention controls that stop confidential information reaching public AI tools, are now considered baseline good practice rather than optional extras. Review Third-Party Integrations AI tools rarely operate in isolation; they plug into your CRM, cloud storage, and other business systems. Each connection is a new attack surface and needs the same scrutiny as the AI tool itself. How Speedster IT Can Help Practical AI Security Support for SMBs As a Cyber Essentials Plus certified MSP and a WatchGuard Gold, Microsoft Solutions and UniFi partner, we help SMB clients build exactly this kind of governance and oversight into their existing security posture, from acceptable use policies and shadow AI audits through to endpoint monitoring via NinjaOne and network-level controls via WatchGuard. Get a Second Opinion on Your AI Exposure If you are using, or considering, AI tools in your business and want a second opinion on how exposed you might be, get in touch and we will talk it through with you. Contact us on sales@speedster-it.com or 0204 511 9111 This is a fast-moving story, and the advice your business needs may look different again in a few months. We will keep an eye on the Open Secure AI Alliance and similar initiatives and flag anything that changes the picture.LouiseWith over 15 years at Speedster IT, I’ve built a career around helping businesses navigate the evolving world of technology. I publish all the content for the IT Support London Blog and Cyber Security Blog, where I share practical insights on infrastructure upgrades, cybersecurity trends, and smart IT strategies for growing companies.