The security industry has spent two years debating whether open AI models are a risk. We think that is the wrong question. Attackers are already using AI at scale; the real question is whether defenders get the same access to frontier capability - with the transparency to trust it. We are answering it by joining Nvidia as an inaugural partner in the Open Secure AI Alliance.
This is a movement of industry leaders collaborating on cybersecurity by sharing research, developing open techniques and tools, and safeguarding the software and critical systems the world runs on. Its work spans four open pillars: open models, open harnesses, open skills, and open research.
Members contribute research, tooling, infrastructure, and operational learnings. In return, the alliance produces stronger defensive agents, open tooling, better deployment practices, and shared evaluation frameworks - benefits that flow back to contributing members and, ultimately, to the entire open-source ecosystem.
Our position is simple: the world needs both closed and frontier open models, and enterprises should not be forced to choose. Closed models such as Claude Opus keep pushing the boundary of raw capability through proprietary innovation. Open models such as Nvidia Nemotron accelerate adoption through transparency, customisation, and deployment flexibility. We work with the best of both worlds - and this alliance strengthens the open half of that equation.
Two decades of coordinated disclosure
TrendAI™ and Nvidia have collaborated across Morpheus, NIM, and Nemotron; integrated our EDR on BlueField DPUs; delivered security-by-design for AI factories through our Nvidia DSX Air integration; and built a long track record of coordinated vulnerability disclosure - including ZDI research into Nvidia’s own stack, where our researchers reported an authentication-bypass vulnerability and, after Nvidia's patch, went back and found two further patch-bypass issues, each disclosed and fixed through the same coordinated process. We also bring evidence for the core premise of the alliance: TrendAI™ Zero Day Initiative™ (ZDI), the world’s largest vendor-agnostic bug bounty programme, has spent two decades demonstrating that vulnerabilities get found and fixed faster when research is shared.
This matters more than ever. Black Duck's 2026 Open Source Security and Risk Analysis Report found open source present in 98% of commercial codebases, with 87% containing at least one known open-source vulnerability. The infrastructure that runs much of the global economy is open - defending it demands transparency, shared intelligence, and the broadest possible community of defenders.
Secure the harness, not just the model
An AI agent is not just a model. It is a system of models, harnesses, and guardrails that determine what the agent can observe, reason about, and do. Industry attention has fixated on models, but much of the real security risk - and the defensive opportunity - lives in the harness: the scaffolding that lets an agent act.
This layer is exactly where alliance members are co-innovating. Nvidia is contributing Nemotron models, training data, and recipes, along with security research harnesses, skills, and techniques for vulnerability discovery and validation - including NOOA (Nvidia Labs Object-Oriented Agent), the newly open-sourced research framework now available on GitHub. TrendAI™ is bringing that same harness-first discipline to Nvidia OpenShell, Nvidia’s open source runtime for autonomous, self-evolving agents: TrendAI Vision One™ governance policies now travel directly into the OpenShell runtime, Agentic Scan inventories every skill and tool an agent can reach and flags behaviour that doesn't match what was declared, and dynamic behavioural analysis catches what static review would miss - before, during, and after an agent acts.
More builders means more defenders
Open models turn AI users into AI builders - and builders into defenders. That expands opportunity, accelerates innovation, and gives enterprises a scalable, secure path to adopting AI on their own terms: adapting models to their industry, data, and operating requirements while protecting what matters.
For some organisations this is not a preference but a mandate. Where sovereignty requirements rule out sending sensitive data to external inference endpoints, open models are the only path to full physical and jurisdictional control. TrendAI Vision One™ for Sovereign and Private Cloud (SPC) gives governments and regulated enterprises exactly that option: open AI models deployed in sovereign private cloud environments, including regional or in-country data centres and fully air-gapped, on-premises deployments. AI-driven defence and control of your data - not one or the other.
Openness alone does not guarantee trust. AI still requires rigorous testing, strong safeguards, secure infrastructure, clear governance, and human oversight. But an open ecosystem widens the community that can do that work, and it builds trust on evidence, visibility, and participation. As policymakers weigh AI safety, our position is on the record: open models and open tooling are defensive assets - enabling transparency, independent evaluation, and shared remediation - not a security liability.
What comes next
Alliance contributions will show up where our customers already work: in TrendAI Vision One's detection engineering, in the open tooling the alliance publishes, and in the research TrendAI and Nvidia share with the broader defender community. For the full alliance roster, see Nvidia's announcement - and follow this space as TrendAI's contributions take shape.