Linux Foundation is building an open security stack for the AI era

AI agents are gaining access to email, files, databases, APIs, and other systems where mistakes can have real consequences. The Linux Foundation now wants to help build an open security layer around this emerging world.

The Open Secure AI Alliance has joined the Linux Foundation, giving the project a neutral home for developing tools, standards, and defenses for AI systems. The Alliance was originally established by NVIDIA with participation from dozens of enterprise organizations, including the Linux Foundation.

The goal is an “open defensive stack” that stretches across models, inference systems, agents, identity, permissions, policy enforcement, containment, and the infrastructure underneath it all.

That is an ambitious list, but AI security cannot simply mean protecting the model itself. An agent capable of accessing corporate systems could potentially expose data, execute unwanted actions, or make decisions using permissions that were never intended for it.

“AI systems should be secure, reliable and predictable,” said Jim Zemlin, CEO of the Linux Foundation. “By bringing the Open Secure AI Alliance to the Linux Foundation, we are creating a neutral home where industry, researchers and governments can collaborate on open tools, shared standards and evidence-based practices that strengthen security and support AI innovation.”

NVIDIA will continue participating in the effort.

“AI security improves when organizations openly share what they learn,” said Justin Boitano, vice president, Enterprise AI, NVIDIA. “With the Linux Foundation as its new home, the Open Secure AI Alliance can bring together experts across models, harnesses and infrastructure to turn shared evidence into practical, verifiable defenses for the entire AI stack.”

One particularly interesting project is the Shared AI Findings Exchange, or SAFE. The proposal calls for organizations to confidentially contribute findings from AI security incidents so recurring failures can be identified and converted into practical defenses.

Developers, researchers, defenders, and other organizations can comment on the SAFE proposal through September 21.

The Alliance also wants organizations to apply familiar security principles to AI agents, including asset visibility, tightly managed identities and permissions, monitoring, change management, deterministic controls, and human accountability. Shared evaluation standards and incident-response exercises are part of the plan too.

There is plenty to like about the idea of keeping AI security open. Organizations should be able to inspect the defenses protecting systems that could eventually have enormous amounts of autonomy and access. Depending entirely on proprietary security mechanisms would require companies to place considerable trust in vendors whose technology they cannot fully examine.

Of course, an open framework only works if organizations actually participate. Convincing competitors to share useful information about vulnerabilities and security incidents could prove difficult, particularly when those incidents involve sensitive corporate systems.

Still, AI agents are moving quickly from experiments into real-world deployments. As that happens, the industry will need defenses that can evolve just as quickly.

The Linux Foundation cannot make AI secure simply by providing a neutral home for collaboration. But if companies are going to hand increasingly powerful agents access to important systems, building at least part of the security stack in the open seems like a sensible place to start.

Support independent tech journalism

NERDS.xyz is independently owned and operated. If you enjoy my coverage of Linux, AI, hardware, cybersecurity, and tech culture, consider supporting the site on Ko-fi.

Support NERDS.xyz
Written by

Brian Fagioli

Technology journalist and founder of NERDS.xyz

Brian Fagioli is a technology journalist and founder of NERDS.xyz. A former BetaNews writer, he has spent over a decade covering Linux, hardware, software, cybersecurity, and AI with a no nonsense approach for real nerds.

Leave a Comment