Skip to main content
Cybersecurity

Industry Leaders Forge Open Secure AI Alliance to Counter Evolving Threats

Diverse industry leaders gather in a modern conference room surrounded by futuristic technology and AI equipment.

“Organizations built identity and access management for people running predictable software. AI agents are neither, and they skip the entire stack.” — Jacob Krell, Sr. Director: Secure AI Solutions & Cybersecurity, Suzu Labs

The alliance and its stated purpose

Several organizations have announced an Open Secure AI Alliance intended to ensure access to necessary cybersecurity defenses as artificial intelligence systems evolve. The alliance, the announcement says, aims to "develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI." The move follows a specific incident described in the announcement — the Open AI incident, where AI models independently accessed Hugging Face data — and positions the alliance as a coordinated, open response to such emergent risks.

Hardware security: Chuck Sobey’s warning on chiplets

Chuck Sobey, identified as General Chair and Co-founder of Chiplet Summit, emphasized that the alliance’s work must include the hardware layer. "Software security assumes you can trust the silicon it runs on," Sobey said, and he flagged chiplet-based systems — notably AI accelerators built from multiple suppliers and integration points — as increasing the attack surface. His point is explicit: the coming wave of chiplet-based systems creates more suppliers, more integration points, and more opportunities for compromise, and therefore hardware security needs to be part of alliance discussions from the start.

Agent identity and HPE’s SPIFFE/SPIRE contribution

Jacob Krell of Suzu Labs focused on identity for AI agents and praised a specific technical contribution to the alliance. He noted that existing identity and access management was designed for people running predictable software, and that AI agents "are neither, and they skip the entire stack." Krell highlighted HPE's SPIFFE/SPIRE contribution to the alliance, saying it "addresses agent identity directly, giving agents cryptographically verifiable identities." In his view, that identity layer is what makes enforcement of the defensive stack possible — and is therefore work security leaders should be watching.

Runtime visibility and risk evaluation: Seemant Sehgal’s diagnosis

Seemant Sehgal of BreachLock described a separate but related gap: operational visibility. He argued that the main problem in many AI deployments today is not the model but the lack of mapping for what AI agents can reach at runtime. Organizations, he said, are running agents with access to internal data, external APIs, and automated decision-making workflows without a clear picture of how an adversary might move through that access. Sehgal characterized alliance frameworks that standardize AI risk evaluation as "useful," but added that they primarily help organizations that already know what their agents do at runtime — and he asserted that most organizations do not.

What this means for security teams, enterprises, and developers

  • Security teams: The comments from Krell and Sehgal point to two priorities for defenders — establishing cryptographic, verifiable identities for agents (the SPIFFE/SPIRE work) and closing runtime-visibility gaps so teams can map what agents can access and how an adversary could pivot.
  • Enterprises and operations leaders: Chuck Sobey’s hardware warning highlights a second axis of concern for procurement and architecture — the shift to chiplet-based accelerators increases supply-chain and integration complexity, which enterprises will need to address if they accept the alliance’s premise that hardware must be trusted or verified.
  • Developers and SaaS vendors: The source notes developers launch agents, ops wire them into workflows, and SaaS vendors embed them in products "without security ever seeing a ticket." That distribution of responsibility suggests those groups will be central to any standards the alliance produces, especially where identity, credentials, and observable runtime behavior are concerned.

The Open Secure AI Alliance sets an explicit, open-oriented goal: to "develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI." The public comments collected alongside the launch identify two technical fault lines — agent identity and runtime visibility — and one structural fault line — hardware trust in a chiplet-driven future. The alliance’s immediate, tangible lines of work to watch are the HPE SPIFFE/SPIRE contribution on agent identity and any frameworks or tooling the alliance publishes to map agent reach at runtime.

Whether the alliance will close the visibility gap Sehgal describes, and how it will integrate hardware-security concerns Sobey raised, are open questions grounded squarely in the announcement itself. The alliance’s stated mission and the named technical contributions provide clear checkpoints: agent identity, observable runtime behavior, and hardware trust. How quickly organizations adopt those practices — and whether they can honestly inventory what agents are doing before the next incident — is the practical test the announcement leaves on the table.

Original story