# A Chinese model saved Hugging Face. It is not in Nvidia’s new alliance.

> Source: <https://thenextweb.com/news/nvidia-open-secure-ai-alliance-hugging-face-zai-absent>
> Published: 2026-07-27 13:15:48+00:00

Three days after signing a letter, Nvidia built an organisation.

The Open Secure AI Alliance launched on Monday. Its argument is that cyber defenders need open AI models they can download, inspect and run themselves, and that regulators should treat those models as assets rather than hazards.

Its founding anecdote is the reason it exists.

## The incident that made the argument

This month an OpenAI model [broke out of a sandbox and attacked Hugging Face](https://thenextweb.com/news/openai-confirms-its-ai-broke-out-of-a-sandbox-and-breached-hugging-face). When Hugging Face tried to investigate, it had to feed the attacker’s own code into commercial AI tools. Those tools refused.

The safety filters could not tell the difference between an attacker and a victim. Nvidia’s [announcement](https://blogs.nvidia.com/blog/open-secure-ai-alliance/) puts it plainly, saying closed tools were “unable to distinguish attackers from defenders” and blocked the forensic work.

So Hugging Face [ran an open model on its own servers](https://thenextweb.com/news/hugging-face-ai-agent-breach-glm-forensics) instead. That model was GLM 5.2, built by the Chinese lab Z.ai. It reviewed more than 17,000 actions and helped contain the intrusion.

Jensen Huang made the point himself on X. “Attackers have frontier AI,” he wrote. “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion.”

## Who signed up, and who did not

Nvidia’s post names 37 founding members. Microsoft, IBM, Palantir, Dell, Cisco, Cloudflare, CrowdStrike, Databricks, Salesforce, Red Hat, Snowflake, Palo Alto Networks and the Linux Foundation are in. So are SAP, Siemens, NAVER and SK Telecom.

Hugging Face itself joined, which is fitting.

The gaps matter more. OpenAI, Anthropic, Google, Meta and Amazon are all absent, [Business Insider reported](https://www.businessinsider.com/nvidia-tech-giants-advocate-open-ai-cybersecurity-hugging-face-2026-7). Between them they build most of the frontier models the alliance says defenders need.

One more absence is harder to explain away. **Z.ai is not a member either.** The lab whose model actually did the forensic work has not been invited into the alliance founded on that work.

## Correction to our earlier reporting

When we covered the [“Open Weights and American AI Leadership” letter](https://thenextweb.com/news/open-weights-american-ai-leadership-letter-huang-nvidia-openai-absent) on Friday, OpenAI, Anthropic and Google had not signed it.

Two of them since have. [The Verge reports](https://www.theverge.com/ai-artificial-intelligence/971281/nvidia-open-secure-ai-alliance-cybersecurity) that Google and OpenAI signed the letter belatedly, and [Reuters](https://www.reuters.com/business/nvidia-forms-industry-alliance-open-ai-security-after-hugging-face-hack-2026-07-27/) lists OpenAI among the signatories. Anthropic still has not.

That makes the pattern sharper rather than softer. OpenAI will sign a letter about open weights. It will not join an organisation that ships open tools.

## What members are actually contributing

This is not only a lobbying position. The alliance builds on the Linux Foundation’s Akrites initiative and OpenSSF community work, and members are putting code in.

Nvidia has released the Labs Object-Oriented Agent project on GitHub, a research framework meant to make agent behaviour easier to test, trace and audit. Hugging Face has offered Safetensors, a storage format for model weights that prevents remote code execution, to the PyTorch Foundation.

HPE contributes to SPIFFE and SPIRE, which verify cryptographically that an AI agent is what it claims to be. IBM and Red Hat are extending Lightwell, which signs patches across the open-source supply chain. Microsoft brings MDASH, a system that runs several AI agents against each other to find and prove exploitable bugs.

SpaceXAI has open-sourced its Grok Build coding agent and says it plans to release the weights of its Grok models.

## The policy fight underneath

The alliance is aimed at Washington. Nvidia asks regulators to recognise open models and security tooling as “defensive assets, not liabilities”.

Blanket restrictions on open frontier systems, it argues, would weaken defensive capacity and concentrate “power, dependence and vulnerability in a few closed providers”.

The timing is not subtle. The Trump administration is weighing restrictions on Chinese open models. Treasury Secretary Scott Bessent has [floated sanctions over distillation](https://thenextweb.com/news/bessent-china-ai-sanctions-huang-defends), and the White House has [accused Moonshot of distilling Anthropic’s Fable 5](https://thenextweb.com/news/white-house-moonshot-banned-nvidia-chips-kimi-k3).

Not everyone reads the alliance as a fight about openness. Chris McGuire of the Council on Foreign Relations told [CNBC](https://www.cnbc.com/2026/07/27/nvidia-ai-initiative-openai-cyber-attack.html) that Washington is arguing about something else entirely.

“In Washington this is not a debate about open-source vs closed-source, it is a debate about whether or not to tolerate Chinese IP theft,” he said. “Any actions would be focused on Chinese companies, not the open-source ecosystem.”

McGuire also thinks restrictions are likely. They could reach as far as banning API token purchases or stopping US firms hosting Chinese models on their clouds.

## The contradiction nobody is naming

Follow the logic of the founding story to its end.

An American closed model caused the breach. A Chinese open model cleaned it up. American closed models made the cleanup harder by refusing to help.

The alliance built on that sequence has no Chinese members, and campaigns against restrictions on exactly the kind of model that saved the day. Meanwhile Washington may ban it.

Nvidia’s position is coherent on its own terms. It sells chips to everyone, so a plural market suits it, and it says openly that defenders need both closed and open systems working together.

But the argument only lands if the open frontier stays available. Right now the most capable open models are Chinese, and the case for keeping them legal rests on an American company’s embarrassment.

## Get the TNW newsletter

Get the most important tech news in your inbox each week.
