cd /news/ai-safety/databricks-joins-the-open-secure-ai-… · home topics ai-safety article
[ARTICLE · art-86318] src=databricks.com ↗ pub= topic=ai-safety verified=true sentiment=↑ positive

Databricks joins the Open Secure AI Alliance to advance AI safety and security

Databricks has joined the Open Secure AI Alliance as a founding member alongside NVIDIA and more than 75 organizations to advance AI safety and security through open frameworks. The alliance aims to share open models, harnesses, and tooling to secure AI systems and strengthen cyber defense. Databricks contributes Omnigent, an open-source meta-harness under Apache 2.0, which supports 13+ harnesses and enforces policies, spend caps, and sandbox isolation.

read6 min views1 publishedAug 4, 2026
Databricks joins the Open Secure AI Alliance to advance AI safety and security
Image: Databricks Blog
From open models to open agent harnesses: Databricks brings open code, community frameworks, and a concrete architecture to AI security

by [Katie Cummiskey](/blog/author/katie-cummiskey), [Maria Pere-Perez](/blog/author/maria-pere-perez), [Arun Pamulapati](/blog/author/arun-pamulapati) and [Nishith Sinha](/blog/author/nishith-sinha)

Databricks is a sponsor at Black Hat USA 2026 this week. Find us at Booths #5106 / #2167, and read how our acquisition of Panther accelerates the Security Lakehouse era.

As AI systems grow more capable and autonomous, two challenges are converging: securing AI systems themselves against new classes of attack, and using AI to strengthen cyber defense. Both require openness because critical security intelligence locked inside a small number of closed systems leaves the broader ecosystem exposed. Databricks supports both mission sides: open frameworks for securing AI systems, and open data via Lakewatch, the Open Security Lakehouse powering agentic threat detection and response at scale.

That's why Databricks is proud to be a founding member of the Open Secure AI Alliance, alongside NVIDIA and other industry leaders. The alliance is built on a simple but powerful premise: AI safety and security research should be shared openly, and the tools it produces should be built on open systems. That work spans AI safety, AI security, and AI-enabled cyber defense, strengthening enterprises, software, and critical systems worldwide. Members are contributing into the open: open models, model weights, open harnesses, open tooling, and the learnings behind them, to accelerate the development of new cybersecurity tools and techniques.

An AI agent isn't just a model. It's a complex system built from models, harnesses, and guardrails that govern what the agent is allowed to do. While much attention has focused on securing open-weight models within enterprise boundaries, model weights are only one layer. Security in the agentic era requires an open execution stack: from the runtime and guardrails underneath, to the harness that orchestrates agents and their tools, to the frameworks that define risks and controls, to the governance layer that ensures enterprise security, auditability and accountability.

Open systems allow the broadest community of defenders to study, test, and strengthen every component of this stack. The result is trust built on assurances, visibility, evidence, participation, and choice.

The alliance spans more than 75 organizations across chips, models, security, and infrastructure. NVIDIA contributes accelerated computing and open AI infrastructure. Databricks brings governed data, model and agent capabilities, and open tools and frameworks for security, governance, red teaming, and cyber defense.

Together with contributions from across the alliance, this work helps strengthen the full agent stack.

The Open Secure AI Alliance advocates for open models, harnesses, and guardrails so defenders can inspect, audit, and govern agent behavior across the full AI stack. Omnigent** **(Apache 2.0) is Databricks' answer to this call, an open-source meta-harness. Omnigent gives developers choice of harness and model, allowing composition and secure sharing, while enforcing policies, spend caps, and sandbox isolation across 13+ harnesses, both open and closed.

Omnigent's contextual policies enable agent behavior governance by tracking session state, blocking slow-burn attacks, and enforcing intent-based authorization. These are exactly the kinds of open, inspectable controls the alliance envisions.

Omnigent is designed to support NVIDIA OpenShell as a governance backend, pairing policy controls with kernel-level isolation for layered, auditable protection from agent authorization through host execution.

The DASF 3.0 catalogs 97 technical security risks across 13 components and maps them to 73 mitigation controls, all cross-referenced to MITRE ATLAS, OWASP, NIST, AIUC-1, HITRUST, ISO and CSA. Released under CC BY-SA 4.0, version 3.0 introduces dedicated coverage for Agentic AI threats (including memory poisoning, goal manipulation, and insecure MCP connections), providing defenders with an open, vendor-agnostic blueprint to move from risk identification to mitigation.

Because DASF connects risk taxonomy to enforceable, vendor-agnostic controls, it gives defenders a concrete path from "named risk" to "deployed mitigation." It offers a common taxonomy for agentic threats and mitigations available to any organization in the community.

The DAGF defines who is accountable and how the enterprise manages it. This framework outlines five pillars for building a responsible and resilient AI program, offering practical insights for decision-making and execution. It addresses core areas, such as AI governance, ethical compliance, risk management, and operational oversight. This helps manage AI programs transparently, securely, and effectively while fostering collaboration across people, processes and technology. In the context of the alliance, DAGF helps enterprises govern how NVIDIA's accelerated computing and AI infrastructure is selected, deployed, and managed, and ensures that open technology is adopted responsibly at scale. Released under the Creative Commons Attribution-ShareAlike 4.0 International License,

BlackIce is Databricks' open-source, containerized red-teaming toolkit. It bundles 14 widely used AI security tools into a single reproducible environment, mapped to MITRE ATLAS and DASF, so a security team can test a system against prompt injection, data leakage, and supply-chain attacks without wiring up each tool by hand.

This lowers the bar for AI red teaming. Standing up 14 tools individually takes time and deep expertise, which puts serious adversarial testing out of reach for most teams. With over 6,000 downloads to date, it is already in the hands of teams that could not have assembled these tools on their own.

On the AI-enabled cyber defense side of the alliance's mission, our commitment to openness extends beyond frameworks. Databricks pioneered the Security Lakehouse, an open, governed architecture that unifies security, IT, and business data so defenders can run detection, investigation, and response at petabyte scale.

With Lakewatch, Databricks’ Open Security Lakehouse, security teams can deploy AI agents that actively triage alerts, conduct threat hunts, and refine detection logic, all on top of open data formats that prevent vendor lock-in. This is the same philosophy that drives the Open Secure AI Alliance: defenders should own their data, their tools, and their intelligence.

The governance foundation for that architecture is Unity Catalog, which Databricks open-sourced under Apache 2.0 and donated to the Linux Foundation. The catalog is the layer that decides which agent can reach which data, model, or tool, and enforces it. Leaving that layer proprietary while everything above it is open would put the most security-critical control point beyond inspection. With an open catalog, meaning open APIs, open table formats, and an open implementation, defenders can audit and extend the enforcement point itself, and security data stays portable across engines rather than locked to one vendor's control plane.

Our commitment to open security builds on a deep open-source heritage that goes back to our founding. Apache Spark,

The Open Secure AI Alliance is a movement to develop and share relevant AI safety and security research transparently. Over time, the alliance will produce a growing body of practical, open capabilities that organizations can inspect, adopt, and build on.

We're excited to stand alongside NVIDIA and the broader alliance in this mission and to continue making open code, open frameworks, and open research available to the community as we secure the agentic era together.

Learn more about Lakewatch, the Open Security Lakehouse and how Databricks is redefining security operations for the agentic era.

Get started with Omnigent to run the open agent meta-harness, its contextual policies, and sandbox isolation in your own environment.

Explore the Databricks AI Security Framework (DASF) 3.0 to understand the risks and controls for securing your AI systems.

Download the Databricks AI Governance Framework (DAGF) to learn about accountability and oversight across your AI program.

Check out our BlackIce GitHub Repo to learn more about the integrated tools, find examples for running them with Databricks-hosted models, and access all Docker build artifacts.

Subscribe to our blog and get the latest posts delivered to your inbox.

── more in #ai-safety 4 stories · sorted by recency
── more on @databricks 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/databricks-joins-the…] indexed:0 read:6min 2026-08-04 ·