The Linux Foundation is taking a more active role in AI security by bringing the Open Secure AI Alliance under its neutral governance, creating an open-source effort focused on protecting AI models, software and autonomous agents. The alliance, originally established by NVIDIA and other industry participants, will develop shared defensive tools and incident intelligence as enterprises move AI systems from experimentation into production.
AI security is entering a new phase. As enterprises deploy large language models and AI agents that can access data, invoke tools and execute workflows, protecting the model alone is no longer enough.
The Linux Foundation believes the industry needs an open security layer spanning the entire AI stack. Its latest move is to provide a neutral home for the Open Secure AI Alliance, an initiative originally established by NVIDIA and enterprise partners to develop open technologies for defending AI systems and software agents.
The alliance will focus on two related objectives: building an open defensive stack and creating mechanisms for organizations to collectively learn from AI security incidents. The move brings the effort alongside existing Linux Foundation security communities, including the Open Source Security Foundation, or OpenSSF.
The timing reflects a rapidly expanding AI security market. Gartner forecasts that spending on products and services designed specifically to secure AI will reach $4.8 billion in 2027, up 68.7% from 2026. The research firm expects the market to reach nearly $7.7 billion in 2028.
Gartner also predicts that more than half of successful cyberattacks against AI agents will exploit access-control weaknesses and prompt injection by 2029. That reflects a fundamental change in the security model: an AI agent is not simply another application endpoint. It may have credentials, access to enterprise data and permission to take actions on behalf of users.
The Open Secure AI Alliance is organizing its security architecture around that broader reality. Its framework extends from model and inference security through agent context and harnesses, identity and policy, enforcement, containment and recovery, and the underlying trusted infrastructure.
That approach is increasingly relevant as organizations adopt agentic AI. McKinsey says autonomous agents introduce new vulnerabilities because they can operate with varying levels of privilege and make decisions without direct human oversight. In a 2025 survey cited by the firm, 80% of organizations reported encountering risky behavior from AI agents, including unauthorized system access and data exposure.
The alliance’s strategy is therefore less about creating another standalone AI security product and more about establishing reusable defensive infrastructure. Open tools, models, evaluations and reference architectures could allow security teams to inspect how protections work, adapt them to their environments and deploy them without being tied to a particular AI vendor.
That vendor-neutral position is important. The AI infrastructure market is increasingly dominated by large technology ecosystems, with NVIDIA, Microsoft, Google, Amazon and other vendors controlling significant portions of the hardware, cloud, model and software stack. Security controls that depend too heavily on one provider can become difficult to move when organizations change models or infrastructure.
Open standards could provide a counterweight.
One of the alliance’s most notable initiatives is the Shared AI Findings Exchange, or SAFE. The proposal is designed to allow organizations to confidentially submit and analyze AI security incidents and near misses, notify affected parties and turn recurring failures into evidence-based controls.
The concept resembles collective-defense models already used in cybersecurity, where organizations share threat intelligence so that one company’s discovery can become another organization’s protection. Applied to AI, the model could help the industry respond more quickly to new prompt-injection techniques, agent vulnerabilities, model weaknesses and insecure configurations.
The alliance is asking developers, researchers, defenders and organizations to comment on the SAFE proposal, with the current contribution period running through September 21.
The Linux Foundation’s involvement could give the project a broader constituency than it might have had under a single technology vendor. Its open-source communities already bring together companies, researchers and government organizations around infrastructure and security projects.
Still, neutrality does not automatically guarantee adoption. AI security is fragmented across application security, identity, data protection, governance, runtime monitoring and infrastructure security. The alliance will need to turn its principles into tools and standards that enterprises can actually deploy and measure.
That challenge is becoming more urgent as AI spending accelerates. Gartner expects worldwide AI spending to reach $2.52 trillion in 2026, with AI cybersecurity spending projected at $51.3 billion and AI infrastructure at more than $1.43 trillion.
For enterprises, the security implications extend beyond protecting confidential information. AI agents can increasingly act inside business systems, creating new questions around authorization, accountability, observability and recovery. McKinsey expects the share of cybersecurity budgets allocated to agentic AI solutions to rise substantially as organizations adapt their identity, governance and security operations to machine-driven activity.
The Linux Foundation’s decision to host the Open Secure AI Alliance is consequently less about another industry consortium and more about where AI security infrastructure should live.
If AI agents are going to become a common enterprise computing layer, their defenses will need to be portable, inspectable and capable of evolving as quickly as the systems they protect. The alliance is betting that open collaboration can provide that foundation.
Market Landscape
AI security is rapidly becoming its own technology category. Gartner forecasts the market for securing AI will reach $4.8 billion in 2027, representing 68.7% growth from 2026, with AI application security, usage controls, governance platforms and AI gateways among the major segments.
The shift is being driven by the move from conventional generative AI applications toward agentic systems. AI agents can access enterprise resources and execute tasks, creating security concerns around identity, permissions, prompt injection, data leakage and autonomous decision-making.
The competitive landscape includes cybersecurity vendors, cloud providers, AI platform companies and open-source communities. NVIDIA, Microsoft, Google and Amazon are developing AI infrastructure and security capabilities, while organizations such as the Linux Foundation and OpenSSF provide venues for open standards and collaborative security development.
The Open Secure AI Alliance is positioning itself at the intersection of these markets by focusing on open defensive infrastructure rather than a proprietary security product.
Top Insights
- The Linux Foundation is giving the Open Secure AI Alliance a neutral governance model for developing open AI security tools and standards.
- SAFE aims to turn confidential incident and near-miss data into shared, evidence-based controls for the broader AI ecosystem.
- AI agents create security challenges beyond model safety, including identity, permissions, tool access, monitoring, enforcement and recovery.
- Gartner expects the market for securing AI to reach $4.8 billion in 2027 as enterprises adopt specialized AI security controls.
- The alliance’s success will depend on whether open security standards translate into deployable tools that enterprises can use across vendors and infrastructures.
Power Tomorrow’s Intelligence — Build It with TechEdgeAI











