The AI conversation has been dominated by model builders for the past two years. OpenAI, Anthropic, Google, and Meta have fought for headlines with ever-larger models and ever-more-powerful hardware. Yet as AI moves from experimental technology into production infrastructure, another challenge has become impossible to ignore: security.
That is the thinking behind the newly-launched Open Secure AI Alliance (OSAA), led by NVIDIA and supported by more than 50 technology companies. Rather than treating AI security as something that can be solved by individual vendors, the Alliance argues that protecting AI systems will require an open ecosystem of shared tools, shared standards, and shared expertise.
For the Cloud, hosting, and infrastructure industry, that makes this far more than another AI announcement. It is recognition that the companies responsible for running digital infrastructure will also play a central role in securing the growing population of AI workloads.
AI infrastructure is becoming critical infrastructure
In announcing the Alliance, NVIDIA said its goal is to develop and share “open tools that promote responsible use of and trust in AI.” It also makes a point that will sound familiar to anyone responsible for production infrastructure:
“Security through obscurity is not security.”
(If you had €1 for every time this has come up during a conversation at CloudFest, the next round would be on you.)
Instead, the Alliance argues that openness enables faster identification of vulnerabilities, stronger defensive tools, and greater resilience across the entire AI ecosystem. The rather straightforward idea at play here is that when researchers, vendors, and operators collaborate openly, security improves more quickly than when organizations work behind closed doors.
That philosophy is hardly revolutionary for the Cloud industry. Open source software already underpins much of the modern internet, from Linux and Kubernetes to OpenTelemetry and Prometheus. These technologies became industry standards precisely because thousands of organizations—as well as many awesomely geeky individuals—contributed improvements, identified weaknesses, and strengthened them together. The Open Secure AI Alliance aims to bring that same collaborative approach to securing AI.
This isn’t just about model developers
Perhaps the most striking aspect of the Alliance is its membership. While AI developers are naturally involved, many of the participating organizations are better known for infrastructure, enterprise platforms, networking, and cybersecurity than for building foundation models.
The list includes familiar names familiar to the CloudFest community, such as NVIDIA, Hewlett Packard Enterprise, Cisco, IBM, Microsoft, Oracle, Dell Technologies, Red Hat, Palo Alto Networks, CrowdStrike, Trend Micro, ServiceNow, and the Linux Foundation.
That mix is significant because it reflects where AI is heading. Enterprises are no longer experimenting with isolated AI applications; they are integrating AI into production environments where availability, governance, compliance, and security matter just as much as model performance. As a result, the organizations operating infrastructure are becoming just as important to AI adoption as those developing the models themselves.
Open-weight AI is changing the conversation
Running alongside the launch of the Alliance is a broader debate around open-weight AI models. Unlike proprietary services that are only accessible via APIs, open-weight models make their trained weights publicly available, allowing organizations to deploy, inspect, and adapt them within their own environments.
Supporters argue that this approach delivers several advantages. Organizations gain greater flexibility over where workloads run, researchers can examine models for vulnerabilities, and infrastructure providers can build secure, sovereign AI platforms without being tied to a single commercial ecosystem.
Microsoft recently reinforced that argument in an open letter supporting open-weight AI, saying these models can “expand access, strengthen competition, improve security, and help sustain American AI leadership.” The company argues that wider access to AI technology encourages innovation while giving organizations more options for deploying AI securely and responsibly. That letter was also signed by dozens of leading providers.
List of Microsoft signatories
1789 Capital • A.Team • Adam • Adaption • Agentastic • Agno • AI Native Foundation • AI Tinkerers • AI21 • alphaXiv • Amazon • AMD • American Innovators Network • AMP • Amplitude • Anaconda • Andreessen Horowitz • AnythingLLM • Applied Compute • Arcee AI • Arena • ARK Invest • Armada • Asana • Assembled • assistant-ui • Atlassian • Atomic Chat • Atreides Management • Autohand AI • Automattic • Baseten • Black Forest Labs • BLACKBOX AI • Block • Bolt • Box • Bria • Browserbase • Cadence • Camber • Capy • Cinder • Ciroos • Cisco • Cline • CloudBees • Cloudflare • Cogensec • Cognition • Cohere • Cohesity • Coinbase • Comcast • Command Code • Complify AI • Composio • Core Automation • CoreWeave • Corridor • Corvic AI • Criteria Corp • CrowdStrike • Crusoe • DART • Databricks • DataRobot • DatologyAI • Daytona • Defense Unicorns • Dell Technologies • depthfirst • DigitalOcean • Disruptive • Docker • DoorDash • Dreamcore • Dropbox • E2B • EdgeRunner • Edgescale AI • Elastic • EleutherAI • Elorian AI • Emergence Capital • Emergent • Endex • EOX Vantage • Exia Labs • EXO • Factory • Fastino Labs • Fastn • Featherless • Fireworks AI • Fleet AI • FriendliAI • General Catalyst • Genspark • GitHub • GitLab • Glean • Glemad • GMI Cloud • GoDaddy • Goodfire • Google • GPU MODE • Groq • Harness • Hugging Face • humans& • Hyde • Hydra Host • Hyland • Hyperbolic • IBM • Inferact • InferX • Infinity • Intangible • Intel • Interconnects AI • Isomer • Jasper AI • Keycard • Kindo • Kong • Kyndryl • Lambda • LangChain • Latitude.sh • Lenovo • Letta • Lightning AI • LightSeek Foundation • Liquid AI • LithosAI • LM Studio • LMSYS • Logical Intelligence • Makora • Mariana Minerals • Megaport • Megaton AI • Mem0 • Merge • Meta • Metabase • microagi • Microsoft • Mistral • Modal • Morph • Mozilla • Nebius • Neon • NeoSigma • Netlify • NimbleBrain • Noah Labs • Nokia • Nolla Health • Notion • Nous Research • NVIDIA • Ollama • Omnara • Open Athena • Open Compute Project Foundation • Open WebUI • OpenAI • OpenClaw • OpenCode • Osmantic • Oumi • Owlery • Palantir • Palo Alto Networks • Paragon • Peregrine • Periodic Labs • Perplexity • Pinterest • Plastic Labs • PlayerZero • Poolside • Postman • Prime Intellect • PrismML • Probabl • Pulse AI • Rackspace Technology • RadixArk • Red Hat • Redblock • RedCloud • Redis • Reducto • Reflection • Regal • Rehearsals • Reka • Replit • Resemble AI • Ricursive Intelligence • RightNow AI • Rillet • Rogo • Runway • Sakana AI • SambaNova • San Francisco Tooling Company • SAP • Sapiom • Scale • Scarf • Sculptor AI • Seekr • SerpApi • ServiceNow • SF Tensor • Siemens • SkyPilot • Snowflake • Snyk • Socket • Sonar • SpaceX • Spotify • Stack Overflow • Stacksync • Sully.ai • Superhuman • Supermemory • Superserve • Sycamore • Synopsys • Telnyx • TensorWave • TestMu AI • The Linux Foundation • TinyFish • Together AI • Tolmo • TrainLoop • Trajectory • TrendAI • Uber • Uniphore • Unsloth • Unusual Ventures • Upbound • Uplevyl • Venice • Vercel • Verda • VESSL AI • Vocara • Webflow • Willow • WOMBO • WordPress.org • Workday • WRITER • Wrynx • xpander.ai • Y Combinator • Zendesk • Zeroset • Zoom • Zscaler
Industry observers have also noted that the Alliance reflects a growing movement among technology companies to promote open-weight AI as an alternative to increasingly closed proprietary ecosystems. Rather than concentrating AI capability within a handful of providers, supporters believe openness creates a healthier and more resilient technology landscape while strengthening defensive capabilities across the industry.
Why this matters to Cloud providers
For Cloud providers and hosting companies, the implications go well beyond offering GPU capacity. AI is rapidly becoming another enterprise workload, bringing with it familiar customer and client expectations around resilience, compliance, governance and operational visibility.
Customers increasingly want to deploy AI where it makes the most sense for their business. That may mean running inference close to users to reduce latency, keeping sensitive workloads within sovereign environments, or hosting models within private infrastructure to satisfy regulatory requirements. Delivering those capabilities demands far more than raw compute power. It requires secure platforms, comprehensive monitoring, robust identity management, and the operational expertise to keep complex AI environments running reliably. It’s not a sprint, and it’s not even a marathon… it’s an ultra-marathon!
This is precisely where the Cloud industry has decades of experience and irreplaceable insights. Hosting providers have spent years building secure multi-tenant platforms, automating infrastructure management and helping customers navigate increasingly complex regulatory requirements. As AI workloads become mainstream, those capabilities become valuable differentiators rather than background services.
A shift in where value is created
The launch of the Open Secure AI Alliance also reflects a subtle but important shift in the AI market. Until now, much of the industry’s attention has focused on who can build the most capable models. Increasingly, however, competitive advantage may come from enabling organizations to deploy those models securely, efficiently and compliantly.
That creates significant opportunities for Cloud providers, managed service providers and infrastructure specialists. Customers are looking for trusted partners who can help them build secure AI environments, manage governance, integrate AI into existing platforms and demonstrate compliance with an expanding set of regulations. Those are operational challenges rather than research challenges, and they align closely with the expertise already found throughout the CloudFest community.
The Open Secure AI Alliance is therefore more than another industry consortium. It acknowledges that the future of AI will depend not only on breakthroughs in model development, but also on the infrastructure that supports them. As AI becomes another critical workload alongside databases, applications and storage, the organizations that know how to operate secure, resilient infrastructure will become indispensable to its success.
For an industry that has quietly powered the internet for decades, that could be one of the biggest opportunities of the AI era.
Sign up for the CloudFest newsletter (below) for more insight, plus event news and free registration.
