What the Open Secure AI Alliance Means for Enterprise AI

By

Leah Weiss

|

July 28, 2026

This week, NVIDIA and more than thirty companies, including Microsoft, Databricks, Snowflake, IBM, Palo Alto Networks, and the Linux Foundation, announced the Open Secure AI Alliance: a shared effort to build open tools for securing AI agents.

It is a genuinely important announcement, and one line in it deserves more attention than the model debate that will dominate the coverage. The alliance states that real AI safety and security depend on the full agent stack, not just on whether model weights are open or closed.

That is the concession the enterprise AI conversation has needed for two years. The model is not where trust comes from. Trust comes from the layers around it.

What the alliance is building

Look at the contributions, and a stack takes shape.

Zero-trust identity frameworks that cryptographically verify agents, so only authorized workloads touch enterprise resources. Safe formats for storing model weights. Digitally signed patches across the open source supply chain. Multi-model scanning harnesses that discover and prove exploitable bugs. Open-sourced coding agents and, soon, open model weights.

Identity. Weights. Code. Harness. Every layer of how an agent runs is getting hardened, in the open, by the companies best positioned to do it.

This is the right work. We are glad it is happening, and several of these companies are partners we build alongside every day.

But walk through that stack again and ask a different question: which layer governs what the agent knows?

Article content

What the alliance is building

Look at the contributions, and a stack takes shape.

Zero-trust identity frameworks that cryptographically verify agents, so only authorized workloads touch enterprise resources. Safe formats for storing model weights. Digitally signed patches across the open source supply chain. Multi-model scanning harnesses that discover and prove exploitable bugs. Open-sourced coding agents and, soon, open model weights.

Identity. Weights. Code. Harness. Every layer of how an agent runs is getting hardened, in the open, by the companies best positioned to do it.

This is the right work. We are glad it is happening, and several of these companies are partners we build alongside every day.

But walk through that stack again and ask a different question: which layer governs what the agent knows?

The perfectly authenticated wrong answer

An enterprise can adopt everything the alliance ships and still face the failure mode that actually stalls AI programs.

Picture an agent that passes every control. Its identity is cryptographically verified. Its weights are stored safely. Its code is signed. Its harness is audited. A CFO asks it for net revenue retention last quarter.

There are three definitions of revenue across the ERP, the warehouse, and the CRM. Two dashboards disagree on NRR. No governed definition exists anywhere. The agent picks one, confidently, and answers.

That is a perfectly authenticated wrong answer. Every security layer worked. The number is still indefensible.

And the access problem is worse than the accuracy problem. A person who has been wrongly granted access to a sensitive dataset will probably never open it. An agent will, at machine speed, with a valid credential, because nothing in its context tells it otherwise. Identity controls verify who the agent is. They say nothing about what it should know, which definitions it should trust, or which data it should never touch for a given question.

Knowledge is a security surface. It is the one layer the open defense stack does not yet cover.

Multi-model makes context the load-bearing layer

There is a second idea in the announcement worth taking seriously. The alliance argues that defenders need closed and open models working together, choosing the right system for each job.

Multi-model is now the official industry posture, and it quietly raises the stakes for context. If your business logic lives inside one vendor's model, through fine-tuning or accumulated prompt engineering, you cannot route freely between models. The moment enterprises run a mix of frontier APIs and open weights on their own infrastructure, business context has to live outside every model, in a layer all of them share.

That layer is where definitions, entities, relationships, lineage, and access policies belong. Build it once, governed and versioned, and every model you route to reasons from the same source of truth. Skip it, and every new model you adopt re-learns your business from raw tables, wrongly, in its own way.

Article content

The missing layer of the open defense stack

The agent stack the alliance describes is identity, permissions, harnesses, guardrails, logs, and evaluation. We would add one: governed context.

Metrics with owners. Entities with resolved definitions. Lineage that explains every answer. Access policies that travel with the data, so an agent's knowledge is scoped as deliberately as its credentials. Human approval on every change to what the system believes, hardened into a versioned, auditable graph.

This is what we build at Preql, and it is why we read this announcement as validation rather than competition. The industry has agreed that securing AI means securing the full stack around the model. The stack they described secures how agents run. Governed context secures what agents know.

An agent with verified identity and ungoverned knowledge is still a liability. The age of AI agents will be secured by both.

‍