
NVIDIA Forms Open Secure AI Alliance After Hugging Face Breach
NVIDIA is bringing more than a hundred technology companies into a shared AI security effort as Microsoft, C1 and Dynatrace introduce new controls for autonomous agents.
Today in 90 Seconds
-
NVIDIA launched the Open Secure AI Alliance, bringing a broad coalition together around shared tools for securing AI systems and agents.
-
Microsoft unveiled Project Perception, coordinating red, blue and green security agents that continuously identify, investigate and remediate risk.
-
C1 launched Shadow AI Discovery to find unapproved agents, MCP servers, API credentials and the systems those agents can access.
-
Dynatrace introduced autonomous SRE agents that can investigate and remediate incidents while preserving auditability and human oversight.
-
Satya Nadella urged enterprises to retain their own AI context, memory and metadata rather than surrendering the entire operating layer to one model provider.
The Signal
Agent Security Is Becoming Shared Infrastructure
July 26 ended with a demand for evidence from the OpenAI and Hugging Face incident.
July 27 produced an industry response.
NVIDIA launched the Open Secure AI Alliance, a broad coalition spanning cloud infrastructure, cybersecurity, enterprise software and AI research. NVIDIA explicitly connected the effort to the Hugging Face incident and argued that defenders need systems they can inspect, adapt and operate themselves.
At the same time, Microsoft introduced an agentic security architecture built around coordinated defensive agents. C1 moved unauthorized agents into enterprise identity governance. Dynatrace added autonomous remediation with auditable action records.
The market is moving beyond asking how to make an individual agent safer.
Security is becoming an infrastructure layer surrounding the complete agent system.
Tesseris Read
A secure model does not automatically create a secure agent.
The operational system also contains identity, credentials, permissions, memory, tools, harnesses, policies, execution records and external services.
NVIDIA now describes agent security in similarly system level terms, explicitly naming identity, permissions, harnesses, guardrails, logs and evaluation as parts of the security stack.
For Tesseris, the important requirement is that these controls remain connected.
An agent should be identifiable before execution, constrained by delegated authority during execution, independently observable while acting, and accountable through evidence afterward.
The security perimeter is expanding from the model to the complete execution chain.
1. NVIDIA Creates the Open Secure AI Alliance
Source: NVIDIA Open Secure AI Alliance announcement
NVIDIA announced the Open Secure AI Alliance with participants spanning companies such as Microsoft, Amazon, Hugging Face, CrowdStrike, Cloudflare, Cisco, IBM, Okta, Salesforce, ServiceNow and Visa.
The alliance plans to develop and share open technologies, techniques and tools for securing software and AI agents. NVIDIA says the Hugging Face incident demonstrated why defenders need systems they can inspect and operate independently. Hugging Face reportedly used an open model on its own infrastructure to analyze more than 17,000 actions during its response.
The notable shift is organizational.
Agent security is beginning to move from proprietary controls inside individual companies toward shared defensive infrastructure.
2. Microsoft Builds a Security System Around Teams of Agents
Source: Microsoft Project Perception announcement
Microsoft introduced Project Perception, an agentic cybersecurity system designed to continuously observe risk, reason over enterprise context and take defensive action.
The architecture coordinates three types of specialized agents. Red agents search for paths to compromise. Blue agents investigate threats and evaluate risk. Green agents apply corrective actions and strengthen defenses.
Microsoft also separates the broader stack into signals, security context, models, a coordinating harness, agents and actuators. Project Perception is scheduled to enter public preview on August 3.
This matters because security automation is moving from isolated assistants toward coordinated autonomous systems capable of changing enterprise environments themselves.
3. C1 Starts Searching for Agents Nobody Approved
Source: C1 Shadow AI Discovery announcement
C1 launched Shadow AI Discovery to identify autonomous systems operating outside formal enterprise governance.
The system scans cloud and endpoint environments for unowned agents, MCP servers, API access, long lived credentials, local configurations and exposed tokens. Discovered agents can then be assigned an owner, reviewed, approved and eventually removed through the same lifecycle used for other enterprise identities.
This exposes a problem that becomes more serious as agent adoption spreads.
An organization cannot govern an agent it does not know exists.
Agent discovery is therefore becoming a prerequisite for identity, authorization and accountability.
4. Dynatrace Gives Operations Agents Permission to Remediate
Source: Dynatrace autonomous operations announcement
Dynatrace expanded its intelligence platform with autonomous agents for incident investigation and remediation.
Its Cloud SRE Agent can coordinate remediation across AWS, Microsoft Azure and Google Cloud, while Dynatrace says actions remain grounded in real time system context and generate a single auditable record. The company also emphasizes human oversight for workflows requiring intervention or approval.
This crosses an important operational boundary.
Observability software traditionally explained what happened.
Agentic observability can now change the system in response.
Once an agent gains remediation authority, evidence of why the action occurred and what state changed becomes as important as the diagnostic insight that preceded it.
5. Satya Nadella Warns Enterprises Not to Outsource the Entire AI Layer
Source: TechCrunch interview coverage
Microsoft CEO Satya Nadella argued that enterprises should preserve control over the infrastructure surrounding AI models rather than depending entirely on one model provider.
He specifically emphasized retaining usage metadata and separating the model from the harness, context and memory so organizations can switch among different models without losing their operating state.
The commercial motivation is worth acknowledging because Microsoft sells infrastructure that benefits from this architecture.
But the design principle is important independently of Microsoft.
Enterprise agent identity, memory and execution history should remain durable even when the underlying model changes.
Since Yesterday
Yesterday's watchlist: 1 moved, 2 remain open.
July 26 asked whether agent platforms would separate identity, authority and action permissions more explicitly.
That question moved today.
C1 is pulling previously invisible agents into identity governance, while Microsoft and Dynatrace are making operating context, action boundaries and execution records more explicit.
The other two questions remain unresolved.
OpenAI had not publicly released the requested Hugging Face agent traces by July 27, and no major new reporting regime specifically for autonomous third party agent incidents emerged during the day's coverage.
The progression is becoming clear:
first observe the incident, then preserve the evidence, then build infrastructure designed to prevent the next one.
Agent Economy Pulse
Agent Security: Critical, unchanged. The Hugging Face incident is now triggering coordinated defensive infrastructure rather than isolated company responses.
Runtime Governance: Accelerating, unchanged. Microsoft and Dynatrace are moving agent control directly into live production operations.
Execution Evidence: Accelerating, unchanged. Audit records and traceability are increasingly being designed alongside autonomous action rather than added after incidents.
Agent Identity: Accelerating, upgraded from Building. C1 is treating discovered agents, MCP systems and credentials as governed enterprise identities.
Trust and Security: Accelerating, upgraded from Building. NVIDIA's alliance moves agent security toward a shared ecosystem problem.
What We Are Watching Tomorrow
Question 1: Will the Open Secure AI Alliance define concrete standards for agent identity, permissions, logs or evaluation?
Question 2: Will enterprise security platforms begin requiring action specific authorization before autonomous remediation?
Question 3: Will agent discovery become a formal part of identity governance rather than a separate security product category?
If those developments continue, the market will be moving from securing individual agents toward governing an entire machine workforce.
Research Note and Sources
The Open Secure AI Alliance structure, membership and Hugging Face response details come from NVIDIA's July 27 announcement. Project Perception capabilities and benchmark figures are Microsoft reported, with public preview scheduled for August 3. C1 and Dynatrace capabilities are vendor reported product claims. Satya Nadella's remarks were reported from his CNN interview by TechCrunch and should be read alongside Microsoft's commercial interest in enterprise AI infrastructure.
Reported facts and Tesseris interpretation are kept separate.



