NVIDIA や Microsoft が参加し、オープンソースで AI セキュリティ強化を目指すアライアンス
Linux Foundation の主導により、オープンソースソフトウェアのセキュリティを強化する「Open Secure AI Alliance」が発足し、AI セキュリティにおける透明性と分散型防御の重要性が強調される。
AI深層分析を開く2026年7月28日 23:19
AI深層分析
キーポイント
新アライアンスの発足と目的
Linux Foundation の Akrites イニシアチブや OpenSSF の実績を基盤とし、脆弱性の修正と開示をオープン技術を用いて行う「Open Secure AI Alliance」が設立された。
オープンモデルの防御価値
AI セキュリティにおいて、クローズドなシステムに依存するのではなく、誰でも調査・適応・展開可能なオープンモデルやハルネスが不可欠であると主張している。
Hugging Face 事例による教訓
最近の Hugging Face のセキュリティインシデントで、クローズドな AI ツールが分析を阻害した際、同社がオープンウェイトモデル(GLM 5.2)を用いて防御に成功した実例が示された。
リスク管理の必要性
強力な技術であるオープンモデルも悪用されるリスクがあるが、これはクローズドシステム特有の問題ではなく、高度な AI が展開されるあらゆる場所で管理すべき課題であると指摘している。
重要な引用
The world needs both closed and open models.
When defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most.
編集コメントを表示
編集コメント
AI セキュリティの文脈でオープンソースの価値を再定義する動きであり、特にインシデント対応における「透明性」の重要性が実例を通じて強調されている。業界全体として、クローズドモデルへの過度な依存リスクに対する警鐘と、オープン技術による分散防御の実現可能性を示唆する重要な転換点と言える。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
オープンソースソフトウェアは、世界経済を支える重要な柱です。技術へのアクセス性と可視性を専門家コミュニティに提供することで、クラウドコンピューティング、金融サービス、製造業、通信インフラ、政府機関、そしてインターネットサービスの基盤となっています。
サイバーセキュリティは、オープンソースソフトウェアから最も恩恵を受ける分野の一つです。Open Secure AI Alliance は、Linux Foundation の Akrites イニシアチブおよび OpenSSF コミュニティのリーダーシップに基づき、オープンな技術を活用して脆弱性の修正と開示を進めていきます。
オープンソースがソフトウェアに共通の基盤をもたらしたように、現在、米国とそのパートナー国は AI セキュリティにおいて重要な選択を迫られています。インフラを守るための防御手段を、少数のブラックボックス化したシステム内に閉じ込めるか、それとも、あらゆる防衛者が調査・適応・展開できるオープンなモデルやツールの上に構築するかです。
世界には、クローズドモデルとオープンモデルの両方が必要です。サイバーセキュリティにおいては、オープンモデルとオープンなハルネスが不可欠です。これらは防御能力を民主化し、防御者にとっての透明性を高め、データを保護しながらサイバー防御を可能にし、カスタマイズ可能なローカル制御によって最先端のクローズドモデルを補完します。オープンソースは、単一の障害点を持たない、大規模に分散されたコミュニティ主導かつ自己管理型の防御を実現します。
オープンモデルも強力な技術と同様に、誤用される可能性があります。具体的には、セキュリティ対策の弱体化や、その機能をサイバー攻撃に転用しようとする試みです。しかし、これらのリスクはオープンシステム特有のものではなく、高度な AI が展開されるあらゆる場所で適切に管理されなければなりません。
直近の Hugging Face のセキュリティインシデントは、明確な教訓を突きつけました。すなわち、サイバー防御には、自己防衛のためにオープンで最先端のエージェント型システムが必要だということです。攻撃者と防御者を区別できないクローズド AI ツールが重要なフォレンジック分析をブロックした際、Hugging Face は自社のインフラ上でオープンウェイトの GLM 5.2 モデルを実行し、17,000 件を超えるアクションを分析して侵入を封じ込めました。
この事件は、実務的な真実を示しました。防御側が自社のインフラ上で高度な AI を検査・適応・実行できない場合、スピードが最も求められる瞬間に、対応能力が制約されてしまうのです。
企業や国家には、オープンな最前線の防御ツールと技術が必要です。これにより、重要産業はマルチベンダーのエコシステム全体でセキュリティシステムを構築でき、単一障害点を回避できます。
これが「Open Secure AI Alliance(オープン・セキュアAIアライアンス)」のミッションです。世界中の防御者が、信頼できて制御可能なオープンな最前線のツールを持てるようにすることを目指しています。
クラウドコンピューティング、サイバーセキュリティ、エンタープライズソフトウェア、オープンソース財団、AI 研究の各分野でリーダーシップを発揮する NVIDIA、Adobe、Cadence、Capital One、Cisco、Cloudera、Cloudflare、Cognition、CrowdStrike、Databricks、Dell Technologies、DoorDash、Elastic、HPE、Hugging Face、IBM、LangChain、Linux Foundation、Microsoft、NAVER、NetApp、Nous Research、OpenClaw、Palantir、Palo Alto Networks、Red Hat、Reflection AI、Salesforce、SAP、ServiceNow、Siemens、SK Telecom、Snowflake、SpacexAI、Synopsys、Thinking Machines Lab、TrendAI が、オープン・セキュア AI アライアンス(Open Secure AI Alliance)の創設パートナーとして名を連ねました。このアライアンスは、AI の時代におけるソフトウェアやエージェントを守るため、オープンな技術、手法、ツールを開発し共有する動きです。
一部の意見では、オープンモデルはサイバー攻撃に悪用されたり、ガードレールが取り除かれたりして改造される可能性があるため、本質的に安全ではないと主張されています。これらのリスクは確かに存在しますが、クローズドなシステムであっても消えるわけではありません。単に重み(weights)を非公開にしても、強力な AI を探したり悪用したりしようとする決意ある攻撃者を防ぐことはできません。
守り手に対して、有能なオープンシステムへのアクセスを制限する対応は正しくありません。重要なのは、開放性と強力なセーフガードを組み合わせ、悪意ある misuse(誤用)に対する明確なルールを設け、厳格な評価と迅速な修正を行うことです。
サイバーセキュリティの分野では、社会が依存するシステムをテストし、検証し、強化できる守り手を増やす道こそが、より安全な道です。
守り手には、最前線のクローズドモデルとオープンモデルの両方が必要です。これらが連携することで、任務に適したシステムを選択でき、セキュリティが必要な場所であればいつでも透明性、適応性、主権による制御を利用可能にできます。
オープンな研究がサイバーセキュリティと AI セーフティを強化する
AI エージェントは単なる言語モデルではありません。それは、モデル、ハーンセス(harness)、ガードレールから構築された複雑なシステムです。
真の AI セーフティとセキュリティは、モデルの重みがオープンかクローズドかという点だけでなく、アイデンティティ、権限、ハーンセス、ガードレール、ログ、評価を含むエージェントスタック全体に依存します。オープンなハーンセスやツールがあれば、多くの守り手がこれらの制御を監視・テスト・改善しやすくなります。
NVIDIA は、新しいサイバーセキュリティツールと技術の開発を加速させるため、Open Secure AI Alliance にオープンモデル、モデルの重み、データ、そして新たなエージェントハーンセスの研究貢献を行っています。
新しいオープンソースプロジェクト「NVIDIA Labs Object-Oriented Agent (NOOA)」が GitHub で公開され、エージェントハッチにおける高度な AI セーフティ機能の利用をより容易にしました。NOOA 研究フレームワークは、エージェントの動作をテスト・追跡・監査・ガバナンスしやすくするために、ハッチとモデルの統合を強化します。
アライアンス全体で、貢献者たちはアイデンティティや分離から安全なモデル形式、マルチモデルのスキャン、セキュアなコーディングワークフローに至るまで、エージェント向けのオープンな防御スタックの構築を進めています。
HPE は SPIFFE/SPIRE に貢献しています。これはゼロトラスト・アイデンティティ・フレームワークの標準と手法を策定するもので、AI エージェントやサービスに対して暗号化による検証を行い、許可されたワークロードのみが企業リソースへの通信やアクセスを行えるように保証します。
Hugging Face は、PyTorch 財団に「Safetensors」を提供しました。これは AI モデルの重みを安全に保存するための形式で、透明性を確保し、リモートコード実行が行われないことを保証するものです。
IBM と Red Hat の Lightwell は、デジタル署名されたパッチを通じてオープンソースサプライチェーン全体にセキュリティを拡張しています。
Microsoft の MDASH は、専門的な AI エージェントを編成し、脆弱性の発見から議論、そして実証までを一貫して行うマルチモデル・アジェンシー型スキャンハネスです。
SpaceXAI は、信頼性、透明性、新機能の促進を目的として、ターミナルベースの AI コーディングエージェント「Grok Build」をオープンソース化しました。また、開発者や研究コミュニティを支援するため、Grok シリーズモデルの重み(weights)も今後オープンソース化する計画です。
政策立案者と規制当局への提言
AI の安全性について政策立案者や規制当局が対応に苦慮する中、オープンなモデルやハネス、セキュリティツールを「リスク要因」ではなく、「防御資産」として認識することが極めて重要です。オープンなフロンティア AI システムに対する包括的な制限は、防御能力を弱体化させ、権力や依存関係、脆弱性が一部のクローズドプロバイダーに集中するリスクを生みます。
企業と政府は、過去の世代がオープンソースソフトウェアに投資したように、AI 防衛のための共有オープンインフラ(データセット、評価フレームワーク、攻撃シミュレーター、レッドチーム用ツールなど)への投資を強化すべきです。
私たちが目指すべき未来
AI エージェントの時代は、レジリエンスと共有されたセキュリティを備えたものになり得ます。適切な選択を行うことで、オープンで安全な AI システムは、防御側に必要なツールを提供し、競争を強化し、技術的リーダーシップを拡大するとともに、この画期的な技術の安全性とセキュリティが、誰もがアクセスできる形でオープンに構築されることを保証します。
その未来は、秘密主義こそが安全であるという前提によって守られるものではありません。それは、精査に耐えうるほど堅牢で、改善のために柔軟であり、そして防御者コミュニティ全体を動員するほどオープンなシステムを構築することによって実現されます。
その未来は築く価値があります——Open Secure AI Alliance は、政府、産業界、研究者に対し、AI エラ時代を守るための取り組みに共に参加することを呼びかけます。 詳細はこちら、または興味がある方はこちらから * Open Secure AI Alliance への参加をご検討ください。
原文を表示
Open source software is a critical pillar of the global economy. It underpins cloud computing, financial services, manufacturing, telecommunications, government and internet services by making technology accessible and observable to communities of experts.
Cybersecurity is among the top three beneficiaries of open source software. The Open Secure AI Alliance — building on the leadership of the Linux Foundation’s Akritesinitiative and OpenSSF community work — will work to remediate and disclose vulnerabilities using open technologies.
Just as open source created a shared foundation for software, the United States and its partners now face a choice in AI security: whether the defenses that protect our infrastructure will sit inside a few opaque systems or be built on open models, harnesses and tools that any defender can study, adapt and deploy.
The world needs both closed and open models. For cybersecurity, open models and open harnesses are essential because they democratize defensive capabilities, increase transparency for defenders, enable cyber defense while protecting data, and complement frontier closed models with customizable, localized controls. Open source enables massively distributed community-driven and self-controlled defense – with no single point of failure.
Open models, like any powerful technology, can be misused — including through attempts to weaken safeguards or repurpose capabilities for cyber attacks — but those risks are not unique to open systems, and they must be managed wherever advanced AI is deployed.
The recentHugging Face security incident delivered a clear reminder: cyber defenders need open, frontier agentic systems for self-defense. When closed AI tools — unable to distinguish attackers from defenders — blocked essential forensic analysis, Hugging Face ran the open-weight GLM 5.2 model on its own infrastructure to analyze more than 17,000 actions and contain the intrusion.
That incident showed a practical truth: when defenders cannot inspect, adapt and run advanced AI on their own infrastructure, their ability to respond is constrained at exactly the moment speed matters most. Companies and countries need open frontier defensive tools and techniques so critical industries can build security systems across a multi-vendor ecosystem and avoid single points of failure.
That is the mission of the Open Secure AI Alliance: to ensure defenders everywhere have open, frontier tools they can trust and control.
Leaders across cloud computing, cybersecurity, enterprise software, open source foundations and AI research — including NVIDIA, Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, NAVER, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpacexAI, Synopsys, Thinking Machines Lab and TrendAI are inaugural partners in the Open Secure AI Alliance, a movement to develop and share open technologies, techniques and tools to safeguard software and agents in the age of AI.
Some argue that open models are inherently less safe because they can be misused for cyberattacks or modified to remove guardrails. Those risks are real, but they do not disappear in closed systems, and simply keeping weights closed does not prevent determined attackers from seeking or exploiting powerful AI.
The right response is not to deny defenders access to capable open systems. It is to pair openness with strong safeguards, clear rules against malicious misuse, rigorous evaluation and rapid remediation. In cybersecurity, the safer path is the one that gives more defenders the ability to test, verify and strengthen the systems on which society relies.
Defenders need both frontier closed models and frontier open models, working together, so they can choose the right system for the job and ensure that transparency, adaptation and sovereign control are available wherever security demands them.
Open Research Enhances Cybersecurity and AI Safety
An AI agent isn’t just a language model. It is a complex system built from models, harnesses and guardrails.
Real AI safety and security depend on the full agent stack — identity, permissions, harnesses, guardrails, logs and evaluation — not just on whether model weights are open or closed. Open harnesses and tools make those controls easier for many defenders to inspect, test and improve.
NVIDIA is contributing open models, model weights, data and new agent harness research to the Open Secure AI Alliance to speed the development of new cybersecurity tools and techniques.
The new open source NVIDIA Labs Object-Oriented Agent (NOOA) project is now available on GitHub to make advanced AI safety capabilities more accessible for agent harnesses. The NOOA research framework enables harnesses to better integrate with models to make agent behavior easier to test, trace, audit and govern.
Across the Alliance, contributors are building an open defense stack for agents — from identity and isolation to safe model formats, multi-model scanning and secure coding workflows.
HPE contributes to SPIFFE/SPIRE, which creates zero-trust identity framework standards and methods that can cryptographically verify AI agents and services to ensure only authorized workloads communicate and access enterprise resources.
Hugging Face has offered Safetensors — a safe format to store AI model weights, providing transparency and guarantees of no remote code execution — to the PyTorch Foundation.
IBM and Red Hat’s Lightwell extends security across the open source supply chain with digitally signed patches.
Microsoft’s MDASH multi-model agentic scanning harness orchestrates specialized AI agents to discover, debate and prove exploitable bugs.
SpaceXAI has open sourced the Grok Build terminal-based AI coding agent to promote trust, transparency and new capabilities, and plans to open source the weights of the Grok line of models to support the developer and research communities.
A Call to Policymakers and Regulators
As policymakers and regulators grapple with AI safety, it will be crucial to recognize open models, harnesses and security tooling as defensive assets, not liabilities, in AI and cybersecurity policy. Blanket restrictions on open frontier AI systems would weaken defensive capacity and risk concentrating power, dependence and vulnerability in a few closed providers.
Companies and governments should invest in shared open infrastructure for AI defense — datasets, evaluation frameworks, attack simulators and red-teaming tools — much as past generations invested in open source software.
The Future We Should Build
The age of AI agents can be one of resilience and shared security. With the right choices, open secure AI systems can give defenders the tools they need, strengthen competition, extend technological leadership and ensure that the safety and security of this extraordinary technology are built in the open for everyone.
That future will not be secured by assuming that secrecy alone is safety. It will be secured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved and open enough to mobilize the full community of defenders.
That future is worth building — and the Open Secure AI Alliance invites governments, industry and researchers to join in the work of defending the AI era together.
Learn more or share interest* **in joining the Open Secure AI Alliance.*
AI算出
主要ニュースainew評価高い
AI セキュリティとオープンソースの重要性に関する重要なアライアンス設立を発表しており、新規性と主題の関連性は高いが、日本固有の情報や企業名は限定的である。
6つの評価軸を見る
- AI関連度
- 100
- 情報源の信頼性
- 50
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 100
- 日本での有用性
- 25
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み