Nvidia、Palantirら37社がオープンウェイトAIのサイバー脅威対策へ連携
本文の状態
日本語全文を表示中
詳細モードで約11分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The New Stack AI
Nvidia, Palantir, Hugging Face など主要 37 社が「Open Secure AI Alliance」を設立し、オープンウェイトモデルの脆弱性特定とパッチ適用を迅速化する技術・ツールの開発に着手する。
AI深層分析を開く2026年8月3日 23:11
AI深層分析
キーポイント
業界大手による新アライアンス結成
Nvidia, Palantir, Hugging Face など主要 37 社が「Open Secure AI Alliance」を設立し、オープンウェイトモデルの脆弱性特定とパッチ適用を迅速化する技術・ツールの開発に着手する。
クローズド型企業のアライアンスからの排除
同アライアンスには OpenAI や Anthropic といったクローズドなプロプライエタリ AI ラボが含まれておらず、オープンウェイトモデルが競合関係にあるためである。
規制当局への提言とパラダイムシフト
Nvidia の Justin Boitano 氏は、オープンモデルを「防御資産」として認識し、インフラ層でのパッチサイクルや追跡可能性(provenance)の確立が重要であると指摘する。
ダウンロード済みウェイトファイルへの規制限界
The Enterprise Edge の Mark Vigoroso 氏は、一度ダウンロードされたウェイトファイルを法的に強制執行できない現状を踏まえ、従来のクローズドモデル中心の監査アプローチは時代遅れであると述べる。
インフラ層における安全性の必要性
実際の安全対策はパッチサイクルやプロベナンスなどインフラ層で行う必要がある。規制は集中型を想定しているが、エコシステムは分散化しており対応が遅れている。
重要な引用
To maintain U.S. leadership in the AI industrial revolution, the infrastructure that runs our economy needs safe, secure access to both closed and open models.
This alliance is an admission that the actual safety work now has to happen in the infrastructure layer: patch cycles, provenance, identity around who's deploying what, because nobody can subpoena a downloaded weights file.
The formation of the Open Secure AI Alliance proves that AI safety isn't just an algorithmic math problem — it is a foundational networking problem.
"Jensen Huang's point that every SaaS company will become a GaaS company captures why this matters now: Software is shifting from passive tools people log into, to AI agents that access data, take actions, and execute workflows."
編集コメントを表示
編集コメント
オープンウェイトモデルのセキュリティ対策において、業界大手が自発的なアライアンスを結成したことは画期的である。しかし、OpenAI や Anthropic の不参加は、クローズドとオープンの対立構造が依然として存在することを示唆しており、今後の連携拡大に注目が集まる。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。

オープンソースソフトウェアやオープンウェイト AI モデルの利用を巡る議論が激化する中、何が「正当な開放性」に該当し、何が窃盗や新たなサイバーセキュリティの脆弱性を生む行為なのかについて、世論は二分されています。
こうした業界全体の懸念に対応するため、37 のパートナー企業が今月、新しい「Open Secure AI Alliance(オープン・セキュア AI アライアンス)」の結成を発表しました。同団体は、脆弱性を迅速に特定して修正する手法やツールを開発し、ソフトウェアを保護することを目指します。
Open Secure AI Alliance 創設メンバー
同アライアンスの創設パートナーには、Adobe、Cadence、Capital One、Cisco、Cloudera、Cloudflare、Cognition、CrowdStrike、Databricks、Dell Technologies、DoorDash、Elastic、HPE、Hugging Face、IBM、LangChain、Linux Foundation、Microsoft、Naver、NetApp、Nvidia、Nous、OpenClaw、Palantir、Palo Alto Networks、Red Hat、Reflection、Salesforce、SAP、ServiceNow、Siemens、SK Telecom、Snowflake、SpaceXAI、Synopsys、Thinking Machines、TrendAI が名を連ねています。
これはテクノロジー業界で最も影響力のある企業群の集結ですが、OpenAI と Anthropic という 2 つの主要な例外が存在します。これらはクローズドでプロプライエタリな AI ラボであり、その不在は当然です。彼らがクローズドラボを運営している以上、オープンウェイト AI モデルは事実上の競合相手となるからです。
Nvidia のエンタープライズプラットフォーム担当バイスプレジデント、ジャスティン・ボイタノ氏は、オープンウェイトモデルが米国の AI 主導権とサイバーセキュリティの基盤であると説明しました。
「AI 産業革命における米国のリーダーシップを維持するためには、経済を支えるインフラがクローズドモデルとオープンモデルの両方へ安全かつセキュアにアクセスできる必要があります」とボイタノ氏は語っています。「サイバーセキュリティにおいては、オープンモデルとオープンなハルネス(枠組み)が不可欠です。これらは防御能力を広げ、守る側の透明性を高め、カスタマイズ可能でローカル化された制御機能によって最先端のクローズドモデルを補完するからです」
規制当局が AI の安全性対応に苦慮する中、ボイタノ氏は「オープンモデルとオープンなツールを防御資産として認識することが重要になる」と予測しています。これにより、透明性の確保、独立した評価、そして共有された対策の実現が可能になると考えられています。
ダウンロードされたウェイトファイルに対して訴追状は発令できない
テクノロジーコンサルティングファーム「The Enterprise Edge」の創設者兼 CEO、マーク・ヴィゴロソ氏は The New Stack に対し、AI 規制当局は従来、「クローズドなラボ数ヶ所を監査対象として AI 安全装置全体を構築してきた」と指摘しました。しかし、そのアプローチはもはや時代遅れです。
「オープンウェイトモデルはこのクローズドモデルへの依存というアプローチを、すでに数か月前に超えてしまいました」とヴィゴロソ氏は話します。「今回のアライアンス結成は、実際の安全性確保の作業がインフラ層で行われる必要があることを認めたものです。パッチ適用サイクルやプロベナンス(出自)、誰が何を展開しているのかというアイデンティティ管理などです。なぜなら、ダウンロードされたウェイトファイルに対して訴追状を発令することはできないからです」
「この同盟は、実際の安全性対策は今やインフラ層で行わなければならないという事実の認容である。パッチ適用サイクル、プロベナンス(出所証明)、誰が何を展開しているかというアイデンティティ管理だ。ダウンロードされた重みファイルに法廷召喚状を送ることはできないからだ。」
Vigoroso氏は、AI安全性をめぐる議論が「モデルレベルの制御」で行き詰まっていると指摘する。真の規制の隙間は、インフラのプロベナンスとアイデンティティにある。つまり、モデル自体が安全かどうかだけでなく、そのモデルはどこから来たのか、誰が展開したのか、何にアクセスしたのかを知る必要があるのだ。
「EU AI OfficeやNISTのAI標準・イノベーションセンター(CAISI)、英国のAIセキュリティ研究所(AISI)といった団体は、ほぼ完全にフロンティアなクローズドモデルに焦点を当てている。オープンウェイトモデル(Mistral、DeepSeek、その他)は規制の盲点にある。一度重みが公開されてしまうと、下流での安全性義務を履行させる手段がなくなるからだ。
現在のAIモデルに関する規制枠組みは、責任を負うデプロイヤーが一人いることを前提としている。しかしオープンソースにはそのような存在が存在しない。これが真実だ。Vigoroso氏によれば、規制当局は中央集権的な世界に向けてルールを書いているが、エコシステムは分散化に向かっているというのだ。
この同盟の意図する具体的な行動に関する詳細な運用情報は現時点では少ないものの、Nvidiaは新しいサイバーセキュリティツールや技術の開発を加速させるため、Open Secure AI Allianceに対して堅固な研究成果を提供すると強調している。
ハーンセス(Harnesses)はモデルと統合され、エージェントのテストを容易にする。
オープンソースの「Nvidia Labs Object-Oriented Agent (NOOA)」プロジェクトが GitHub で公開され、エージェントハッチにおける高度な AI セーフティ機能の利用が容易になりました。この研究フレームワークにより、ハッチはモデルと統合しやすくなり、エージェントの挙動をテストや追跡、監査、ガバナンスしやすくなります。
認証 ID とエンドツーエンド暗号化を提供する企業 Atsign の CEO、アパナ・ライヤサム氏は The New Stack に対し、「AI ブリッツクリーク(電撃戦)に関する議論は、決定的な転換点に達した」と語りました。これは、ライヤサム氏が「レガシーで穴だらけのインフラ」の上に成り立つものとしてきた、次世代のオープン認知イノベーションを構築することができなくなった瞬間です。
「AI ブリッツクリークに関する議論は決定的な転換点に達した」という言葉が示す通りです。
ライヤサム氏はさらに、「Open Secure AI Alliance の設立は、AI セーフティが単なるアルゴリズムや数学の問題ではないことを証明している。これは基盤となるネットワークの問題だ」と指摘しました。「現代の AI を訓練し実行するために必要な大規模で分散されたパイプラインには、信頼に関する全く新しいパラダイムが必要だ。真の安全性とは、これらのモデルにデータを提供するパイプラインが本質的に不可視であり、攻撃不可能で、オープンなネットワーク境界を完全に排除されていることを保証することである」のです。
ここで重要なのは、保存中のデータを保護する世界から、AI の結合組織が設計段階からセキュリティを備えた世界へと移行しているという点です。
すべての AI ベンダーを統括する単一の存在が必要か?いや、それは不要だ。
エージェント型IDと権限セキュリティ企業Recoの創設者兼CPO、Gal Nakash氏はThe New Stackに対し、Open Secure AI Alliance(オープンセキュアAIアライアンス)の発足は「重要なシグナル」であり、AIセキュリティが単一のベンダーやクローズドなフレームワークだけで解決できない理由を浮き彫りにしていると語りました。
Nakash氏はさらに、「ジェンセン・ホアンの『すべてのSaaS企業がGaaS(Generative AI-as-a-Service)企業になる』という指摘は、今この問題がなぜ重要なのかを捉えている」と述べました。「ソフトウェアは、単にログインして使う受動的なツールから、データにアクセスし、行動を起こし、ワークフローを実行するAIエージェントへとシフトしています。オープンソースのツールや共有規格は業界のスピードアップに寄与しますが、それらはID、権限、データアクセス、そして振る舞いという実態あるエンタープライズの文脈に基づいて初めて意味を持ちます」と解説しました。
自動化されたID駆動型マイクロセグメンテーション企業Zero NetworksのフィールドCTO、Chris Boehm氏もThe New Stackに対し、Open Secure AI Allianceのニュースを聞いて「どこかで見たような気がする」と感じたと語りました。
Boehm氏は「これはMicrosoftにおけるTPM(Trusted Platform Module)の物語が繰り返されているように見えます。業界団体が『信頼できるハードウェア』の定義を行い、プラットフォームベンダーがそれを採用し、数年後には推奨事項から調達要件へと変わるというケースです」と分析しました。
彼は「Windows 11はまさにTPM 2.0とSecure Bootでその役割を果たし、LinuxやAppleも追随した」と説明。Bohm氏はさらに、「AIインフラストラクチャでも同様のことが起きるだろう。証明されたシリコンが規制対象のワークロードにおける最低限の基準となり、ベンダーリストはそれに対応できる企業に絞り込まれるはずだ」と予測しています。
「業界団体が信頼できるハードウェアの定義を定め、プラットフォームベンダーがそれを採用し、数年後にはそれが推奨事項ではなく調達要件となるケースに見える」という指摘があります。
よりグローバルで地理的に包括的なアプローチが必要です。
オープンテクノロジー団体 OpenUK の CEO であるアマンダ・ブロック氏は、The New Stack に対し、Open AI アライアンスは間違いなく素晴らしい出発点だと語りました。特に先週 OpenAI が明らかにしたセキュリティ上の問題点を踏まえると、その意義は大きいものです。
「しかし、米国のオープンウェイトにおけるリーダーシップに関する公開書簡と同様に、これは米国が直面する課題に対する米国の対応に過ぎません」とブロック氏は指摘します。「オープンモデルを閉鎖するための大統領令が出されるという噂が数週間前から流れており、中国の Kimi K3 を巡る政権内の混乱によってさらに悪化しています。」
このアライアンスが成功するためには、米国中心の創設メンバーを超えて、「よりグローバルで地理的に包括的なアプローチ」を取らなければならないとブロック氏は強調します。
「また、AI のインフラストラクチャやエージェント機能、開発ツールを構築している個人やイノベーターからなるオープンソース・エコシステムとも連携する必要があります。重要なのは、オープン AI インフラの開発が、最先端モデルを少数の企業が開発する現状とは対照的に、革新の主導権を多くの人々の手に移す点にあります」とブロック氏は付け加えています。
Nvidia のボイターノ氏も、ブロック氏の見解に同調しています。The New Stack がドラフト版をレビューしたブログ記事で、彼は「オープンなモデルは、AI ユーザーを AI 開発者へと変え、機会を広げ、革新を加速し、進歩が一部の組織や地域に集中するのを防ぐ」と述べています。
ボイターノ氏は結論として、オープンなモデルは、AI システムの振る舞いに関する独立した科学研究を可能にし、研究者がそれらを理解・評価・改善できるのだと指摘しています。これは彼が「広範で継続的な防御の実現」と呼ぶものに関わる話です。
今後、AI セーフティを担う団体や運動、あるいは同盟は、単なるモデル監査機関ではなく、アイデンティティ検証、コンテンツの出自証明、信頼性の担保などを含む「信頼インフラの基準策定機関」へと進化していくでしょう。これらはガバナンスやコンプライアンスのために既存のアプローチを借用する形になるはずです。結果として、オープンウェイトの普及が進む中で生き残る唯一の執行層となる可能性があります。
この記事は元々 The New Stack に掲載された「Nvidia, Palantir, Hugging Face join 34 others in race to defend open-weight AI from cyber threats」を基にしています。
原文を表示

The current maelstrom of discussion surrounding the use of open-source software and open-weight AI models appears to be splitting opinion on what constitutes legitimate openness versus actions that might constitute theft and create new cybersecurity vulnerabilities.
In a direct move to address these industry-wide concerns, 37 partners announced on Monday the formation of the new Open Secure AI Alliance and how the newly created body will develop techniques and tools to safeguard software by rapidly identifying and patching vulnerabilities.
Open Secure AI Alliance inaugural partners
The inaugural partners of the Open Secure AI Alliance are Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell Technologies, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, the Linux Foundation, Microsoft, Naver, NetApp, Nvidia, Nous, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection, Salesforce, SAP, ServiceNow, Siemens, SK Telecom, Snowflake, SpaceXAI, Synopsys, Thinking Machines, and TrendAI.
It’s a grouping of some of the most influential names in technology, but also includes two notable exceptions: OpenAI and Anthropic, two closed, proprietary AI labs. Their absence is understandable, as they operate closed labs and open-weight AI models are effectively the competition.
Nvidia VP of enterprise platforms, Justin Boitano, has explained that open-weight models are foundational to American AI leadership and cybersecurity.
“To maintain U.S. leadership in the AI industrial revolution, the infrastructure that runs our economy needs safe, secure access to both closed and open models,” Boitano said. “For cybersecurity, open models and open harnesses are essential because they broaden defensive capability, increase transparency for defenders, and complement frontier closed models with customizable, localized controls.”
As regulators grapple with AI safety, Boitano predicts it will be important to “recognize open models and open tooling as defensive assets” — thus enabling transparency, independent evaluation and shared remediation.
Nobody can subpoena a downloaded weights file
Mark Vigoroso, founder & CEO of technology consultancy firm The Enterprise Edge, tells The New Stack that AI regulators have traditionally “built their entire AI safety apparatus” around auditing a handful of closed labs. And now, that approach is out of date.
“Open weight models blew past that closed model approach months ago,” Vigoroso says. “This alliance is an admission that the actual safety work now has to happen in the infrastructure layer: patch cycles, provenance, identity around who’s deploying what, because nobody can subpoena a downloaded weights file.”
“This alliance is an admission that the actual safety work now has to happen in the infrastructure layer: patch cycles, provenance, identity around who’s deploying what, because nobody can subpoena a downloaded weights file.”
Vigoroso argues that the AI safety debate is “stuck on model-level controls”, while the real regulatory gap is provenance of infrastructure and identity, i.e., knowing where a model came from, who deployed a model and what it touched, not just whether the model itself is safe.
“Groups like the EU AI Office, NIST’s Center for AI Standards and Innovation (CAISI), and the UK’s AI Security Institute (AISI) focus almost entirely on frontier closed models. Open weight models (Mistral, DeepSeek, and others) fall into a regulatory blind spot: Once weights are released, there’s no way to enforce downstream safety obligations.
Current regulatory frameworks for AI models assume a single accountable deployer; open source has none. That’s the real story: Regulators are writing rules for a centralized world while the ecosystem is decentralizing, Vigoroso says.
While detailed operational information explaining the intended actions of this alliance is currently scant, Nvidia has highlighted that it is contributing solid research to the Open Secure AI Alliance to speed the development of new cybersecurity tools and techniques.
Harnesses integrate with models, making agents easier to test
The open source Nvidia Labs Object-Oriented Agent (NOOA) project is now available on GitHub to make advanced AI safety capabilities more accessible for agent harnesses. This research framework enables harnesses to integrate with models to make agent behavior easier to test, trace, audit, and govern.
Aparna Rayasam, CEO of verified identity and end-to-end encryption company Atsign, tells The New Stack that the “AI blitzkrieg conversation has reached a critical inflection point.” This moment is one where we cannot build the next era of open cognitive innovation on top of what Rayasam calls “legacy, Swiss-cheese infrastructure.”
…the “AI blitzkrieg conversation has reached a critical inflection point.”
“The formation of the Open Secure AI Alliance proves that AI safety isn’t just an algorithmic math problem — it is a foundational networking problem,” Rayasam says. “The massive, distributed pipelines required to train and run modern AI demand an entirely new paradigm of trust. True safety means ensuring that the data pipelines feeding these models are inherently invisible, un-attackable, and completely stripped of open network perimeters.”
The key notion here is that we are moving from a world of protecting data at rest to a world where the connective tissue of AI must be secure by design.
One AI vendor to secure them all? No thanks.
Founder and CPO of agentic identity and permissions security company Reco, Gal Nakash, tells The New Stack that the launch of the Open Secure AI Alliance is an “important signal” which underlines why AI security can’t be solved by one vendor or one closed framework.
“Jensen Huang’s point that every SaaS company will become a GaaS company captures why this matters now: Software is shifting from passive tools people log into, to AI agents that access data, take actions, and execute workflows,” says Nakash. “Open source tools and shared standards can help the industry move faster, but they need to be grounded in real enterprise context across identity, permissions, data access and behavior.”
Chris Boehm, Field CTO at automated, identity-driven microsegmentation company Zero Networks, tells The New Stack that news of the Open Secure AI Alliance makes him feel like he’s seen this before somewhere.
“This looks like the Trusted Platform Module (TPM) at Microsoft story all over again,” Boehm says. “It’s a case of an industry group defining what trusted hardware means, the platform vendors adopt it, and within a few years it’s a procurement requirement rather than a suggestion.”
He explains that “Windows 11 did exactly that with TPM 2.0 and Secure Boot”, and both Linux and Apple adapted. “I’d expect the same for AI infrastructure, where attested silicon becomes the floor for regulated workloads, and the vendor list narrows to whoever can meet it,” predicts Boehm.
“This looks like a case of an industry group defining what trusted hardware means, the platform vendors adopt it, and within a few years it’s a procurement requirement rather than a suggestion.”
A more global and geographically-inclusive approach is needed
Amanda Brock, CEO of open technology body OpenUK, tells The New Stack that the Open AI Alliance is undoubtedly a great starting point, particularly with OpenAI’s security woes it divulged last week.
“But, like the open letter on US Leadership in open weights, this is a US response to a US challenge,” Brock says. “Rumors of a forthcoming Presidential Executive Order to close down open models have been circulating for weeks — and worsened by the administration being thrown into turmoil over China’s Kimi K3.”
For this alliance to succeed, Brock insists that it will need to take a more “global and geographically-inclusive approach”, beyond the US-centric founding members.
“It must also engage the open source ecosystem of individuals and innovators who are building the infrastructure, agentic harness functions and developer tools for AI. It’s important to realize that open AI infrastructure development shifts the innovation into the hands of the many, in direct opposition to the small number of corporate creators of frontier models,” Brock adds.
Nvidia’s Boitano echoes Brock’s view. In a blog post reviewed in draft by The New Stack, he writes that “open models turn more AI users into AI builders,” expanding opportunity, accelerating innovation, and keeping progress from being concentrated in only a few organizations or regions.
Boitano concludes by saying that open models also enable independent scientific research into how AI systems behave, allowing researchers to understand, evaluate, and improve them. It’s all about what he has called making broad, continuous defense possible.
Looking ahead, it feels like the next wave of AI safety bodies, movements, or alliances won’t just be model auditors—they’ll be trust-infrastructure standards bodies (encompassing identity verification, content provenance, credence, etc.) using borrowed approaches to governance and compliance. Ultimately, this may be the only enforcement layer that survives open weight proliferation.
The post Nvidia, Palantir, Hugging Face join 34 others in race to defend open-weight AI from cyber threats appeared first on The New Stack.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み