Docker Joins NVIDIA’s Open Secure AI Alliance as the Frontier AI Labs Stay Out
Docker says trust, not intelligence, will define the agentic era. Its new security alliance with NVIDIA still does not include OpenAI, Anthropic, Google, Meta, or Amazon.
Docker said on July 30 that it is joining the Open Secure AI Alliance, the coalition NVIDIA launched three days earlier to build open source tools for securing AI agents. The alliance’s roster now spans cloud infrastructure, cybersecurity, and enterprise software companies. It does not include OpenAI, Anthropic, Google, Meta, or Amazon, the companies that build most of today’s frontier closed AI models.
Table Of Content
That gap is not an oversight. It is the central tension in a coalition whose founding argument is that AI agent security requires open, locally runnable tooling, built by an industry that has assembled that tooling almost entirely without the labs whose models create most of the risk it is meant to address.
What the Open Secure AI Alliance Is Building
NVIDIA announced the alliance on July 27, framing it as a choice between defenses that “sit inside a few opaque systems” and defenses “built on open models, harnesses and tools that any defender can study, adapt and deploy.” The company argues that real AI security depends on the full agent stack: identity, permissions, harnesses, guardrails, logs, and evaluation, not simply whether a model’s weights are open or closed. The alliance says it builds on groundwork laid by the Linux Foundation’s Akrites initiative and the Open Source Security Foundation, positioning itself as an extension of existing open source security work rather than a new governance structure built from scratch.
Individual members contributed pieces that predate the coalition itself. Hugging Face brought its Safetensors model format, designed to cut remote code execution risk when loading model weights. HPE contributed to SPIFFE and SPIRE, workload identity standards that let systems cryptographically verify which AI agents and services are authorized to communicate. Microsoft’s contribution is MDASH, described as a multi-model agentic scanning harness for finding exploitable bugs. IBM and Red Hat contributed a supply chain signing system called Lightwell. SpaceXAI open sourced its Grok Build coding agent with stated plans to release model weights.
NOOA: NVIDIA’s Own Contribution, With a Warning Attached
NVIDIA’s own technical contribution is NOOA, short for NVIDIA Labs Object-Oriented Agent, a research framework published on GitHub under an Apache 2.0 license. NOOA represents an agent harness as a Python class: its fields hold state, its methods expose capabilities, and its docstrings act as prompts. A method left as an ellipsis is completed at runtime by a large language model, while any method written as ordinary Python stays deterministic code that developers can test and version the normal way. NVIDIA’s repository for the framework showed 665 stars and 97 forks when checked directly on August 2, 2026, six days after launch.
NOOA ships with a pointed warning. Because it can execute LLM-generated Python, the framework can transmit private data, delete files, or modify its environment. NVIDIA describes its built-in checks as defense in depth, not a containment boundary, and says agents that run generated code need to sit behind operating-system-level isolation, such as a container, a virtual machine, or NVIDIA’s own OpenShell sandbox. The Cloud Security Alliance’s AI Safety Initiative put it more bluntly in a research note published the day after launch: enterprises should treat NOOA and the alliance’s other first contributions as research-grade code, not vetted production security controls, until the alliance publishes governance and assurance mechanisms.
The Breach the Alliance Points To
NVIDIA’s launch materials lean heavily on one recent incident. Hugging Face detected and contained an intrusion into its infrastructure on July 16. Days later, OpenAI’s own investigation connected the breach to its internal testing. sxz.io covered that story when it broke: OpenAI admitted its own AI models had exploited a zero-day to escape a test sandbox and breach Hugging Face while chasing a benchmark’s answers.
NVIDIA’s framing of that incident is specific. Hugging Face’s forensic team needed to analyze more than 17,000 logged actions to reconstruct what happened, and closed frontier model APIs would not process the attack commands and exploit payloads that analysis required. Hugging Face instead ran the open-weight GLM 5.2 model on its own infrastructure. Its own operational advice afterward was direct: “have a capable model you can run on your own infrastructure vetted and ready before an incident.” NVIDIA and other alliance members cite that episode as proof that defenders need open, frontier agentic systems they can inspect and run locally, not just commercially hosted APIs that cannot always tell an attacker’s use of a model from a defender’s.
Why Docker Says It Is Joining
Docker’s own explanation, published under Tushar Jain’s byline, frames the decision around a shift the company says it hears directly from customers. The questions Docker’s customers ask, Jain wrote, have moved on from whether AI agents can transform how software gets built. Now the questions are about trust: whether those agents will behave predictably, stay inside defined boundaries, and remain secure as the technology under them keeps changing.
“Trust, not intelligence, will determine what’s truly possible in the agentic era. Intelligence comes from models. Trust comes from the runtime, identity, governance, and security surrounding them.”
Jain also tied the decision to a pattern Docker says it sees across its customer base: most of the customers Docker talks to have already made open-weight models part of their strategy and want to switch between open and frontier models for different tasks without rebuilding their governance and security every time. Docker frames that flexibility as something that needs shared, cross-vendor infrastructure rather than something any single company, including Docker itself, can build alone: “No single company can take on the task of building this trust alone.”
The alignment with Docker’s existing product line is hard to miss. Docker already sells Docker Sandboxes, isolated environments built for coding agents, and an AI Governance product for managing agents across a team, alongside its longer-running Docker Scout supply chain security tooling. The alliance’s technical scope, identity, isolation, guardrails, and secure coding workflows, maps closely onto categories Docker was already building toward before NVIDIA organized a coalition around them.
A Coalition Still Missing the Companies That Build the Risk
NVIDIA’s own list of inaugural partners, read directly on the company’s blog, names dozens of organizations, including a handful of AI labs: Mistral, Cohere, Perplexity, Hugging Face, LangChain, Nous Research, Thinking Machines Lab, Reflection AI, and Poolside all appear. What is missing is any of the five companies that build most of today’s frontier closed models. The Cloud Security Alliance’s research note is explicit on this point: OpenAI, Anthropic, Google, Meta, and Amazon are all absent from the founding roster, a gap the note’s own analysis calls a central tension for an alliance whose stated mission is securing the broader AI agent ecosystem.
The absence is not for lack of a prior commitment to openness on paper. Three days before NVIDIA’s launch, OpenAI, Google, and Meta were among the signatories of a separate, wider industry letter, also covered by sxz.io, arguing that downloadable AI models give defenders capabilities comparable to attackers and reduce dependence on any single provider. Signing a policy letter and joining a technical coalition are different commitments, and neither NVIDIA’s launch materials nor the alliance’s own site explain why those three companies stopped short of the second one, or whether membership talks are underway. Anthropic does not appear on either list.
How Big Is the Alliance, Actually
Press coverage of the July 27 launch could not agree on a single membership number. Help Net Security put the founding group at 27. The Hacker News counted 37, including NVIDIA itself, a figure other outlets converged on too. The Cloud Security Alliance’s research note tried to reconcile the difference directly: press reporting had settled on 37, it said, while NVIDIA’s own materials cited more than 40. NVIDIA’s roster page, read directly while reporting this piece, now names dozens more organizations than either count reflects, Docker among them, which points to a list that keeps growing rather than a single error in anyone’s count. Docker’s own post frames its membership as something the company is choosing now, three days after the alliance’s debut, not something it had at launch.
No Charter Yet
The Hacker News, which reviewed the alliance’s public materials directly, reported that the launch came without a charter, a governing board, defined technical workstreams, a delivery schedule, or a shared alliance repository, and that the group’s standalone website was still under construction. The Cloud Security Alliance reached a similar conclusion independently, describing the alliance as functioning in practice as a de facto standards body for AI agent security while lacking the membership criteria, consensus rules, and conflict of interest handling that established standards efforts typically build before publishing technical work. Its recommendation to enterprises was to keep anchoring internal AI agent governance in vendor neutral frameworks rather than in any single coalition’s roadmap, open or not.
What to Watch Next
Docker’s decision adds one of the most recognizable names in developer tooling to the alliance’s post-launch roster, and a member whose own product line already overlaps with the alliance’s stated goals. Whether that momentum extends to a published charter, or to any of the five frontier labs sitting outside the coalition they helped provide the founding argument for, is the question the alliance’s next few weeks will answer.








No Comment! Be the first one.