As AI capabilities advance, they transform the security landscape in real time. To address these challenges at scale, no single company can act in isolation. We must bring together our respective expertise across the industry. That is why Red Hat is proud to participate as an inaugural member of the new Open Secure AI Alliance with NVIDIA.
This initiative focuses on developing open tools and techniques to safeguard the AI stack—from open weight models to agent harnesses—to help drive safety, transparency, and broad scientific scrutiny. Open source models and frameworks act as vital defensive assets. They broaden defensive capability, increase visibility for security practitioners, and prevent critical defensive intelligence from being locked behind proprietary walls.
Scaling defensive speed through open source innovation
Defending open source software requires an ecosystem approach. By coordinating upstream with maintainers, industry partners, and community foundations, we can better protect the shared digital infrastructure that banking, healthcare, telecom, and enterprise environments depend on every day.
Red Hat’s commitment to securing the enterprise software fabric is rooted in the belief that security must be integrated directly into the open source development process. Our participation in efforts like the Open Secure AI Alliance builds upon our broader ecosystem strategy:
- Lightwell: Automated vulnerability discovery is essential, but it must lead to stable, production-ready fixes. Lightwell serves as our initiative with IBM to deliver hardened, verified remediation back to open source packages. By routing automated insights directly into structured open source processes, we help ensure that fixes are delivered reliably to upstream projects without disrupting software velocity.
- OpenAI Daybreak: AI accelerates vulnerability discovery, but addressing those vulnerabilities requires an open source process capable of scaling patches at the same speed. Participating in the OpenAI Daybreak Cyber Partner Program brings defensive AI tools directly to our developers and maintainers. Combining automated discovery with our established community patch pipelines allows us to mitigate systemic risk across software supply chains.
- Project Akrites: As AI workloads and agents scale across hybrid cloud environments, establishing consistent security boundaries, provenance, and operational governance becomes paramount. Through initiatives like Project Akrites, we are laying the foundational framework needed to govern and run AI-assisted tools securely alongside traditional containerized workloads.
These initiatives are just the tip of the iceberg for our approach to more broadly securing open source at all levels, from AI models to the building blocks of Linux. We continue to drive initiatives around these requirements, including future work to push open source standards around AI safety and model guardrails.
Trust is built on open collaboration
AI models, agentic harnesses, and open source dependencies underpin the infrastructure of modern computing. Trying to secure this landscape by fragmenting behind closed, proprietary boundaries simply shifts risk rather than solving it.
Open source is a critical pillar of global innovation. The best way to defend it is together—in the open, upstream, and with maintainers in control. By combining defensive AI tooling with established, community-driven remediation, Red Hat and our partners are working to deliver enterprise infrastructure that remains resilient, transparent, and trusted for the road ahead.
About the author
Chris Wright is senior vice president and chief technology officer (CTO) at Red Hat. Wright leads the Office of the CTO, which is responsible for incubating emerging technologies and developing forward-looking perspectives on innovations such as artificial intelligence, cloud computing, distributed storage, software defined networking and network functions virtualization, containers, automation and continuous delivery, and distributed ledger.
During his more than 20 years as a software engineer, Wright has worked in the telecommunications industry on high availability and distributed systems, and in the Linux industry on security, virtualization, and networking. He has been a Linux developer for more than 15 years, most of that time spent working deep in the Linux kernel. He is passionate about open source software serving as the foundation for next generation IT systems.
More like this
What is metal to agents? Navigating the architecture of enterprise AI
Operationalizing agentic AI: The Day 0-2 blueprint for enterprise infrastructure
Can Compliance Be A Piece Of Cake? | Compiler
Standardizing the AI stack with PyTorch
Browse by channel
Automation
The latest on IT automation for tech, teams, and environments
Artificial intelligence
Updates on the platforms that free customers to run AI workloads anywhere
Open hybrid cloud
Explore how we build a more flexible future with hybrid cloud
Security
The latest on how we reduce risks across environments and technologies
Edge computing
Updates on the platforms that simplify operations at the edge
Infrastructure
The latest on the world’s leading enterprise Linux platform
Applications
Inside our solutions to the toughest application challenges
Virtualization
The future of enterprise virtualization for your workloads on-premise or across clouds