Much of the public discussion around AI and its impact on cybersecurity focuses almost exclusively on models, with some arguments calling for a central authority to manage the latest models behind closed doors. There have even been discussions around strictly regulating or outright banning open weights models in the interest of security. But as global regulators mull the future of open AI models, a core question falls by the wayside: How do we actually secure AI systems?

AI security is a software challenge, not just a model issue

An AI agent isn't just a model but rather a complete software stack. Securing this system requires analyzing the core model, the agentic harness, sandboxing techniques, runtime guardrails, data controls, and a host of other underlying infrastructure layers. Crucially, three of those four components—harnesses, sandboxes, and traditional application layers—are fundamentally rooted in software engineering, not the model.

Trying to secure the AI landscape by fragmenting software behind closed, proprietary boundaries simply shifts risk rather than solving it. Decades ago, when Linux first hit the scene, there was uncertainty and doubt cast around open source as a stable, secure solution for enterprise companies. Naysayers claimed only closed development could offer enterprise-grade reliability. However, time proved the exact opposite: open source software has since become the de facto catalyst powering a vast majority of global enterprise IT where scale and security are non-negotiable.

We are seeing an exact echo of that resistance today. Just as Linux proved that transparency and community collaboration create a more robust operating system, open source AI models, open source agentic harnesses, and transparent sandboxing will prove to be the most secure foundation for the future of computing.

Why open models and transparency are vital for defense

In cybersecurity, transparency is part of how you create secure systems. As the old IT principle goes: security through obscurity is less secure.

Limiting ourselves to a small set of proprietary models for cybersecurity research and threat mitigation introduces serious risks. Defenders have no way to manage what tools attackers choose to use. If researchers and security teams are restricted from accessing and inspecting open defensive models, they risk becoming blind to the tools and vectors exploited by threat actors. Furthermore, concentrating access within a handful of closed providers creates concentrated systemic risk.

Broad access to open weights models gives defenders the exact tools needed to build effective mitigation strategies. Open models allow for broad scientific scrutiny, which is vital for identifying and addressing latent vulnerabilities that would otherwise remain hidden inside proprietary "black box" systems.

We saw a clear example of this dynamic in action during a recent security incident involving Hugging Face. While the source of the vulnerability involved proprietary models (systems we are told to trust as inherently safe) the actual mitigations and protections were driven by open weights models. Open weights models were critical to resolving the threat. This is why Red Hat signed Microsoft's letter on Open Weights and American AI Leadership. Broad, open access to defensive tools spreads security pervasively across the software development lifecycle.

Advancing state-of-the-art protection through shared learning

With this in mind, Red Hat is doing what we do best to help address the growing need for secure AI: working with the community. Most recently, as part of the Open Secure AI Alliance, Red Hat collaborated with NVIDIA, the Linux Foundation, and other members to develop a Request for Comments (RFC) for the Shared AI Findings Exchange (SAFE) Working Group

Until now, IT teams have investigated AI security incidents internally, keeping critical operational insights trapped within individual enterprise walls. The SAFE guidelines change that paradigm by creating a neutral framework to confidentially collect, analyze, and distribute findings from AI operational failures without placing blame.

By supporting incident reporting and sharing threat intelligence openly, we advance the state of the art together. Through open collaboration, the entire ecosystem benefits: tools evolve faster, defensive capabilities grow stronger, and critical infrastructure becomes better protected against real-world attacks.

Moving forward together

Whether in base operations, software engineering, or enterprise application delivery, AI tools are advancing at unprecedented speed. A system's strength relies on a combination of core models and the open source harnesses wrapped around them to safely guide behavior toward intended outcomes.

At Red Hat, we believe open collaboration and transparency remain the best, fastest, and safest ways to evolve technology. By focusing on original, human-driven insights and fostering open ecosystems – across open source software, open weights models, and open agentic harnesses – we can advance security alongside capability.

The full SAFE RFC proposal is available now on GitHub for community review, discussion, and contributions. 


About the author

Chris Wright is senior vice president and chief technology officer (CTO) at Red Hat. Wright leads the Office of the CTO, which is responsible for incubating emerging technologies and developing forward-looking perspectives on innovations such as artificial intelligence, cloud computing, distributed storage, software defined networking and network functions virtualization, containers, automation and continuous delivery, and distributed ledger.

During his more than 20 years as a software engineer, Wright has worked in the telecommunications industry on high availability and distributed systems, and in the Linux industry on security, virtualization, and networking. He has been a Linux developer for more than 15 years, most of that time spent working deep in the Linux kernel. He is passionate about open source software serving as the foundation for next generation IT systems.

UI_Icon-Red_Hat-Close-A-Black-RGB

Browse by channel

automation icon

Automation

The latest on IT automation for tech, teams, and environments

AI icon

Artificial intelligence

Updates on the platforms that free customers to run AI workloads anywhere

open hybrid cloud icon

Open hybrid cloud

Explore how we build a more flexible future with hybrid cloud

security icon

Security

The latest on how we reduce risks across environments and technologies

edge icon

Edge computing

Updates on the platforms that simplify operations at the edge

Infrastructure icon

Infrastructure

The latest on the world’s leading enterprise Linux platform

application development icon

Applications

Inside our solutions to the toughest application challenges

Virtualization icon

Virtualization

The future of enterprise virtualization for your workloads on-premise or across clouds