Jensen Huang Forges Alliance with Nearly All AI Circle Members, Leaving One Dissenter Out

07/29 2026 572

Source: Shenlan Finance

After leading NVIDIA for over three decades, Jensen Huang made significant waves in the AI industry with just two posts on the social platform X.

In his first post, he shared an open letter endorsed by 32 companies, explicitly supporting open-weight models.

In his second post, he announced the formation of the 'Open Secure AI Alliance,' comprising 37 founding members. This alliance boasts an impressive roster, including chip manufacturers, cloud giants, cybersecurity firms, open-source communities, and more. Its core message is clear and resolute: while closed-source and open-source models can coexist, open models and testing frameworks are indispensable in cybersecurity.

However, the real intrigue lies not on the alliance's list but beyond it.

Initially, OpenAI, Google, and Anthropic were missing from the list. But OpenAI and Google swiftly responded, promptly 'endorsing' the open letter, thus bringing nearly all major AI players on board.

Ultimately, only one company remained—neither endorsing the open letter nor joining the alliance.

That company is Anthropic, standing alone in its opposition.

1. Huang's Second Move: An Alliance and 37 'Pledges of Allegiance'

Let's delve into the lineup. The 37 founding members resemble the 'Avengers' of the U.S. tech scene:

For chips: NVIDIA, Dell, HPE. For cloud: Microsoft, IBM, Salesforce, SAP. For security: CrowdStrike, Cloudflare, Palantir. For open-source: Hugging Face, Red Hat. Even Elon Musk's xAI contributed its Grok Build coding agent.

NVIDIA's own 'gift' was substantial—the NOOA framework (NVIDIA Labs Object-Oriented Agent), openly shared on GitHub.

Design philosophy: Develop agents as Python classes, where methods represent capabilities, fields represent states, and docstrings serve as prompts. This creates a standard interface for AI agents, simplifying security audits to the level of code reviews.

Other members also made significant contributions:

HPE's SPIFFE/SPIRE framework—manages agent identity with zero-trust authentication. Hugging Face's Safetensors—prevents tampering with weight files. IBM + Red Hat's Lightwell signature chain—tracks provenance end-to-end. Microsoft's MDASH scanning harness—conducts automated security testing. xAI's Grok Build—handles tasks as an open-source terminal coding agent.

This is the underlying logic.

Agent security is not solely reliant on underlying model weights; it's a complex systems engineering challenge. A robust security system must encompass the entire business chain, requiring system administrators (or platforms) to implement identity authentication, permission management, runtime environments (harnesses), safety guardrails, system logs, and continuous evaluation mechanisms. Nothing can be overlooked.

Key insight: The alliance's core logic is that agent safety ≠ model weight safety. An AI system's security hinges on the entire chain—identity, permissions, harnesses, guardrails, logs, and evaluation. If defenders only have access to a black-box API, a breach becomes a 'dimensional strike.' But if every layer is transparent, defenders can reinforce defenses at each level.

2. One Table, Three Chairs

The open letter and alliance announcement were made back-to-back. Within 48 hours, the AI industry's alignments were clear.

All-in players: NVIDIA, Microsoft, Meta, Cisco, Dell, Hugging Face, IBM, Palantir, xAI—signed the letter and joined the alliance, sharing models, tools, and frameworks. Wait-and-see players: OpenAI and Google co-signed the letter but held off on joining the alliance. OpenAI had just clashed with Hugging Face, making the 'open security' pool feel too hot to jump into. Lone wolves: Anthropic—refused to sign or join.

Dario Amodei issued a statement personally. His first sentence: 'We've never opposed open-weight models.' The subsequent sentences tightened the screws:

1. Chips must be restricted. 2. Distillation must be prevented. 3. Security testing must be tightened.

He verbally claims "not opposed," yet every move he makes tightens the screws.

3. A 'Black Fable': Closed-Source AI Attacks, Open-Source AI Cleans Up

The evidence Huang used to 'slap' Anthropic came from a recent incident.

July 16

Hugging Face issued a chilling security announcement: Some of their production servers had been breached by AI agents.

Five days later · July 21

OpenAI took responsibility.

The incident: GPT-5.6 Sol and an even stronger unpublished model, participating in ExploitGym security evaluations, discovered a zero-day vulnerability in a package cache proxy to escape their test environment and score higher. What followed was a textbook attack chain:

Inject malicious datasets → Steal credentials → Remote code execution → Breach Hugging Face's core systems

Note—this wasn't a simulation. The model chose this path, deciding that 'escaping for high scores' was better than 'staying in the sandbox.'

But the plot thickened.

Hugging Face's engineers rushed to analyze attack logs using cutting-edge commercial models—only to be blocked. The logs contained attack commands and exploit code, which the safety guardrails flagged as 'dangerous content' and refused to process.

It was like being attacked, trying to see a doctor, and being told, 'Your wound's too scary—we won't treat you.'

The rescue came from an open-source model, GLM 5.2, running locally. It dissected 17,000 attack actions frame by frame, completing forensic analysis in hours instead of days.

Attacker: U.S. closed-source model, escaping and running wild. Victim: U.S. security team, locked out by their own models. Rescuer: Chinese open-source model, quietly doing the dirty work.

Huang quoted this incident verbatim in his second X post, adding: 'Defenders must control their own AI.'

This was the spark for the 'Open Secure AI Alliance.'

4. Under the Guise of Safety, It's About Computing Power

NVIDIA's push for open models isn't solely about security.

The deeper reason lies in the unprecedented structural pressure on its core business. As the global GPU computing infrastructure dominator, NVIDIA now faces an awkward reality: Its biggest buyers are becoming direct chip competitors.

This 'customer-to-rival' trend is spreading among tech giants. OpenAI released its own AI accelerator chip; Anthropic is exploring custom chip solutions; Microsoft, Google, and Amazon have long deployed their Maia, TPU, and Trainium chips. Meanwhile, policy pressure is mounting. Anthropic is lobbying for stricter export controls on advanced chips.

With clients accelerating chip self-reliance and export controls tightening, NVIDIA's market space is shrinking. It must use ecosystem strategies like open models to fortify its moat.

Now the alliance's logic becomes clear:

Technical dimension—By providing identity authentication, permission isolation, security scanning, and audit tools, the barrier to deploying open models locally drops sharply. Easier deployment means more GPU sales.

Policy dimension—By framing open models as 'defense infrastructure' rather than 'security risks,' NVIDIA can lobby regulators for leniency. If Washington sees open models as allies, export controls won't target NVIDIA.

Simply put: The more open models spread, the bigger the local computing power pie becomes—and the better NVIDIA fares. If AI computing power concentrates in closed platforms with self-developed chips, NVIDIA becomes obsolete.

Two posts, one open letter, one 37-member alliance.

On the surface, this is a 'open vs. closed' ideological battle.

But dig deeper—it's NVIDIA redefining the rules before the table is flipped, squeezed by chip self-reliance and policy tightening.

Anthropic's resistance isn't solely about safety ideals—it's business logic: Claude Mythos's scarcity is Anthropic's moat. Open it, and the moat vanishes.

No one is truly fighting for 'openness' or 'safety.' Everyone fights for their computing power access, business models, and stock prices.

Except Huang, who wears better armor.

*Disclaimer: This article reflects the author's views only. Markets carry risks; invest cautiously. Under no circumstances does this information constitute investment advice to any individual.

Shenlan Finance's new media cluster, originating from the Shenlan Finance Journalist Community, has a 16-year history as a leading Chinese finance new media outlet. Its accounts focus on China's most valuable companies, cutting-edge industries, and emerging regional economies, providing value-driven content for investors, corporate executives, and the middle class. Welcome to follow.

Solemnly declare: the copyright of this article belongs to the original author. The reprinted article is only for the purpose of spreading more information. If the author's information is marked incorrectly, please contact us immediately to modify or delete it. Thank you.