NVIDIA launched the Open Secure AI Alliance on July 27, 2026 with more than 30 named partners, and HPE joined as a founding member, naming its work on the SPIFFE and SPIRE workload-identity projects as its contribution. The same announcement page now lists more than 120 organizations, among them Amazon, Intel, Okta, Visa, Workday, Wiz and Zscaler, and on September 14 the alliance moved under the Linux Foundation for neutral governance. Seven weeks in, the alliance’s public RFC repository holds exactly one proposal, and it is not about identity.
That proposal is SAFE, the Shared AI Findings Exchange, published through the Linux Foundation on August 4. It reads like an incident-reporting compact with clocks attached: tell the affected organization as soon as you suspect it, notify customers with credible exposure inside 72 hours, file a confidential initial report in four business days, publish a preliminary factual report at 30 days and remediation status at 90. Membership in SAFE would carry that duty regardless of whether an operator believed the environment was simulated. Community comments on the draft are due September 21.
Read the reportable-event list closely and the gap becomes obvious. An operator must report an AI system that escapes or bypasses “a sandbox, network, identity, policy or tool boundary.” Identity failure is already a reporting trigger in the alliance’s only draft, while the mechanism for giving an agent an identity of its own has no workgroup, no RFC and no published schedule.
For security architects the practical read is not to wait. SPIFFE and SPIRE graduated from the Cloud Native Computing Foundation in September 2022, and HPE says in its newsroom post that it already runs them inside GreenLake on short-lived identities and mutual TLS. The standards conversation is moving elsewhere too: NIST’s NCCoE concept paper of February 5, 2026 lists SPIFFE and SPIRE as one way agent workloads could be identified and authenticated, and Okta made Agent SSO generally available on August 24, built on the Cross App Access standard. Okta has since contributed its Cross App Access implementation to the alliance, and NVIDIA’s August 4 contributions roundup groups it under identity and access alongside Amazon’s Cedar authorization language and Palo Alto Networks’ Agent Guard. Contributions are accumulating. None has entered the RFC process.
Keep the membership figure in perspective. NVIDIA still labels every listed organization an inaugural partner, which makes the roster a statement of intent rather than a record of shipped work. Virtualization Review asked in July whether HPE’s GreenLake deployment would become a formal reference design, and nearly two months later that is still unanswered. OpenAI, Google and Anthropic are also still absent, as The Verge noted at launch, which matters for a compact whose worth depends entirely on who files reports into it.
The signal worth tracking is a second RFC in that repository. Linux Foundation governance makes one more likely, since turning member contributions into open specifications is what the foundation’s projects are built to do, but it has not happened yet. An identity or workload-attestation proposal landing there would mean agent-identity tooling is genuinely consolidating. Until one does, treat SPIFFE and SPIRE support as an RFP line item to pursue with vendors directly, and read the alliance for what it has actually published: a reporting regime, not a control.
Sources: NVIDIA Blog, NVIDIA contributions roundup, Linux Foundation (SAFE), Linux Foundation (governance), Open Secure AI Alliance RFCs



Leave a Reply