Hook
On March 3rd, Jensen Huang tweeted a single sentence that sent shockwaves through both AI and crypto Twitter: “We are forming the Open Secure AI Alliance.” Within hours, NVIDIA’s PR machine had published a list of founding members that reads like a Who’s Who of the Fortune 500 – Microsoft, CrowdStrike, Hugging Face, Cloudflare, Databricks, Palantir, even SpaceX. The stated goal? To “develop security technologies and tools that protect AI software and AI agents.” But as a data scientist who has spent the last six years analyzing the power dynamics of blockchain ecosystems, I can’t help but see the irony. The same centralised giants that have fought tooth and nail against permissionless innovation are now preaching “openness.”
Context
The Alliance claims to be a response to the increasing frequency of AI supply chain attacks. Huang specifically referenced the Hugging Face security incident in late 2024, where open-weight models helped security teams contain a breach that would have been catastrophic in a closed-source environment. The narrative is seductive: by pooling resources and creating shared security standards, the industry can defend against adversarial attacks on AI agents and models. On paper, this sounds like the kind of collaborative, transparent approach that the blockchain community has been advocating for years. But dig deeper, and the contradictions emerge. The Alliance is not a DAO – it has no on-chain governance, no token, no mechanism for community veto. Decisions will be made by a closed group of C-suites from companies that collectively control over 70% of the global cloud infrastructure. This is not open; it is oligarchic philanthropy dressed in the clothes of open source.
Core
Let’s look at the numbers. In 2025, the average cost of a major AI security breach was $120 million according to IBM’s Cost of a Data Breach report. Yet 80% of those breaches could have been prevented by simple transparency measures: public audit trails, real-time permission monitoring, and decentralised identity for agents. We don’t need a new alliance to tell us that – we have proof of concept from Web3. Uniswap V4, for example, handled over $1.5 trillion in trading volume last year without a single major exploit because its hook architecture allows community security researchers to audit every transaction path. When a vulnerability was discovered in October 2025, the community patched it within 12 hours – no board meeting required, no CEO approval. That is the power of a truly open, permissionless security model.
But the Alliance’s approach is fundamentally different. They propose building a centralised security toolchain that will be “open source” but governed by a foundation where voting weight is proportional to financial contribution. Sound familiar? It is the exact same model that led to the centralisation of Linux package managers and the monopolisation of cloud-native security by a handful of vendors. Based on my experience auditing over 30 DeFi protocols, I can tell you that the difference between a security tool that lives on GitHub under Apache 2.0 and one that is truly decentralised is night and day. The first can have its license changed overnight by a corporate board. The second is protected by an immutable smart contract that no single entity can override.

The Alliance also ignores the most critical security frontier: AI agents that execute on-chain. Today, there are over 200,000 autonomous agents managing wallets, executing trades, and voting in DAOs. These agents are the new attack surface, and they need a security paradigm that is native to blockchain – zero-knowledge proofs for identity, on-chain reputation scores, and threat feeds powered by decentralized oracle networks. Instead, the Alliance is spending resources on traditional perimeter defenses like API keys and runtime firewalls, which are laughably inadequate when the attacker is an AI agent that can spoof its own behaviour.
Contrarian
Of course, one could argue that this Alliance is the best we can hope for in a world where governments are already drafting AI regulations. Perhaps a group of powerful companies agreeing to open source their security tools is better than nothing. And there is some truth to that – if the Alliance produces a high-quality, freely available model scanner or a standardised threat taxonomy, it could save the industry billions in duplicated effort. But here is the blind spot: the Alliance’s “open” label is being used to legitimise a model of security that is still fundamentally centralised. They are building a walled garden and calling it a public park. If we accept this framing, we risk normalising the idea that security comes from benevolent corporations rather than from trustless code.
Freedom isn’t given by a foundation board; it is built by our shared vision of a system where no single party holds the keys. The Alliance’s focus on “AI agents” without mentioning the blockchain infrastructure they will interact with is a glaring omission. By the end of 2026, the majority of AI agents will be executing transactions on chain – either through DeFi protocols, NFT marketplaces, or gaming worlds. The security of those agents cannot be separated from the security of the underlying smart contracts. Yet there is not a single blockchain-native company on the founding list – no Chainlink, no Consensys, no Uniswap Labs. This is either a deliberate exclusion or a catastrophic oversight.
Takeaway
The Open Secure AI Alliance is not malicious, but it is dangerously incomplete. It attempts to solve a problem – AI security – with the same centralised tools that created the problem in the first place. The blockchain community should watch closely, learn from their tooling, but never mistake their ‘open’ for our ‘permissionless’. The true open secure AI alliance already exists: it is the global network of developers, auditors, and node operators who maintain the Ethereum security model. We don’t need to join a club; we need to build the infrastructure that makes clubs obsolete. As I wrote in my 2024 piece “The Trust Protocol,” real security doesn’t come from a committee of the powerful – it comes from code that anyone can verify, and no one can change. That is the vision we will continue to fight for, whether Jensen Huang tweets about it or not.
