Chief Technology Officer and Senior Vice President, Global Engineering

As AI capabilities advance, they transform the security landscape in real time. To address these challenges at scale, no single company can act in isolation. We must bring together our respective expertise across the industry. That is why Red Hat is proud to participate as an inaugural member of the new Open Secure AI Alliance with NVIDIA. This initiative focuses on developing open tools and techniques to safeguard the AI stack—from open weight models to agent harnesses—to help drive safety, transparency, and broad scientific scrutiny. Open source models and frameworks act as vital defensive assets. They broaden defensive capability, increase visibility for security practitioners, and prevent critical defensive intelligence from being locked behind proprietary walls.Scaling defensive speed through open source innovationDefending open source software requires an ecosystem approach. By coordinating upstream with maintainers, industry partners, and community foundations, we can better protect the shared digital infrastructure that banking, healthcare, telecom, and enterprise environments depend on every day.Red Hat’s commitment to securing the enterprise software fabric is rooted in the belief that security must be integrated directly into the open source development process. Our participation in efforts like the Open Secure AI Alliance builds upon our broader ecosystem strategy:Lightwell: Automated vulnerability discovery is essential, but it must lead to stable, production-ready fixes. Lightwell serves as our initiative with IBM to deliver hardened, verified remediation back to open source packages. By routing automated insights directly into structured open source processes, we help ensure that fixes are delivered reliably to upstream projects without disrupting software velocity.OpenAI Daybreak: AI accelerates vulnerability discovery, but addressing those vulnerabilities requires an open source process capable of scaling patches at the same speed. Participating in the OpenAI Daybreak Cyber Partner Program brings defensive AI tools directly to our developers and maintainers. Combining automated discovery with our established community patch pipelines allows us to mitigate systemic risk across software supply chains.Project Akrites: As AI workloads and agents scale across hybrid cloud environments, establishing consistent security boundaries, provenance, and operational governance becomes paramount. Through initiatives like Project Akrites, we are laying the foundational framework needed to govern and run AI-assisted tools securely alongside traditional containerized workloads.These initiatives are just the tip of the iceberg for our approach to more broadly securing open source at all levels, from AI models to the building blocks of Linux. We continue to drive initiatives around these requirements, including future work to push open source standards around AI safety and model guardrails.Trust is built on open collaborationAI models, agentic harnesses, and open source dependencies underpin the infrastructure of modern computing. Trying to secure this landscape by fragmenting behind closed, proprietary boundaries simply shifts risk rather than solving it.Open source is a critical pillar of global innovation. The best way to defend it is together—in the open, upstream, and with maintainers in control. By combining defensive AI tooling with established, community-driven remediation, Red Hat and our partners are working to deliver enterprise infrastructure that remains resilient, transparent, and trusted for the road ahead.