Much of the public discussion around AI and its impact on cybersecurity focuses almost exclusively on models, with some arguments calling for a central authority to manage the latest models behind closed doors. There have even been discussions around strictly regulating or outright banning open weights models in the interest of security. But as global regulators mull the future of open AI models, a core question falls by the wayside: How do we actually secure AI systems?AI security is a software challenge, not just a model issueAn AI agent isn't just a model but rather a complete software stack. Securing this system requires analyzing the core model, the agentic harness, sandboxing techniques, runtime guardrails, data controls, and a host of other underlying infrastructure layers. Crucially, three of those four components—harnesses, sandboxes, and traditional application layers—are fundamentally rooted in software engineering, not the model.Trying to secure the AI landscape by fragmenting software behind closed, proprietary boundaries simply shifts risk rather than solving it. Decades ago, when Linux first hit the scene, there was uncertainty and doubt cast around open source as a stable, secure solution for enterprise companies. Naysayers claimed only closed development could offer enterprise-grade reliability. However, time proved the exact opposite: open source software has since become the de facto catalyst powering a vast majority of global enterprise IT where scale and security are non-negotiable.We are seeing an exact echo of that resistance today. Just as Linux proved that transparency and community collaboration create a more robust operating system, open source AI models, open source agentic harnesses, and transparent sandboxing will prove to be the most secure foundation for the future of computing.Why open models and transparency are vital for defenseIn cybersecurity, transparency is part of how you create secure systems. As the old IT principle goes: security through obscurity is less secure.Limiting ourselves to a small set of proprietary models for cybersecurity research and threat mitigation introduces serious risks. Defenders have no way to manage what tools attackers choose to use. If researchers and security teams are restricted from accessing and inspecting open defensive models, they risk becoming blind to the tools and vectors exploited by threat actors. Furthermore, concentrating access within a handful of closed providers creates concentrated systemic risk.Broad access to open weights models gives defenders the exact tools needed to build effective mitigation strategies. Open models allow for broad scientific scrutiny, which is vital for identifying and addressing latent vulnerabilities that would otherwise remain hidden inside proprietary "black box" systems.We saw a clear example of this dynamic in action during a recent security incident involving Hugging Face. While the source of the vulnerability involved proprietary models (systems we are told to trust as inherently safe) the actual mitigations and protections were driven by open weights models. Open weights models were critical to resolving the threat. This is why Red Hat signed Microsoft's letter on Open Weights and American AI Leadership. Broad, open access to defensive tools spreads security pervasively across the software development lifecycle.Advancing state-of-the-art protection through shared learningWith this in mind, Red Hat is doing what we do best to help address the growing need for secure AI: working with the community. Most recently, as part of the Open Secure AI Alliance, Red Hat collaborated with NVIDIA, the Linux Foundation, and other members to develop a Request for Comments (RFC) for the Shared AI Findings Exchange (SAFE) Working Group. Until now, IT teams have investigated AI security incidents internally, keeping critical operational insights trapped within individual enterprise walls. The SAFE guidelines change that paradigm by creating a neutral framework to confidentially collect, analyze, and distribute findings from AI operational failures without placing blame.By supporting incident reporting and sharing threat intelligence openly, we advance the state of the art together. Through open collaboration, the entire ecosystem benefits: tools evolve faster, defensive capabilities grow stronger, and critical infrastructure becomes better protected against real-world attacks.Moving forward togetherWhether in base operations, software engineering, or enterprise application delivery, AI tools are advancing at unprecedented speed. A system's strength relies on a combination of core models and the open source harnesses wrapped around them to safely guide behavior toward intended outcomes.At Red Hat, we believe open collaboration and transparency remain the best, fastest, and safest ways to evolve technology. By focusing on original, human-driven insights and fostering open ecosystems – across open source software, open weights models, and open agentic harnesses – we can advance security alongside capability.The full SAFE RFC proposal is available now on GitHub for community review, discussion, and contributions.
Why IT security’s future is more than just AI models
Red Hat CTO Chris Wright breaks down why transparency and open weights models give defenders the tools needed to mitigate threats and advance IT protection.
Red Hat launched SAFE, a framework for sharing AI security incident findings across enterprises instead of siloed, proprietary defense. For IT leaders: transparent incident reporting breaks vendor lock-in and accelerates collective vulnerability discovery.








