Open Secure AI Alliance: Why the Future of Enterprise AI Depends on Owning Your Intelligence, Not Renting It
Written by Rhys Oxenham, VP and GM of AI, SUSE
In the rush to deploy artificial intelligence, enterprise leaders are confronting an uncomfortable reality: convenience has come at the expense of control. Relying exclusively on third-party API endpoints exposes organizations to unpredictable costs, context leakage and sudden access restrictions. The strategic mandate emerging across the industry is clear: enterprises need to own their intelligence, not rent it.
Owning that intelligence, however, requires far more than downloading an open-weight model. It demands an entire technology stack, from silicon up through the runtime to the AI framework itself, that is transparent, inspectable and secure by design. No single vendor can deliver true operational resilience from inside a proprietary silo, and no enterprise should trust a “sovereign” solution that is itself trapped inside a closed architecture.
This is the problem the newly formed Open Secure AI Alliance has been built to address. Founded around NVIDIA and joined by a growing group of industry players, including SUSE, the Alliance brings together infrastructure, security and AI vendors around a shared goal: establishing open standards, inspectable tooling and auditable frameworks across the entire AI lifecycle, so that enterprise AI can be both sovereign and secure by design, rather than one or the other.
Why the case for open just got urgent
A recent security incident involving Hugging Face illustrated the urgency of this shift starkly. As increasingly autonomous AI systems interact with enterprise infrastructure, security teams are discovering that proprietary endpoints create dangerous blind spots. When incident responders needed to perform rapid local forensics and contain the breach, closed commercial tools failed to provide the visibility required. Defenders turned instead to open-weight models deployed on local infrastructure, not as a compromise, but because open-weight models have now reached the maturity and capability needed for serious, real-time enterprise use.
The incident proved a vital point for the industry: effective AI defence cannot be outsourced to third-party endpoints where an organization lacks the authority to direct the response, nor can it rely on a single vendor’s closed cloud. Achieving genuine “defensive velocity”, and long-term digital sovereignty alongside it, requires inspectable tools, open-weight models and ecosystem-wide open standards working together.
Defining Private Enterprise AI
The Alliance’s work centers on a concept increasingly referred to as Private Enterprise AI. To be clear, “private” here does not mean restricting workloads to a legacy on-premises data center. It means private to the organization itself. Whether deployed in a core data center, at the edge, in a specialized NeoCloud, or across public cloud infrastructure, Private Enterprise AI is about guaranteeing complete ownership of an organization’s technology stack, domain workflows and proprietary intellectual property, regardless of where the workload physically runs.
Relying exclusively on third-party APIs turns AI adoption into a compounding financial burden, with costs scaling unpredictably as usage grows. Shifting toward Private Enterprise AI allows organizations to move to a more controllable model while retaining the flexibility to draw on public cloud resources on their own terms. Recent global shifts have also shown how quickly access to frontier models can be altered by changing export controls or vendor access restrictions, underlining why direct control over infrastructure matters strategically, not just financially.
The rapid advancement of open-weight models, including Google DeepMind’s Gemma, Mistral Large, Z.ai GLM and Kimi K3, means near-frontier capability can now be hosted safely in-house as a sovereign baseline. This gives organizations true choice: dynamically balancing performance, cost and privacy across a hybrid model portfolio, rather than being locked into a single vendor’s roadmap.
Security has to start below the application layer
An AI model is only as secure and reliable as the environment hosting it. True operational resilience, and alignment with evolving regulatory frameworks such as the European AI Act, cannot be achieved at the application layer alone. Traceability, data protection and model lineage need to be enforced continuously throughout the underlying runtime.
When autonomous AI threats emerge, security teams cannot defend what they cannot inspect. Closed commercial endpoints obscure the telemetry required for threat hunting, auditing and incident response. Open-weight architectures and inspectable frameworks give enterprise defenders the transparency needed to audit workflows, run local forensics and isolate threats in real time. This is precisely the open innovation model the Open Secure AI Alliance is designed to accelerate, allowing the global ecosystem to identify software supply chain vulnerabilities and harden systems faster than any closed platform could act alone.
A shared foundation, not a single vendor’s vision
As such, the industry needs to hold onto two truths simultaneously. Open source has a vital part to play in driving the rapid innovation and near-frontier capabilities that make Private Enterprise AI fully viable. At the same time, an AI stack and its security posture are more than just a model; they require enterprise safeguards, zero trust security and a hardened underlying runtime. When speed, privacy and local execution matter, having the power to run and observe advanced models safely within your own control eliminates single points of failure and guarantees true business continuity.
As the discussion around enterprise AI matures, the conversation needs to move beyond model chasing and toward the underlying infrastructure that makes AI trustworthy at scale. Grounded in open standards, hardened runtimes and a shared commitment to Private Enterprise AI, initiatives like the Open Secure AI Alliance point toward a future where trust, security and speed are not competing priorities, but reinforce one another.



