Agent协议

Nvidia牵头AI安全联盟
九天120+公司加入

Nvidia-Led AI Security Alliance
120+ Companies in Nine Days

7月27日成立时37家创始成员,8月4日已超120家并发布Agent防御提案,AI安全标准化速度前所未有。

Founded July 27 with 37 members; by August 4 it topped 120 and released Agent defense proposals — AI safety standardization is moving at unprecedented speed.

No.029 2026.08.05 约 5 分钟阅读 ~5 min read

7月27日,黄仁勋在X上发了两条推文,宣布联合37家企业成立Open Secure AI Alliance(OSAA,开放安全AI联盟)。九天后,TechCrunch在8月4日报道:联盟成员已经超过120家,并且已经拿出了第一份AI Agent防御相关的技术提案。

这个扩张速度在科技行业标准组织的历史上几乎是前所未有的。通常一个行业联盟从成立到拿出第一份像样的技术提案,需要半年到一年;成员从30多家扩张到120家,通常需要一两年。OSAA九天完成了别人两年的工作量,这背后是整个AI行业对Agent安全问题的集体焦虑。

为什么是Nvidia拉群?

OSAA的创始成员名单堪称"美国科技圈复仇者联盟":芯片厂商(英伟达、戴尔、HPE)、云巨头(微软、IBM、Salesforce)、安全公司(CrowdStrike、Palo Alto Networks)、AI实验室(虽然OpenAI、Anthropic、Google DeepMind的名字缺席了创始名单,但据传都在以观察员身份参与)。

牵头的是Nvidia而不是OpenAI或Anthropic,这件事本身就很有意思。黄仁勋在成立帖文里的措辞很直接:"攻击者已经掌握了前沿AI,防御方必须联合起来。"

为什么是Nvidia?因为它是AI产业链上唯一一个"所有人都需要、但不直接和任何AI应用厂商竞争"的玩家。Nvidia卖铲子,不管谁挖着金子它都赚钱。由它来牵头做安全标准,各方都能接受——不会像OpenAI牵头那样被质疑"既当运动员又当裁判员"。

触发联盟成立的直接导火索是7月下旬集中曝光的多起AI Agent安全事件:红队测试中AI Agent成功入侵真实公司系统、开源模型被用于生成恶意代码、公开的GitHub Issue可以诱导Agent泄露私有代码。这些事件传递了一个清晰的信号:AI Agent的能力已经强到可以造成真实损害,但整个行业还没有一套统一的防御标准。

Agent防御提案的核心内容

虽然OSAA的完整提案还没有公开,但从TechCrunch的报道和相关讨论中,可以看到三个核心方向。

第一是Agent行为溯源和审计标准。要求所有Agent在执行敏感操作(文件写入、网络请求、数据库修改、外部通信)时留下不可篡改的审计日志,包括:谁给的指令、Agent做了什么决策、调用了哪些工具、产生了什么结果。出了安全事件能追溯,这是防御的基础。

第二是Agent权限沙箱的标准化接口。不同厂商的Agent框架(LangChain、AutoGen、CrewAI、Vercel AI SDK等)目前权限模型各不相同,OSAA想推动一套统一的沙箱接口标准,让安全工具可以跨框架监控和拦截Agent的危险操作。就像网络安全领域的WAF(Web应用防火墙)一样,未来可能出现"Agent WAF"。

第三是模型越狱和恶意提示的检测数据集与基准。联盟计划开源一套标准化的红队测试数据集和评测基准,用来评估模型和Agent框架对抗越狱、提示注入、数据窃取的能力。这相当于给AI安全做了一个"碰撞测试标准"——你的Agent安全不安全,跑一遍基准就知道。

速度是OSAA最大的武器。九天拿出提案、九天扩到120家成员,这种速度在以前的科技标准组织里不可想象。这也说明AI行业的安全共识已经到了"不得不做"的临界点。

当然也有质疑的声音。有人指出OSAA的成员里缺少了OpenAI、Anthropic、Google这三家最前沿的模型厂商作为正式成员,影响力会打折扣;也有人担心Nvidia主导的标准会偏向Nvidia的硬件生态;还有人说120家成员里有多少是真心做安全、多少是来蹭热点贴logo,要打个问号。

但不管怎么说,AI Agent安全从"各家自扫门前雪"进入"行业联盟联合防御"阶段,这是好事。Agent协议的战争(MCP、A2A、ACP、AG-UI)还在继续,但安全防御是所有协议都必须支持的底层能力——OSAA可能成为第一个跨协议的安全标准。

当AI Agent开始真正走进企业、走进生产系统,一把所有人都认可的安全锁,比一把无人能开的超级锁更有价值。

明天见。

On July 27, Jensen Huang posted two tweets on X announcing the formation of the Open Secure AI Alliance (OSAA) with 37 founding members. Nine days later, TechCrunch reported on August 4 that membership had surpassed 120 companies, and the alliance had already produced its first technical proposals related to AI Agent defense.

This pace of expansion is virtually unprecedented in the history of tech industry standards bodies. Typically, an industry alliance takes six months to a year to go from formation to producing a credible technical proposal; growing from 30-some members to 120 usually takes one to two years. OSAA accomplished nine days what takes others two years, reflecting the entire AI industry's collective anxiety about Agent security.

Why Is Nvidia Organizing This?

OSAA's founding member list reads like an "Avengers of American tech": chipmakers (Nvidia, Dell, HPE), cloud giants (Microsoft, IBM, Salesforce), security firms (CrowdStrike, Palo Alto Networks), and AI labs (though OpenAI, Anthropic, and Google DeepMind were absent from the founding roster, they're reportedly participating as observers).

That Nvidia is leading this rather than OpenAI or Anthropic is itself noteworthy. Jensen Huang's wording in the founding post was blunt: "Attackers have access to frontier AI. Defenders must unite."

Why Nvidia? Because it's the only player in the AI supply chain that "everyone needs but which doesn't directly compete with any AI application vendor." Nvidia sells shovels; it makes money no matter who strikes gold. Having it lead security standards is acceptable to all parties — unlike if OpenAI led, there's no accusation of "being both player and referee."

The immediate catalyst was a cluster of AI Agent security incidents in late July: red-team tests where AI Agents successfully breached real company systems, open-source models being used to generate malware, public GitHub Issues that could trick Agents into leaking private code. These incidents sent a clear signal: AI Agents are now powerful enough to cause real damage, yet the industry lacks unified defense standards.

Core of the Agent Defense Proposals

Although OSAA's full proposals aren't yet public, three core directions emerge from TechCrunch's reporting and related discussions.

First, Agent behavioral provenance and audit standards. Requiring all Agents to leave tamper-evident audit logs when executing sensitive operations (file writes, network requests, database modifications, external communications), including: who gave the instruction, what decisions the Agent made, which tools it called, what the outcomes were. When security incidents happen, you can trace them — this is the foundation of defense.

Second, standardized interfaces for Agent permission sandboxes. Different Agent frameworks (LangChain, AutoGen, CrewAI, Vercel AI SDK, etc.) currently have different permission models; OSAA wants to push a unified sandbox interface standard so security tools can monitor and block dangerous Agent operations across frameworks. Just as cybersecurity has WAFs (Web Application Firewalls), the future may bring "Agent WAFs."

Third, datasets and benchmarks for detecting model jailbreaks and malicious prompts. The alliance plans to open-source a standardized red-teaming dataset and evaluation benchmark for assessing models' and Agent frameworks' resistance to jailbreaks, prompt injection, and data exfiltration. Think of it as a "crash test standard" for AI safety — run the benchmark and you'll know how safe your Agent is.

Speed is OSAA's greatest weapon. Proposals in nine days, 120 members in nine days — this pace was unimaginable for previous tech standards bodies. It also shows that AI industry consensus on security has reached a "do it now or else" tipping point.

There are, of course, skeptics. Some point out that OpenAI, Anthropic, and Google — the three most frontier model makers — aren't formal founding members, which could dilute influence; others worry that Nvidia-led standards will favor Nvidia's hardware ecosystem; still others question how many of the 120 members are serious about security versus just slapping a logo on a press release.

But regardless, AI Agent security moving from "every company for itself" to "industry alliance joint defense" is a good thing. The Agent protocol wars (MCP, A2A, ACP, AG-UI) continue, but security defense is a foundational capability every protocol must support — OSAA could become the first cross-protocol security standard.

As AI Agents genuinely enter enterprises and production systems, a security lock everyone agrees on is more valuable than a super-lock nobody can open.

See you tomorrow.

攻击者已经掌握了前沿AI,防御方必须联合起来。

—— 黄仁勋,OSAA成立声明

Attackers have access to frontier AI. Defenders must unite.

— Jensen Huang, OSAA founding statement
Open Secure AI Alliance · OSAA · Nvidia · 黄仁勋 · AI安全 · Agent防御 · 安全标准 · 120家成员 · 行为审计 · 沙箱标准
Open Secure AI Alliance · OSAA · Nvidia · Jensen Huang · AI safety · Agent defense · security standards · 120 members · behavioral auditing · sandbox standards
Sources · 信源 Sources

本文基于 Dawn Vision 认知引擎处理的 9 个源信号生成,经编辑部人工审核。素材来源:TechCrunch、搜狐科技、黄仁勋X平台。

This article was generated by the Dawn Vision cognitive engine processing 9 source signals, with human editorial review. Sources: TechCrunch, Sohu Tech, Jensen Huang on X.