Security3 min read

Securing the AI Era: Broadcom Joins the Open Secure AI Alliance

Photo for Chris WolfChris Wolf
AI processor with interconnected data pathways representing secure AI infrastructure, open source collaboration, and cybersecurity innovation through the Open Secure AI Alliance.

The same AI capabilities that are making enterprises more productive are making them harder to defend. Cyberattacks that once required manual effort have become AI-driven, self-evolving campaigns that adapt faster than traditional defenses can respond. The security community needs tools that can match that pace, and open models and open source infrastructure are central to how we get there.

This is why Broadcom’s software business, and several other fellow industry partners, have joined NVIDIA as founding members of the The Open Secure AI Alliance, an industry-wide initiative for building an open and collaborative security ecosystem for the AI era. This ‌initiative, which builds on the leadership of the Linux Foundation’s Akrites initiative and OpenSSF community work, strives to remediate and disclose vulnerabilities using open technologies.

Broadcom served as one of the original Project Glasswing members, and in the months since that project was announced, we've been collaborating with industry peers, enterprise organizations, and government entities to share findings and refine best practices. Broadcom has historically played a significant role in driving open and interoperable technology ecosystems. We've been among the top contributors to Kubernetes for the past decade, with projects including Harbor, Antrea, Velero, and Contour originating from our engineering teams. And we’re the steward and primary maintainer of Spring (including Spring AI), RabbitMQ, Photon OS and Salt, widely adopted open source software used in application development and delivery. The security landscape presented a natural opportunity to bring that track record to the Open Secure AI Alliance.

Why Open Models and Tools Matter for Defense

Linus's Law states that “given enough eyeballs, all bugs are shallow.” In other words, if enough people are looking at a certain code, security and quality issues will be discovered. In cybersecurity, trust must be earned through verification. Open-source models and harnesses provide global visibility and auditability, community-based testing and innovation. These are examples of reasons why Broadcom supports open models, harnesses, and tools. 

Open-weight models have become a key part of how enterprises deploy AI privately and securely. You can take a capable, publicly available model, fine-tune it to a specific use case, and run it in an environment you fully control, with your data never leaving your perimeter. That combination of performance, flexibility, and data sovereignty is why open-weight models have proven effective for security use cases including vulnerability discovery. As a result, as fully open source models mature, both vendors and organizations will have greater options to control how safety guardrails are designed and enforced.

The important thing to understand is that neither open-weight nor fully open source models are the complete answer on their own, and no single model solves every problem at the optimum cost. A heavy reasoning model is the right tool for writing complex code or validating exploits. A smaller, lighter model handles high-speed tasks more efficiently. The organizations getting the most out of AI for security are matching their model choices to specific workloads rather than defaulting to one architecture for everything.

How We Are Putting This Into Practice

We have strategically integrated AI models into our product software security engineering work, including: vulnerability discovery, exploit validation, patch generation, and regression testing. The discipline required to get value from these models — context, tooling, direction, validation — has been embedded in how our engineering teams operate.

Broadcom’s operating view is that the defender community at large, including the organizations that depend on software, regardless of their scale or internal security resources, must be able to reach the same security outcomes through the vendors and partners they already trust. The use of Frontier AI models for security cannot be the exclusive domain of organizations large enough to build and run them independently. Making those capabilities accessible is part of what the Alliance is designed to do.

The Path Forward

The Open Secure AI Alliance is a key vehicle for the work that needs to happen next. Security frameworks that hold up under today’s rapidly expanding AI era are built in the open, tested broadly, and continuously refined by people with different threat models and different vantage points.

Broadcom is committed to that kind of sustained collaboration. The defender community needs it, and the pace of AI-driven threats makes it urgent.