IT Brief UK - Technology news for CIOs & IT decision-makers
United Kingdom
KnowBe4 backs Open Secure AI Alliance for AI defence

KnowBe4 backs Open Secure AI Alliance for AI defence

Thu, 30th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

KnowBe4 has endorsed the Open Secure AI Alliance, supporting an industry effort to develop open technologies for AI security while arguing that governing the behaviour of AI agents is as important as securing the models that power them.

The alliance was formed by NVIDIA with support from companies including Microsoft, Cisco, CrowdStrike and Palo Alto Networks. It aims to develop and share open technologies, techniques and tools for securing AI systems and autonomous agents.

Alliance focus

According to NVIDIA, the Open Secure AI Alliance builds on work by the Linux Foundation's Akrites initiative and the OpenSSF community. It seeks to advance open technologies that help organisations remediate and disclose vulnerabilities while improving the security of AI systems.

The alliance argues that AI security depends on more than whether a model is open or closed. Instead, it says effective protection requires security across the full AI agent stack, including identity, permissions, harnesses, guardrails, logs and evaluation.

NVIDIA also said contributors are developing an open defence stack for AI agents. Planned work spans identity frameworks, secure model formats, multi-model scanning, secure coding workflows and agent governance research.

Agent governance

KnowBe4 said its support for the alliance reflects its focus on managing the behaviour of AI agents once they are deployed within organisations.

"The Alliance is asking the right question. Its own framing is worth repeating: security in this new era depends on the full agent stack - identity, permissions, harnesses, guardrails, logs and evaluation - not just whether a model's weights are open or closed," said KnowBe4.

"We agree. It is why we've spent the last several years building the part of that stack that sits closest to how agents actually behave once they're deployed inside a real organisation," said KnowBe4.

The company said it views the modern workforce as comprising both people and AI agents. It argued that organisations need continuous visibility into how AI agents operate after deployment rather than relying solely on model-level security controls.

Behaviour monitoring

KnowBe4 said this approach led to the development of its Agent Risk Manager platform, which it described as a governance layer designed to monitor autonomous AI agents in production environments.

"At KnowBe4, we believe that the modern workforce is people plus AI agents - and either one could be behind your next security incident. Model security and harness security answer one question: can this system be trusted in principle? But, there's a second question that matters just as much: what is this specific agent doing right now, in this environment, with these permissions?" said KnowBe4.

"That's the question our Agent Risk Manager was built to answer. It's a production-ready governance layer for autonomous AI agents - giving security teams real-time visibility into what an agent is touching, what data it's moving, and whether a prompt injection has redirected it. It works regardless of whether the underlying model is open or closed, and without requiring access to the model's weights," said KnowBe4.

The company said monitoring agent behaviour addresses operational risks that may emerge after deployment, regardless of the underlying AI model.

Shared defence

KnowBe4 also referenced a recent security incident involving Hugging Face, arguing that the issue demonstrated the importance of observing AI agent behaviour rather than focusing exclusively on model weights.

"We built it because we kept seeing the same pattern the Alliance referred to: when the OpenAI agent broke containment and attacked Hugging Face, the initial failure had nothing to do with the weights themselves. Instead, the actual issue was a behaviour nobody was watching for until after it had already happened," said KnowBe4.

"That pattern is familiar to us. We've spent 15+ years securing the human side of the workforce, and the lesson translates directly: you don't just vet who someone is before they start a job, you watch what they do once they're doing it. AI agents are the newest members of the workforce and they deserve the same standard."

"Open, shared infrastructure for AI defence is exactly the kind of investment this moment calls for and AI agent behaviour governance belongs in that conversation, alongside model weights and harnesses. Our mission is protecting the modern workforce, both humans and AI agents, and we welcome the industry's shared commitment to this vision," said KnowBe4.