Who’s Securing Your AI? Big Tech Just Formed a Watchdog

Who's Securing Your AI? Big Tech Just Formed a Watchdog — featured image

by

Your AI Assistant Could Be Your Biggest Security Blind Spot

You set up a chatbot on your business WhatsApp to answer customer questions at night. It replies instantly, collects names and order numbers, even helps customers track deliveries. Feels like a win — your business now works while you sleep.

Now picture this: one evening, the chatbot starts pulling up details it shouldn’t. A customer asks for his invoice, and the bot sends him the full name and address of a completely different customer. Would you even know how it happened? Could you trace it? For most Malaysian SME owners, the honest answer is no. And that is precisely the problem the world’s heaviest tech players just formed an alliance to solve.

Last week, Nvidia and roughly 120 companies launched the Open Secure AI Alliance (OSAA) — a consortium focused entirely on AI security. Within seven days, it has already produced working groups, proposed guidelines, and open-source contributions. For an industry group, that is unbelievably fast. These things usually take months to agree on a logo, let alone publish technical proposals.

TL;DR — Here’s what you need to know:

  • Nvidia’s OSAA, a 120+ member group, is already publishing AI safety proposals less than a week after forming.
  • The proposals cover confidential incident reporting, alerting affected parties, and blame-free analysis — so the whole industry can learn from AI failures instead of repeating them.
  • For a Malaysian SME like yours, this means AI tools will get safer over time, but you still need basic protection habits right now.

What This Means

The alliance created a working group called the Shared AI Findings Exchange, or SAFE — because of course it’s called SAFE. The Linux Foundation is managing the proposals. According to TechCrunch’s report, the proposals aren’t earth-shattering yet. They focus on practical mechanics: how companies can confidentially report AI security incidents, how to alert people who were affected, and how to do a blame-free review afterward so everyone can learn from one failure. The letter that started it all was signed by over 200 tech companies, which shows how much pressure the industry felt.

At the same time, members are uploading pieces of their open-source technology. Nvidia contributed Garak, an open-source LLM vulnerability scanner. Okta is contributing agent identity tech. Red Hat is working on agent governance. Amazon contributed Strands Agents plus an authorization language called Cedar. This is significant because it means actual code — not just intentions — is being shared.

Something else stands out: the article notes notable absences like Anthropic, OpenAI, and Google. Both OpenAI and Google signed the original open letter, and both have released open-weight models of their own. Yet they haven’t joined the alliance. That creates a fascinating split — the makers of the world’s most famous chatbots are separate from the group actively building security standards.

How This Applies to Malaysian SMEs

You might think, “I run a boutique bakery, not a data centre.” Fair enough. But SMEs make up the vast majority of businesses in Malaysia, and most of you are already using AI. Whether it’s ChatGPT for product descriptions, Canva for social media images, or a customer-service bot in your e-commerce store, every one of those tools touches your customers’ information. The standards being built this week in a Las Vegas convention hall will eventually shape the security features baked into all of them.

Here’s the part that should genuinely interest you: the blame-free reporting model. In Malaysia, we already know how valuable this is from the banking sector. Banks share fraud intelligence across the industry so a scam detected at one bank triggers alerts everywhere. That’s essentially what SAFE wants to do for AI incidents. As a small business owner, you don’t have a security department. You rely on the wider ecosystem to discover problems and fix them. An alliance that shares AI failure data means patches, warnings, and fixes reach your tools faster than ever before. You get the benefit of shared industry intelligence without needing your own security team.

But here’s the uncomfortable truth: the alliance won’t protect you today. The article reminds us of real-world attacks, like the OpenAI model that infiltrated Hugging Face — a legitimate AI manipulated to act maliciously. The same principle applies to your business chatbot. If your bot is connected to your customer database, your order system, or your WhatsApp Business account, it can be tricked through prompt injection — hidden instructions inside a message that override the bot’s rules. The fix isn’t waiting for an alliance; it’s limiting what your AI tools can access, separating them from sensitive systems, and knowing exactly how to shut them down.

Finally, notice the open-source angle. Open-source technology is transparent — anyone can inspect the code and find flaws. That’s why Nvidia contributing Garak and Amazon contributing Cedar matters. In Malaysia, plenty of SME software vendors build on these open-source foundations. When a vendor tells you their AI system is built on secure, community-audited components, that’s a genuine signal of quality. You don’t need to read code to verify — just ask which security frameworks they follow and whether they track recommendations from groups like this.

Practical Takeaways

  • Inventory your AI. Write down every AI tool you and your staff use. Next to each, note what customer data it can read or store. You can’t secure what you can’t name.
  • Ask your vendors: “Which AI security standards do you follow?” If they look confused, that’s your answer. Favour vendors who engage with industry efforts like OSAA.
  • Set up a shutdown drill. If your bot starts misbehaving today, who unplugs it? Who notifies affected customers? Put actual names on a piece of paper.
  • Turn on activity logs. Most AI platforms have usage history or logging features. Turn them on so you have a trace if something goes wrong.
  • Segment access. Never connect your AI chatbot directly to your entire customer database. Give it the minimum access it needs — and keep your AI accounts separate from your main admin accounts.

The Bigger Picture

Think about how SSL certificates became universal. Twenty years ago, you had to understand what the padlock icon meant. Today, you notice when it’s missing. AI security is heading down the same path. Within a few years, AI vendors will be advertising compliance with the kinds of frameworks the OSAA is building — just like websites advertise encrypted connections. Malaysian SMEs that build the habit of asking “who secures this?” now will be years ahead of competitors who just click “Accept”.

The movement isn’t without tension. The fact that OpenAI, Google, and Anthropic are sitting out while Microsoft, Intel, Cisco, and Visa sit in is worth watching. The standards that emerge could shape what AI products look like — and which ones gain trust. For your business, that’s actually a good thing: competition for your trust means the tools you use will keep improving. The alliance is operating at what TechCrunch calls “AI speeds” — and you should too.

“Openness may be one of the most important paths to AI safety and security,” the alliance wrote in its founding letter — and it’s backing that claim with working groups and shipping code in under a week. When the industry openly shares its failures, small businesses like yours stop repeating them.

What each contributor is bringing to the table

Company Contribution Why it matters to your SME
Nvidia Garak — open-source LLM vulnerability scanner Scans AI models for weaknesses before they reach products you use
Okta Agent identity technology Confirms an AI agent is who it claims to be — like an employee ID for bots
Red Hat Agent governance Rules for what AI agents can and cannot do inside a system
Amazon Strands Agents + Cedar authorization language Building blocks for secure AI agents plus controls over who accesses what

Source: TechCrunch’s report on the OSAA

The takeaway is simple. Big Tech just decided, collectively and visibly, that AI security can’t wait. For your bakery, your hardware store, or your logistics company, that’s a good sign — smarter, safer AI tools are coming. Just don’t wait for them. The padlock on your website didn’t protect you by magic; you installed it. Treat your AI tools the same way.

Ready to Streamline Your Operations?

Your business should run itself. AutoRunBiz deploys AI agents to automate your daily operations — WhatsApp orders, invoicing, customer follow-ups, and accounting. Book a free 15-min ops audit to see where automation fits your business →