---
title: Canonical joins the Open Secure AI Alliance
description: Canonical is now part of the Open Secure AI Alliance, working with NVIDIA
  and partners to safeguard software and agents in the age of AI.
url: https://canonical.com/blog/open-secure-ai-alliance?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

28 August 2026

# Canonical joins the Open Secure AI Alliance

[AI/ML](https://canonical.com/blog/tag/ai-ml)
[nvidia](https://canonical.com/blog/tag/nvidia)
[Security](https://canonical.com/blog/tag/security)

---

Share the article

Canonical is now part of the [Open Secure AI Alliance](https://blogs.nvidia.com/blog/open-secure-ai-alliance/), announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and AI research. The alliance aims to develop and share open technologies, techniques, and tools to safeguard software and agents in the age of AI.

## **The bedrock for AI**

Alongside NVIDIA and a coalition of industry leaders, we are embarking on a critical mission: to ensure that the tools needed to secure the age of AI are open, transparent, and accessible to defenders everywhere.

The Open Secure AI Alliance recognizes a fundamental truth: an AI agent is more than just its model weights. It is a full stack of software, harnesses, and guardrails. And at the base of that stack sits the infrastructure.

Ubuntu is the platform of choice for AI development and deployment, from a developer’s workstation to the edge and the data center. The security of that platform shapes the security of everything built on top of it, making Canonical’s role in securing the AI ecosystem a natural fit.

## **Open source makes verification possible**

When the source is open, you can inspect it, test it, and confirm the software does what it says it does. Then you can make the software better, and more resilient yourself, and publish the fixes for everyone running it.

The same holds across the agent stack. Identity, permissions, guardrails, logs, and evaluation are easier to check when the code and the tooling are open source. That is what open source tools give defenders. More to examine, and more to improve.

## **Resilient AI open source software stack**

Resilience starts with the platform underneath. Ubuntu LTS supports UEFI Secure Boot to verify the boot chain, and AppArmor is enabled by default to confine applications. TPM-backed full-disk encryption can be enabled during installation, protecting disk-encryption keys and releasing them only when the machine boots into an expected state. For workloads that need data protected while it is being processed, Ubuntu supports [confidential computing](https://ubuntu.com/confidential-computing) as both guest and host, enabling confidential AI use cases with silicon-level encryption.

An AI system depends on far more than the operating system (OS). Libraries, runtimes, databases, message queues, and monitoring tools all sit on top of the OS, and much of that software comes from the wider Ubuntu archive, rather than the core set of packages. [Ubuntu Pro](https://ubuntu.com/pro) extends Canonical’s maintenance across that whole archive, including the Universe repository, with up to 15 years of security maintenance, compliance, and support.

This coverage is critical for environments that demand high stability. Financial services, healthcare, telecommunications, energy, manufacturing, automotive, and public sector teams keep the same release in production for a long time, and the software running on it has to be maintained for just as long. AI infrastructure is starting to work the same way, and that kind of long-term maintenance is what Canonical has been doing for years.

Trust in AI will be earned the way trust in open source was earned. In public, over time, with the work available for anyone to check.

We are glad to be part of it.

Learn more about the [Open Secure AI Alliance](https://blogs.nvidia.com/blog/open-secure-ai-alliance/).

Learn more about security maintenance with [Ubuntu Pro](https://ubuntu.com/pro).

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Securing AI agent workflows on Ubuntu with the new NVIDIA OpenShell snap](https://canonical.com/blog/nvidia-openshell-ubuntu-announcement)

By packaging OpenShell as a snap, Canonical is enabling enterprises to confidently run next-generation agentic workflows across local devices, hybrid environments, and private clouds.

[Canonical](https://canonical.com/blog/author/canonical)

1 June 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
