OpenHands Joins the Open Secure AI Alliance to Help Build AI Security in the Open

Written by

Robert Brennan

Published on

AI agents are quickly moving from individual developer tools to systems that operate across repositories, infrastructure, and entire organizations.

That shift changes the security conversation. Securing an AI agent is not only about securing the model. An agent is a complete system made up of models, harnesses, execution environments, identities, permissions, integrations, policies, and logs. Every layer affects what the agent can do, what it can access, and whether its actions can be observed and governed.

That is why OpenHands has joined the Open Secure AI Alliance, a new industry initiative launched by NVIDIA and partners across AI, cybersecurity, enterprise software, cloud infrastructure, and open source.

The Alliance is focused on developing and sharing open technologies, techniques, and tools that help defenders secure software, AI agents, and the infrastructure around them. Its founding premise is one we strongly share: defenders need access to security infrastructure they can inspect, test, adapt, and improve for the environments they are responsible for protecting.

Agent security requires an open systems approach

The AI security debate is often reduced to whether a model is open or closed. But models are only one layer of the agent stack.

Once a model is connected to a harness, given tools, and allowed to operate inside a real environment, the security boundaries expand considerably. Teams must determine:

  • Which users and agents are allowed to initiate work

  • What repositories, services, and data an agent can access

  • Which commands and tools it can execute

  • Where the execution takes place

  • How credentials and permissions are scoped

  • Whether every action can be traced and audited

  • How suspicious or unintended behavior is detected

  • How vulnerabilities are reported and remediated

NVIDIA’s Alliance announcement makes the same distinction: meaningful AI safety depends on the full agent stack, including identity, permissions, harnesses, guardrails, logs, and evaluation. Open harnesses and security tools give more defenders the ability to inspect, test, and improve those controls rather than treating agent behavior as a black box.

This is foundational to how we are building OpenHands. OpenHands is the open source platform for building and running software engineering agents, with the interface, automation, execution, and control layers needed to move from a single local agent to a system operating across an organization. Developers can inspect and extend the open framework, choose models that meet their requirements, review supported tool and execution activity, and deploy the platform on infrastructure they control.

Openness is a security capability

Open source does not automatically make a system secure. It does make a different security model possible.

When agent infrastructure is open, defenders can examine the execution path instead of relying entirely on vendor assurances. They can test how the system behaves under failure, add controls for their own threat model, validate what information leaves an environment, and contribute fixes that benefit the broader ecosystem.

Open systems also reduce reliance on a single provider. Organizations can choose different models for different tasks, operate agents inside controlled environments, and maintain the ability to respond when external services are unavailable or inappropriate for a sensitive workload.

This matters especially in areas such as vulnerability remediation, incident response, secure software development, and critical infrastructure. Defenders may need to run capable models locally, customize their tooling, analyze sensitive data within an approved environment, or modify a harness to support an urgent investigation. Achieving that boundary depends on the full configuration, including model endpoints, integrations, logging, and telemetry.

The Alliance was formed around the principle that defenders need access to capable open models, harnesses, and tools, alongside closed systems, so they can select and control the right technology for the job.

At OpenHands, we use a simple design principle for that foundation: Your environment. Your models. Your control. That principle is already reflected in how OpenHands is built and used across the open-source ecosystem.

What OpenHands contributes to the open security ecosystem

OpenHands is not approaching this work from theory alone. The project already provides open infrastructure used to build, run, evaluate, and study capable software agents.

The OpenHands agent harness is MIT-licensed and designed to make agent execution more inspectable and configurable. Teams can run agents inside self-deployed Docker environments, control where execution happens, and adapt security configurations to their own requirements through agent instructions, runtime configuration, and organizational policies.

This creates a practical foundation for security research as well as production deployment. Researchers can inspect the full agent loop, reproduce experiments, substitute models, modify tools and safeguards, and evaluate how agents behave when they interact with real systems.

That openness has made OpenHands useful beyond production deployments. Researchers use the harness to study how agents behave when they can actually browse, execute commands, modify files, and interact with software environments rather than only generate text. OpenHands researchers also contributed to OpenAgentSafety, an extensible benchmark that evaluates agent behavior across more than 350 benign and adversarial tasks.

Other recent research has used OpenHands to study whether coding agents introduce vulnerabilities and how tool-using agents behave across longer, multi-turn interactions. That work reinforces an important point: agent security cannot be solved with a single system prompt or model-level safeguard. It requires evaluation, isolation, policies, observability, and controls that extend into the environments where agents actually act. Other recent work has used OpenHands to study whether coding agents introduce vulnerabilities and how tool-using agents behave over longer interactions.

OpenHands also provides an open harness for developing and evaluating open models. It supports a broad range of models without tying the agent system to a single provider.

With more than 80,000 GitHub stars, OpenHands’ large open source community creates an opportunity to test these ideas in public, surface failure modes quickly, and turn lessons from researchers and practitioners into infrastructure others can inspect and reuse.

From open agents to controlled agent infrastructure

Developers are already proving that coding agents can perform meaningful engineering work. They can investigate failures, modify code, review pull requests, update dependencies, and execute multi-step workflows.

The next challenge is making those capabilities safe and repeatable beyond one developer’s laptop. As agents spread across teams, organizations need infrastructure that can define execution boundaries, govern access, monitor usage, and preserve a durable record of relevant agent and workflow activity. They need to know not just which model produced an answer, but what the agent actually did.

OpenHands is designed around that progression. Developers can begin locally with an open, model-agnostic agent environment. Teams can turn useful workflows into shared automations that run against GitHub, Slack, CI systems, and other engineering tools. As adoption grows, the OpenHands Agent Control Plane adds the organization-level governance, visibility, access controls, and deployment options needed to operate those workflows across teams.

The goal is not to weaken agent capability in exchange for governance. It is to give agents the freedom to do meaningful work inside clearly defined and observable boundaries.

Building the open defense stack for agents

The Open Secure AI Alliance brings together organizations working across identity and isolation, safe model formats, vulnerability scanning, secure coding workflows, agent evaluation, and the infrastructure used to test, trace, and govern agent behavior.

OpenHands represents the part of that stack where agents interact with source code, engineering tools, and execution environments. We are joining the Alliance to help develop open foundations for making those interactions more observable, controllable, and secure.

No single company can secure the entire agent ecosystem alone. Models, runtimes, identity systems, sandboxes, security tools, and control layers need shared interfaces and standards that allow each layer to be evaluated independently and improved collectively.

We look forward to collaborating with NVIDIA and the broader Alliance community on those foundations as agents become a larger part of how software is built and operated.

About OpenHands

OpenHands is the open-source platform for building and running software engineering agents, with the interface, automations, and control layer needed to go from a single local agent to a system running across an entire organization. The mission is to make agent-based software development accessible, transparent, and controllable by default. That starts in the open.

Developers can start locally with Agent Canvas, connect the models and tools they already use, and run agents against real repositories. As workflows mature, teams can turn one-off agent wins into repeatable automations that keep working when the laptop is closed. For organizations scaling agent usage, OpenHands Enterprise adds the control layer required to run agents safely across teams, repositories, and environments.

Join the OpenHands community and help us build the agentic SDLC in the open. Contribute to the project, share what you’re building, and help shape the open infrastructure developers and organizations need to run increasingly capable agents with more visibility and control. Download OpenHands to start running agents locally, automate real engineering workflows, and scale them when you’re ready.

Get useful insights in our blog

Insights and updates from the OpenHands team

Sign up for our newsletter for updates, events, and community insights.

By submitting your email you agree to our Privacy Policy