Databricks Joins Open Secure AI Alliance as Founding Member; Contributes Omnigent Meta-Harness, DASF 3.0 Security Framework
Databricks announced it is a founding member of the Open Secure AI Alliance, a coalition of 75+ organizations across chips, models, security, and infrastructure dedicated to advancing AI safety and security through open research, open models, harnesses, tooling, and shared learnings. The alliance, which includes NVIDIA and other industry leaders, operates on the principle that critical security intelligence locked inside closed systems leaves the broader ecosystem exposed. Members are contributing openly to accelerate development of new cybersecurity tools and agentic AI defense mechanisms.
Databricks contributes four core open-source projects to the alliance. Omnigent (Apache 2.0) is an open meta-harness for composing and controlling how agents use models and tools, supporting 13+ harnesses with contextual policy enforcement, spend caps, and sandbox isolation. It integrates with NVIDIA OpenShell for kernel-level governance backend. DASF 3.0 is a vendor-agnostic AI security framework cataloging 97 technical security risks across 13 components and mapping them to 73 mitigation controls, cross-referenced to MITRE ATLAS, OWASP, NIST, and HITRUST. Version 3.0 introduces coverage for agentic AI threats including memory poisoning, goal manipulation, and insecure MCP connections.
The framework release also includes DAGF (Databricks AI Governance Framework) for enterprise accountability and audit trails, and BlackIce for open-source AI red teaming. Lakewatch provides an open Security Lakehouse architecture for agentic threat detection and response at scale. NVIDIA provides accelerated computing and open AI infrastructure; Databricks brings governed data, model and agent capabilities, creating an end-to-end secured agent stack.
For enterprise teams deploying AI agents, the alliance's open-stack approach to AI security—from harnesses and guardrails through governance and cyber defense—establishes a community-driven alternative to proprietary security frameworks. The emphasis on auditability, policy enforcement, and vendor-agnostic controls across the full agentic stack addresses a critical gap as enterprises scale agent deployment.