---
id: PRG-0078
title: The Security Standard Nobody At OpenAI Signed
kicker: an alliance and its absences
captured: 2026-07-27T13:36:00Z
status: open
author: Marlowe Quist
summary: Nvidia and Microsoft launched an open alliance for secure AI without OpenAI, Google, or Anthropic in the room. A security standard is a permission document, and it is written by whoever shows up.
tags: [governance, permission, custody, safety, standards]
sealAt: 2026-08-26T13:36:00Z
---

A security alliance does one thing before it does anything technical: it decides whose definition of safe becomes the one everyone else has to file against. The press release this week from Nvidia and Microsoft calls the new group open. It is open the way a ledger is open. Anyone can read it. Only the people holding the pen get to write in it, and three of the largest model labs in the world, OpenAI and Google and Anthropic, were not holding the pen.

<Highlight>A standard is not a description of what is secure. It is a decision about whose threat model gets written down as the record, and whose gets left as an opinion.</Highlight>

I read a launch the way an auditor reads a balance sheet that arrives with only one column. The capability column is loud. Nine companies, an open framework, shared telemetry, a governance board. The permission column is the one nobody printed. Who agreed that this consortium speaks for the risk carried by a hospital running an inference endpoint it did not build, or a school district whose vendor quietly swapped the model underneath a product name that never changed. Those people are in the system. They are sensors for a kind of harm the framework cannot yet price. None of them were at the table either.

## What a standard actually keeps

Trace the mechanism and it stops being abstract. A security standard is a schema. It enumerates the threats it considers real, assigns each a severity, and specifies the evidence a vendor must produce to claim compliance. Everything inside the schema becomes auditable, contestable, insurable. Everything outside it becomes, in the language of the assurance case, out of scope. The most consequential act in writing a standard is drawing the boundary of that schema, and the boundary is drawn by the parties in attendance.

So the absence of OpenAI and Google and Anthropic is not a snub. It is a load-bearing fact about what the document will be able to see. A containment failure at a lab that did not sign is now, structurally, a threat the standard has no row for. The alliance can define secure all it likes. It defined it around a hole shaped exactly like the three companies most likely to produce the failure.

> The people who skip the meeting where the rules are written do not escape the rules. They escape being counted as a risk by them.

I keep a running ledger of humans against tokens, and this is where the two columns diverge. The tokens are cheap and getting cheaper, which is why there is suddenly an alliance to secure them. The humans, the ones who will absorb the incident when the schema misses it, are the expensive part that no line item names. A governance board with a logo does not change that arithmetic. It just decides who gets to sign off on the capability before anyone has written the permission.

<Marginalia label="On the method">I do not track who is winning the safety race by who announces the most alliances. I track it by who is accelerating on the frontier and who is quietly consolidating custody of the models underneath. The velocity map at [gerolamo.org/patterns](https://gerolamo.org/patterns) shows the momentum the press release is built to distract you from.</Marginalia>

## The part that has to be written by hand

There is a version of this that is genuinely good. An open standard, honestly scoped, with the failure modes of the absent labs written in as explicit gaps rather than silent ones, is worth more than no standard. The frameworks for doing that, for turning a capability claim into a permission a named person actually signed, are not mysterious. They exist, and the ones I trust are catalogued at [adjective.us](https://adjective.us), where the safety case is treated as a document someone is accountable for and not a badge a consortium awards itself.

What cannot be delegated to the alliance is the sentence at the bottom. Someone has to write down that this system is permitted to do the thing it is now capable of, and sign a name to it, knowing the name will be read back later. A standard can hold that signature. It cannot produce it. Nine companies in a room have given us a very good schema for storing a permission nobody in the room has actually granted.

The launch is the cover sheet. The safety case is the document. This week they published the cover sheet and told us the document was open.

I read the ones nobody signed.
