Matt Duren explains the background to the establishment of the ‘Open Secure AI Alliance’ and KnowBe4’s commitment in light of the challenges posed by a digital workforce comprising both humans and AI agents.
Matt Duren, ’SVP of AI & Data’ at KnowBe4, discusses the new ‘Open Secure AI Alliance’ in his latest statement and explains its aims: “NVIDIA recently founded the ‘Open Secure AI Alliance’ in collaboration with Microsoft, Cisco, CrowdStrike, Palo Alto Networks and many other companies. KnowBe4 also supports this alliance.” The aim of this alliance is to develop and provide open-source tools that can be used to secure Artificial Intelligence (AI) in the age of autonomous AI agents.
Open Secure AI Alliance: Security as a multi-faceted challenge
“The alliance is asking the right question, and its answer is worth repeating,” emphasises Duren. This is because security depends “on the entire agent stack, on identities, authorisations, harnesses, guardrails, protocols and evaluation”.
Whether an AI system is an ‘open-weight model’, whose parameters can be freely downloaded, or a closed model, is just one of many factors to consider.
“We see it exactly the same way. That is precisely why, in recent years, we have developed the part of this stack that most closely resembles the actual behaviour of agents once they are deployed in a real-world business.”
Modern workforces comprise people and AI agents
Duren describes this new challenge: “For us, the modern workforce consists of people and AI agents, and either side could be behind the next security incident. Model and harness security answer the question of whether a system can, in principle, be trusted.”
However, a second question is just as important: “What exactly is a particular agent doing right now, in this specific environment, with these permissions?”
To answer this question, KnowBe4 has developed the ‘Agent Risk Manager’. This production-ready governance layer for autonomous AI agents is designed to provide security teams with a real-time overview of what an agent is accessing, what data it is moving, and whether a ‘prompt injection’ has caused it to deviate from its intended path. “It works regardless of whether the underlying model is open or closed.”
In principle, the same security criteria should apply to AI agents as to human staff
The ‘Agent Risk Manager’ was developed because, in practice, they had repeatedly encountered the same pattern, “which the ‘Open Secure AI Alliance’ also refers to”. Duren explains: “When the OpenAI agent broke out of its environment and attacked Hugging Face, the cause did not lie in the model itself. The real problem was its behaviour, which nobody had been monitoring until the damage had already been done.”
They are therefore very familiar with this pattern. For over 15 years, they have placed the individual within the organisation at the heart of their security approach – and the lessons learnt from this can be directly applied: “You don’t just check who someone is before they take up a post, but you also pay attention to what they do once they are in the role.” AI agents are now also part of the workforce. Duren emphasises: “And the same standards should apply to them!”
An open, shared infrastructure for defending against AI-enabled threats is precisely the investment that is needed now. “And control over the behaviour of agents is just as much a part of this discussion as the security of the models themselves.” Their mission, therefore, is to safeguard the modern, digital workforce – that is, both people and AI agents alike. “It is therefore to be welcomed that the industry is joining forces to make AI safer using open, shared tools”, so Durens’ concluding comment.
Key findings from the DS editorial team
- The use of Artificial Intelligence – particularly in the form of autonomous AI agents – poses such a significant challenge to the industry and to users within organisations that any initiative to cooperate on security issues is to be welcomed.
- Open virtual tools based on common standards, designed to make the use of AI safer, form the basis for the sensible and successful exploitation of the opportunities it offers.
- From now on, humans and AI, each with their own specific functions, will represent the workforce in companies when it comes to understanding processes.
- Early detection is more crucial than ever – potentially harmful behaviour on the part of sections of the workforce must be identified in good time, i.e. ideally before a safety-critical incident occurs, so that corrective action can still be taken.
- However, in the context of contingency and recovery planning, as well as in ensuring that operations are geared towards resilience and stability, the possibility of a harmful incident occurring should always be factored in.
Conclusion
AI requires up-to-date security concepts, common standards and close collaboration between humans and machines. Early detection, prevention and a high level of resilience to potential security incidents are crucial in this regard.
Further information
DATENSICHERHEIT.DE, 08|16|2026
EU AI Act: Handlungsdruck auf IT- und Datenverantwortliche im KI-Umfeld bleibt hoch
DATENSICHERHEIT.DE, 08|13|2026
KI-Nutzungsdruck als Risiko: 5 Schritte für einen verantwortungsvollen Einsatz
DATENSICHERHEIT.DE, 07|18|2026
Fortune 100: KI-gestützte Phishing-Angriffe auf 86 Prozent der großen Welt-Unternehmen
DATENSICHERHEIT.DE, 01|28|2026
KI-Agenten und IT-Sicherheit: Zwei Seiten einer Medaille
DATENSICHERHEIT.DE, 11|08|2025
Einsatz von KI-Agenten: Lückenlose Governance für Unternehmen mittlerweile unerlässlich
DATENSICHERHEIT.DE, 06|09|2025
Aufbau der KI-Kompetenz in der Belegschaft: Von der Pflicht zur Kür