Box joins the Open Secure AI Alliance

|
Share

Open Secure AI Alliance

Key takeaways:

  • Box joins the Open Secure AI Alliance alongside NVIDIA and a broad coalition of industry leaders, as part of an initiative built on the Linux Foundation and OpenSSF community.
  • Enterprise AI security requires protecting the full agent stack, and Box is contributing to best practices in four critical areas: agent guardrails, prompt injection defenses, secure tool use, and auditable AI workflows.
  • Open infrastructure is the foundation of trustworthy enterprise AI, and just as open-source software strengthened the broader technology ecosystem, open models, harnesses, and security tooling can democratize defensive capabilities. 

Solving for expanding attack surfaces

The Open Secure AI Alliance, building on the leadership of the Linux Foundation and the OpenSSF community, is committed to developing and sharing open technologies, techniques, and tools to safeguard software and AI agents in the age of AI. Its founding membership spans cloud computing, cybersecurity, enterprise software, open-source foundations, and AI research, representing some of the most consequential technology organizations in the world.

For IT decision-makers, the Alliance addresses a challenge that’s already on your radar: as AI agents proliferate across enterprise environments, the attack surface expands. Prompt injection, unauthorized tool use, opaque decision-making, and unauditable workflows remain active concerns for any organization deploying AI at scale.

The Alliance's work is grounded in a foundational insight: an AI agent is a complex system built from models, harnesses, and guardrails. Real AI safety and security depend on the full agent stack: identity, permissions, harnesses, guardrails, logs, and evaluation. Open tools and open harnesses make those controls easier for defenders to inspect, test, and improve.

Securing the content that fuels AI

Box has spent two decades helping enterprises manage, secure, and govern their most sensitive content. We understand that the value of AI is inseparable from the integrity of the content it touches. When AI agents can read contracts, analyze financial records, process customer data, and trigger downstream workflows, the stakes for security and governance are extraordinarily high.

Box is contributing to the development of best practices and building tooling in several critical areas:

  • Agent guardrails: Defining and enforcing boundaries on what AI agents can access, modify, and act upon within enterprise content environments
  • Prompt injection defenses: Building open, testable protections against adversarial inputs designed to manipulate AI behavior
  • Secure tool use: Establishing standards for how AI agents authenticate, authorize, and interact with enterprise systems and APIs
  • Auditable AI workflows: Ensuring that every AI-driven action on enterprise content is logged, traceable, and reviewable for compliance and governance purposes

These are the practical requirements that IT and security leaders tell us they need before they can confidently expand AI deployment across their organizations.

BoxWorks

Empowering businesses to deploy with confidence

Box's mission is to help organizations unlock the value of their enterprise content with AI in a way that preserves the security, governance, compliance, and transparency that regulated industries and security-conscious enterprises depend on.

That mission aligns with what the Open Secure AI Alliance is building. By contributing to an open ecosystem of secure AI tools and practices, we are helping ensure that the organizations we serve — and the broader enterprise community — can build and deploy AI they can genuinely trust.

One of the Alliance's core arguments, and one we at Box endorse, is that security through obscurity is not a strategy. Just as open-source software created a shared foundation that strengthened the entire technology ecosystem, open models, harnesses, and security tooling can democratize defensive capabilities and give more organizations the ability to test, verify, and strengthen the AI systems on which they depend.

Widespread adoption of AI agents in the enterprise will demand both resilience and shared security. But that future will not be secured by assuming that secrecy alone means safety. It will be secured by building systems that are strong enough to withstand scrutiny, flexible enough to be improved, and open enough to mobilize the full community of defenders.

Box is committed to that work and we invite our customers, partners, and the broader IT community to engage with the Open Secure AI Alliance as it develops the open standards and tools that will define secure enterprise AI for years to come.

To learn more about the Open Secure AI Alliance and Box's role in advancing secure, trustworthy enterprise AI, visit box.com.