Skip to main content
  1. Blog
  2. Article

Canonical
on 28 August 2026

Canonical joins the Open Secure AI Alliance


Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and AI research. The alliance aims to develop and share open technologies, techniques, and tools to safeguard software and agents in the age of AI.

The bedrock for AI 

Alongside NVIDIA and a coalition of industry leaders, we are embarking on a critical mission: to ensure that the tools needed to secure the age of AI are open, transparent, and accessible to defenders everywhere.

The Open Secure AI Alliance recognizes a fundamental truth: an AI agent is more than just its model weights. It is a full stack of software, harnesses, and guardrails. And at the base of that stack sits the infrastructure.

Ubuntu is the platform of choice for AI development and deployment, from a developer’s workstation to the edge and the data center. The security of that platform shapes the security of everything built on top of it, making Canonical’s role in securing the AI ecosystem a natural fit.

Open source makes verification possible

When the source is open, you can inspect it, test it, and confirm the software does what it says it does. Then you can make the software better, and more resilient yourself, and publish the fixes for everyone running it.

The same holds across the agent stack. Identity, permissions, guardrails, logs, and evaluation are easier to check when the code and the tooling are open source. That is what open source tools give defenders. More to examine, and more to improve.

Resilient AI open source software stack

Resilience starts with the platform underneath. Ubuntu LTS supports UEFI Secure Boot to verify the boot chain, and AppArmor is enabled by default to confine applications. TPM-backed full-disk encryption can be enabled during installation, protecting disk-encryption keys and releasing them only when the machine boots into an expected state. For workloads that need data protected while it is being processed, Ubuntu supports confidential computing as both guest and host, enabling confidential AI use cases with silicon-level encryption.

An AI system depends on far more than the operating system (OS). Libraries, runtimes, databases, message queues, and monitoring tools all sit on top of the OS, and much of that software comes from the wider Ubuntu archive, rather than the core set of packages. Ubuntu Pro extends Canonical’s maintenance across that whole archive, including the Universe repository, with up to 15 years of security maintenance, compliance, and support. 

This coverage is critical for environments that demand high stability. Financial services, healthcare, telecommunications, energy, manufacturing, automotive, and public sector teams keep the same release in production for a long time, and the software running on it has to be maintained for just as long. AI infrastructure is starting to work the same way, and that kind of long-term maintenance is what Canonical has been doing for years.

Trust in AI will be earned the way trust in open source was earned. In public, over time, with the work available for anyone to check.

We are glad to be part of it.

Learn more about the Open Secure AI Alliance.

Learn more about security maintenance with Ubuntu Pro.

Related posts


Canonical
1 June 2026

Securing AI agent workflows on Ubuntu with the new NVIDIA OpenShell snap

AI Ubuntu tech blog

By packaging OpenShell as a snap, Canonical is enabling enterprises to confidently run next-generation agentic workflows across local devices, hybrid environments, and private clouds. ...


estelacarmona
28 August 2026

AI harnesses for telco autonomous networks

5G Ubuntu tech blog

As the telco industry transitions toward Autonomous Networks Level 4, a fundamental architectural challenge has emerged: how do you build a secure, reliable and interoperable AI harness that bridges probabilistic AI reasoning with deterministic, carrier-grade network execution? ...


seth-arnold
11 July 2026

Januscape vulnerability CVE-2026-53359 mitigations available

Security and Compliance Ubuntu tech blog

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID CVE-2026-53359 and is referred to as Januscape. This vulnerability affects all Ubuntu releases. Neither NVD nor Kernel.org have published their own CVSS scores for this issu ...