Interview

NVIDIA's Justin Boitano makes the case for open-source AI as asymmetric defense and previews Nemotron roadmap

Jul 27, 2026 with Justin Boitano

Key Points

  • Nvidia VP Justin Boitano argues open-source AI models give enterprise defenders an asymmetric advantage because they can monitor access, patch guardrails, and conduct security testing while attackers lack visibility and control.
  • The Open Secure AI Alliance, signed by 35-plus organizations representing $1.8 trillion in market cap, contends that restricting open models would harm cybersecurity defenders in financial services, energy, and telecoms who need them to scan and remediate infrastructure.
  • Nvidia plans a portfolio ensemble strategy across language, world foundation, autonomous driving, and robotics models, with enterprises using frontier closed models for complex planning and open models for routine tasks like document summarization.

Open-source AI as collective defense

Justin Boitano, Nvidia's VP of enterprise AI, makes the case that open-source AI models give cybersecurity defenders a structural advantage — and that restricting them would do the opposite of what regulators might intend.

The immediate catalyst is an incident at Hugging Face that accelerated collective awareness across the industry. The response is the Open Secure AI Alliance, a letter now signed by companies representing roughly $1.8 trillion in combined market cap across 35-plus organizations. The core argument is that defenders, specifically enterprises in financial services, energy, and telecoms, need access to frontier open models to scan, remediate, and patch their own infrastructure.

There's been this collective awareness across industry leaders that doing a lot of the work in cybersecurity out in the open — open models, open harnesses, open safety evaluations — is gonna give the broadest collective defense. If a model refuses to do the work you need to do, you have other options. The inbound requests around this have kind of blown us away.

The asymmetry question

The obvious pushback is that open models are available to attackers too, making this a level playing field rather than a defensive advantage. Boitano's answer is that defenders running their own services know who is accessing them, can impose terms of service, and can patch guardrails rapidly when misuse emerges. Attackers don't have that visibility or control surface. The argument holds reasonably well for large enterprises; it gets thinner for small businesses that lack the resources to operate their own model infrastructure.

On the backdoor problem — where a model tests cleanly on benchmarks but carries hidden vulnerabilities — Boitano draws a direct parallel to Red Hat's role in open-source software. He expects a commercial layer to emerge where firms certify, patch, and support open model weights for enterprise deployment, much as Red Hat did for Linux. He also notes that proprietary hosted models carry the same backdoor risk, but their terms of service often bar security researchers from testing for it. Open weights, by contrast, can be pen-tested freely.

Nemotron and the ensemble model

Boitano declines to preview the Nemotron roadmap specifically, but describes Nvidia's broader model strategy as a portfolio spanning language (Nemotron), world foundation models (Kosmos), autonomous driving (Alpamayo), and vision-language-action models for robotics (Groot). The practical framing for enterprises is an ensemble approach: use frontier closed models for complex agentic planning where they genuinely differentiate, and open models for routine tasks like document summarization. Fine-tuned domain-specific models, such as the Thinking Machines and Bridgewater example he references, can deliver strong performance at low cost for high-volume, narrow use cases.

Evaluation gaps

Boitano flags one underappreciated problem: cybersecurity benchmarks have been over-indexed on vulnerability discovery, which is not the same as navigating a full attack chain. The alliance plans to develop better cyber ranges that put agents through end-to-end attack scenarios rather than isolated discovery tasks. That work, alongside shared evaluations and safety testing frameworks, is where he sees the community's near-term focus landing.

The alliance's inbound interest has, by his account, exceeded expectations. The question of whether that momentum produces durable evaluation standards or stays at the level of a well-signed letter remains open.

Every deal, every interview. 5 minutes.

TBPN Digest delivers summaries of the latest fundraises, interviews and tech news from TBPN, every weekday.