Open Models Need Open Context
Back to top
August 3, 2026
Open Models Need Open Context
NVIDIA and 36 partners launched the Open Secure AI Alliance this week, and the argument is right: defenders need frontier AI they can inspect, modify, and run on their own infrastructure.
Blanket restrictions on open weights would concentrate defensive capability in a handful of opaque systems. But look closely at the incident that justified the whole thing.
When Hugging Face was breached, closed AI tools obstructed the forensics: they couldn’t tell an investigator from an intruder. So, the team ran an open-weight model on their own infrastructure and analyzed more than 17,000 actions to contain it.
An open model with no evidence is a very fast opinion. What made that investigation possible was a complete, structured, query-able record of what actually happened, available in real time, at the fidelity required to distinguish legitimate behavior from hostile behavior.
That is the layer nobody is fighting over yet, and it is the one that decides whether any of this works.
Three layers, not one
We have spent the last year arguing that machine-speed defense has three layers, not one:
OSAA just made the industry case for open harnesses and open models with more force than we ever could. Good. That argument is now settled, and it should be.
What open context actually means
A word on this, since it would be easy to use the phrase loosely.
It means the semantics are discoverable and the evidence is addressable by someone who doesn’t work here. Our REST API, Trigger API, record object definitions, metric catalog, and code examples are on our public documentation site, not behind a partner portal, not under NDA, not a slide in an integration deck. Start here: docs.extrahop.com/current/api. Anyone evaluating whether an agent can actually reason over network evidence can read the object model first and decide for themselves.
That is a deliberate choice, and it costs us something. A documented object model is a commitment you can be held to and a surface competitors can study. We think that trade is correct. An evidence layer nobody can inspect is not a foundation for autonomous defense, it is a dependency, and dependencies are exactly what OSAA is warning about.
This is a commercial real-time data lake, built at ingest speed. AI-driven attacks compress the time from initial access to consequence into minutes. A defense agent waiting for evidence to land in a batch pipeline is reasoning about a network that no longer exists. Machine-speed attacks can only be answered from a substrate that is already current when the agent asks.
An invitation
To everyone else holding security telemetry: publish your object models. Not a connector list, not a partner integration matrix, the actual schemas, the actual semantics, the actual query surface. If open weights are a defensive asset, open evidence definitions are too, and none of us should be asking defenders to trust a data layer they aren’t allowed to read.
Why this is harder than it looks
An agent reasoning over stale, sampled, or pre-summarized telemetry is not slow, it is confidently wrong, at scale, with permission to act. Move an agent from direct-on-detection attachment to a queue-mediated path and reasoning quality never changes. The outcome does, because the evidence arrived late and lossy. Transport delay is not a footnote in agentic defense. It is frequently the whole result.
Attackers already have frontier AI. The open ecosystem defenders need is not just open weights; it is open context. Evidence layers that any harness, any model, and any vendor’s agent can query, with semantics you can discover and detail you can verify.
Open models. Open harnesses. Open context.
Two of three now have a coalition behind it.
We started the Agentic SOC Alliance last week with fifteen partners to work on the third: context, harness, and model as one architecture, with the claims built as tests anyone can run rather than slides anyone can write.
Different starting point than OSAA, same conclusion: defenders win in the open or they don’t win.
If you’re building in this space, come argue with us.

Shape the Future of Autonomous Security
If your organization is helping shape that future, apply to join the Agentic SOC Alliance today →
Discover more

CEO, ExtraHop
Greg Clark serves as CEO of ExtraHop and is co-founder and managing Partner of Crosspoint Capital Partners, a private equity investment firm focused on the cybersecurity, privacy and infrastructure software markets. Crosspoint has helped many of its platform portfolio companies scale across growth horizons through operational improvement and by combining with management, including taking on the role of CEO during critical inflection periods on the journey to profitable growth. Clark served as Executive Chair of DigiCert as well as CEO of Forescout Technologies to help those companies through critical inflection points.
Clark brings to ExtraHop decades of cybersecurity sector expertise, technology management expertise and a proven ability to scale businesses. He has led multiple companies through phases of innovation and growth, including Blue Coat Systems where he served as CEO from 2011 to 2016, prior to the company being acquired by Symantec Corporation. Following that transaction, Clark served as CEO and member of the Board of Directors of Symantec from 2016 through 2019. Earlier in his career, Clark served as CEO of Mincom (acquired by ABB Group), E2open and Dascom (acquired by IBM).
Share
Key Takeaways
- Three Layers of Defense: Effective autonomous security architecture depends on integrating three specific layers: transparent context, a controlled harness, and interchangeable reasoning models for comprehensive, verifiable protection.
- Prioritize Open Context: While open models gain attention, open context—real-time, query-able security data—remains the critical, missing foundation necessary to distinguish legitimate network behavior from hostile actions.
- Avoid Confidently Wrong: AI agents using stale, sampled, or pre-summarized data are "confidently wrong." Real-time telemetry is essential, as machine-speed attacks leave no room for delayed, lossy evidence pipelines.
- Demand Verifiable Evidence: Vendors must publish schemas, semantics, and object models. Defenders cannot trust an evidence layer they cannot inspect, as closed systems create dangerous, opaque dependencies for security teams.








