IBM Developer

Blog post

IBM's Open Source AI Security Baseline Framework

Build trusted AI with governance and security standards

By Arnaud Le Hors, Derek Leist

IBM is committed to developing best-in-class open source AI models. These models must be trusted, well-governed, safe, and secure. IBM became the first major open source model developer to achieve ISO 42001 certification for the Granite AI Management System (AIMS). This certification covers Granite language models and demonstrates IBM's commitment to responsible AI development. The ISO 42001 audit was completed with zero major non-conformities, a significant achievement.

Why open source AI needs security standards

To extend that commitment to the open source community, IBM researchers came together. The team includes technical experts in AI alignment, AI governance, cybersecurity, and AI safety. They identified best practices, tooling, and principles for AI development and deployment. Today, IBM releases this work on GitHub as the Open Source AI Project Governance and Security (OSAIPGS) Baseline, or the AI Baseline.

IBM releases the AI Baseline under a permissive Apache 2.0 license. This encourages adoption for responsible open source AI project development and deployment. It also kick-starts conversations in the open source community. The AI Baseline is intentionally flexible. It applies broadly across projects of varying maturity level, complexity, scope, and size.

The success of open source AI depends on safe, secure development and deployment. This includes AI models, tooling, and other assets, collectively called "open source AI projects." Security and governance have become major topics in the open source community over the past year. This intensified after the announcement of Project Glasswing.

Building on OpenSSF foundations

Since its launch in 2020, the Open Source Security Foundation (OpenSSF) has become a leading voice. It drives thought leadership, tooling, and community norms for responsible open source project development. These assets have an important impact on open source AI development. For example, the IBM Granite team uses tooling from the Model Transparency Project to cryptographically sign Granite models. This builds on work from OpenSSF.

OpenSSF developed the Open Source Project Security Baseline as one of its initiatives. This baseline defines different sets of requirements that open source projects should meet. Requirements depend on project maturity level. The Security Baseline provides a solid foundation. It purposefully remains flexible enough to apply to all open source projects.

The AI Baseline framework

The Open Source AI Project Governance and Security Baseline, proposed by IBM Research, expands on that work. It acts as a minimum set of requirements for open source AI projects. Requirements are relative to maturity and risk level. Including risk in the considerations is important. There is significant heterogeneity within open source AI project tooling, models, and assets. The AI Baseline extends the principles of the OpenSSF Open Source Project Security Baseline. It addresses the unique challenges of developing, deploying, and managing AI projects in open source.

The open source AI community needs a common set of norms. These norms underpin how we build and deploy open source AI tooling, models, and systems. To inform the AI Baseline, the team focused on IBM Granite's core best practices. These practices operationalize IBM's internal AI management system. They ensure Granite models are secure, robust, transparent, and aligned with governance objectives. IBM intends this as a starting point for the open source community. It's based on IBM's research, operations, and best practices in building and deploying open source models tailored for enterprise use.

How to get involved

IBM hopes other organizations will contribute to this effort. We want to drive discussions on how to improve the AI Baseline and its adoption across the open source AI community. IBM invites comments and is considering providing the AI Baseline as a technical contribution to a security-focused organization, such as OpenSSF, for further refinement. This depends on sufficient community interest.

Explore the guiding principles, the checklist, and the FAQ. Let us know what you think in the AI Security Baseline GitHub repository today!