The Open Secure AI Alliance, which now comprises more than 120 organizations, is presenting a new framework for sharing incidents involving agentic AI. SAFE aims to transform security issues with AI agents into protection for the entire ecosystem.
The Linux Foundation today released a Request for Comments for the Shared AI Findings Exchange (SAFE). It consists of a set of proposed guidelines that translate incidents involving AI agents into shared defense measures. Nvidia, Cisco, CrowdStrike, Hugging Face, and Red Hat are among the members collaborating on the initial proposal.
SAFE revolves around several concrete agreements. Members will collect and analyze AI incidents and “near misses” confidentially, notify affected parties, identify recurring points of failure, and publish substantiated recommendations that reduce systemic risks. The approach draws on precedents from the aviation and financial sectors, where incident sharing has long been common practice.
In late July, Nvidia founded the Open Secure AI Alliance following a high-profile incident at Hugging Face. It started with 37 major tech companies. Within a few weeks, the group grew to more than 120 members.
Tip: OpenAI test leads to incident at Hugging Face
A reporting ladder with deadlines
SAFE defines a notification ladder with fixed deadlines. Affected organizations are notified as soon as possible, and customers with demonstrable exposure within 72 hours. A confidential initial report follows within four business days, and a preliminary public report, along with an analysis of the failure points, within 30 days. Members must also report near misses, not just confirmed damage.
For now, the framework remains a concept. There is no implementation timeline yet, nor is there a mechanism for submitting an initial report; what is available is a GitHub repository for public feedback and a charter for the working group. The Linux Foundation manages the review process as a neutral party.
Nvidia is also providing a suite of open-source tools. These include the NOOA research harness, the OpenShell runtime, which restricts what an agent can see and do, and Garak, a vulnerability scanner for LLMs. NeMo Guardrails, NeMo Anonymizer, and NeMo Safe Synthesizer are also part of the initiative. Other members are contributing across the board: Okta and Palo Alto Networks in the area of identity, Amazon with Strands Agents and Cedar, and Microsoft with PyRIT and RAMPART.