Open Secure AI Alliance Proposes SAFE Guidelines

The Open Secure AI Alliance published a request for comments on its Shared AI Findings Exchange, or SAFE, guidelines as Black Hat opened in Las Vegas on August 4. According to NVIDIA and BankInfoSecurity, the proposal covers confidential collection and analysis of AI security incidents and near misses, notification of affected parties, and evidence-based recommendations intended to reduce recurring control failures.
The Open Secure AI Alliance published a request for comments on the Shared AI Findings Exchange (SAFE) guidelines on August 4 as the Black Hat conference opened in Las Vegas. According to NVIDIA, the proposed guidelines are intended to confidentially collect and analyze AI incidents and near misses, inform affected parties, identify recurring control failures, and publish evidence-based operating recommendations.
The Linux Foundation is accepting industry comments on the proposal, BankInfoSecurity reports. The alliance, which began with 37 companies in July, now has more than 120 organizations, according to NVIDIA. NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat are among members contributing to the initial SAFE proposal.
A reporting framework for agent incidents
BankInfoSecurity reports that SAFE is organized around five proposed principles: openness with accountability, open learning, risk-based response, member sovereignty, and separating learning from enforcement. The framework focuses on information sharing following AI-agent security incidents.
The source material describes an AI agent as more than a model, including identity controls, harnesses, guardrails, logs and evaluation. NVIDIA describes securing such systems as requiring more than vulnerability scanning.
In its blog post, the alliance argued that defenders need to respond rapidly at agent speed to protect infrastructure and intellectual property, and that trusted ecosystems can strengthen collective defense.
Open tools alongside the guidelines
NVIDIA also described the SAFE proposal as part of a broader set of open, inspectable security contributions from alliance members across the AI security stack. The retrieved material does not provide implementation specifications for all of those tools, but the stated scope includes agent behavior testing, tracing, auditing, governance, and runtime restrictions.
For security and ML platform teams, a voluntary incident-sharing framework is most useful when reporting fields can be mapped to existing telemetry and incident-response workflows. Comparable industry efforts often face practical questions about confidentiality, legal review, data retention, and how consistently participants classify an AI-specific incident or near miss. The Linux Foundation's comment process is therefore a material next step for teams seeking clarity on the proposal's governance and operational requirements.
Key Points
- 1SAFE proposes confidential incident and near-miss sharing, aiming to turn individual agent-security failures into ecosystem-wide defensive evidence and guidance.
- 2The RFC addresses agent systems beyond models, including identity controls, harnesses, guardrails, logs, and evaluation, according to NVIDIA.
- 3Shared reporting frameworks can help practitioners compare recurring control failures, although adoption and governance determine whether voluntary guidance gains operational value.
Scoring Rationale
The SAFE proposal addresses a growing operational gap in reporting and learning from AI-agent security incidents. It is relevant to security engineers and ML platform teams, though it remains a proposed voluntary framework rather than an adopted technical standard.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


