In brief: The Open Secure AI Alliance has presented a draft of the SAFE guidelines for confidential, industry-wide sharing of AI security incidents, complementing it with open tools spanning the entire agentic AI security stack.
At the start of the Black Hat conference in Las Vegas, the Open Secure AI Alliance, with over 120 member organizations, published a Request for Comments on the SAFE guidelines (Shared AI Findings Exchange). The goal is an industry-wide mechanism to confidentially collect and analyze incidents involving agentic AI and to make them usable as a shared protective measure for the entire ecosystem.
The Linux Foundation has published the draft of the SAFE guidelines (Shared AI Findings Exchange), developed by a working group of the Open Secure AI Alliance. NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat, among others, are involved in drafting it. The guidelines call for confidentially capturing and analyzing AI security incidents and near-misses, notifying affected parties, identifying recurring control failures, and deriving evidence-based operational recommendations from them intended to reduce systemic risk.
For CISOs, it is relevant that, according to the Alliance, AI agents should not be viewed as a single model but as a system composed of identity controls, execution environments (harnesses), guardrails, logs and evaluation mechanisms. Classic vulnerability scanning alone is therefore not sufficient to secure agentic AI. An industry-wide exchange of incident data is intended to help defenders keep pace with attackers, who are increasingly using AI agents for attacks.
Alongside the SAFE guidelines, members of the Alliance have provided further open tools spanning the entire AI security stack. NVIDIA is contributing, among other things, the NOOA research harness (NVIDIA Labs Object-Oriented Agent) for analyzing agent behavior, the OpenShell runtime for enforcing security and privacy controls at the agent level, and open model families such as Nemotron, Cosmos, Isaac GR00T, BioNeMo and Alpamayo with open weights and training data. This is complemented by signed agent skills that have been checked for risks such as prompt injection and tool poisoning, the tools NeMo Guardrails, NeMo Anonymizer and NeMo Safe Synthesizer for privacy and policy enforcement, and the LLM vulnerability scanner Garak.
According to the announcement, further Alliance members have delivered their own contributions across the areas of identity and permissions, runtime guardrails, security AI models, observability, evaluation, data security, and availability and resilience; details on individual contributions were only partially disclosed at the time of publication. For enterprise security leaders, the SAFE draft offers a starting point to engage early with a possible industry-wide standard for sharing AI security incidents before it is finally adopted.
Source: blogs.nvidia.com · Published August 4, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.