AI Leaders Propose SAFE Guidelines for Cybersecurity Transparency

| Source: NVIDIA Blog

Tags: Open Secure AI Alliance, NVIDIA, agentic AI security, SAFE guidelines, Linux Foundation, CrowdStrike, Black Hat

NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat launched a Request for Comments on SAFE (Shared AI Findings Exchange) at Black Hat, proposing that 120+ Open Secure AI Alliance members confidentially share agentic AI security incidents and publish evidence-based operating recommendations.

Details

The Open Secure AI Alliance — now over 120 organizations strong — submitted a Request for Comments to the Linux Foundation at this year's Black Hat conference on SAFE: Shared AI Findings Exchange. The proposed guidelines would create a standardized process for confidentially collecting and analyzing AI security incidents and near misses, notifying impacted parties, identifying recurring control failures, and publishing evidence-based operating recommendations across the ecosystem. NVIDIA's contributions span the full security stack: the NOOA (NVIDIA Labs Object-Oriented Agent) research harness for agent auditing and tracing, the OpenShell runtime for restricting agent access and execution permissions, and open model families (Nemotron, Cosmos, Isaac GR00T, BioNeMo, Alpamayo) with cryptographically signed, vulnerability-scanned agent skills. The initiative frames agentic AI security as a system problem rather than a model problem — requiring identity controls, harnesses, guardrails, logs, and evaluation working together. The framing is analogous to ISAC (Information Sharing and Analysis Center) models that have operated in financial services and critical infrastructure for years. SAFE is still in public comment period; the guidelines are not yet finalized. Organizations with relevant experience are encouraged to submit feedback before the RFC closes.