
Summary
- The Linux Foundation has released a request for comments (RFC) on the SAFE (Shared AI Findings Exchange) guidelines
- NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat participated in drafting the proposal
- The framework proposes privately collecting and analyzing AI security incidents and near-misses, then sharing findings across the ecosystem
The Linux Foundation has released a request for comments (RFC) on a new draft guideline called SAFE (Shared AI Findings Exchange), aimed at strengthening security for agentic AI. The announcement was timed to coincide with the opening of the Black Hat conference, with the draft prepared by a working group under the Open Secure AI Alliance.
What was announced
The SAFE guidelines propose a process for privately collecting and analyzing AI-related incidents and near-misses, notifying affected parties, identifying recurring control failures, and publishing evidence-based operational recommendations to reduce systemic risk. NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat were confirmed to have participated in drafting the proposal.
What's changing
Beyond SAFE, the Open Secure AI Alliance has been expanding its portfolio of open-source tools across the security stack. NVIDIA is reported to have contributed NOOA, a research harness for testing and auditing agent behavior; OpenShell, a runtime that limits the scope of agent access; NeMo Guardrails, which helps enforce safety policies; and Garak, a vulnerability scanner. "Defenders now need to move at agent speed," the company said.





Comments