The Information Machine
Concluded·following since 4 Aug 2026·Day 3·9 sources·updated 9 Aug 2026

Open Secure AI Alliance's SAFE incident-sharing RFC

The gist

Open Secure AI Alliance publishes SAFE incident-sharing RFC and open-source tools at Black Hat, backed by 120-plus organizations

A 120-plus organization coalition proposing a structured, confidential incident-sharing framework for agentic AI security represents a broad industry coordination effort. The RFC stage means the framework has no binding authority yet, and its practical effect depends on whether organizations adopt and contribute to it.

The full picture

The Open Secure AI Alliance, a coalition of more than 120 organizations including Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat, Amazon, and Microsoft, published a Request for Comments for the Shared AI Findings Exchange (SAFE) Working Group on August 4, 2026, at the Black Hat conference in Las Vegas. The Linux Foundation issued the RFC, which proposes a vendor-neutral framework for confidentially reporting and analyzing agentic AI security incidents and near misses, then converting findings into reusable defenses. SAFE is modeled after NASA's Aviation Safety Reporting System for blameless reporting of AI operational failures. It is not a finished standard, reporting authority, or completed specification; it remains an open proposal seeking community contributions on GitHub.

The framework defines a notification ladder: affected organizations must be notified immediately, customers with demonstrable exposure within 72 hours, a confidential initial report within four business days, and a preliminary public report within 30 days. Members are required to report near misses, not only confirmed incidents. SAFE covers model, tools, permissions, runtime environment, safeguards, monitoring, and human oversight when reviewing incidents, and intends to publish reusable tests, detection rules, and incident response guidance based on collected data.

Alongside the RFC, alliance members released open-source tools. NVIDIA contributed the NOOA research harness, OpenShell runtime sandbox, verified agent skills with cryptographic signing, NeMo Guardrails, and the Garak LLM vulnerability scanner. CrowdStrike fine-tuned NVIDIA Nemotron Nano for cyber defense, reporting 96% accuracy in generating investigation queries and outperforming larger models on Security Operations Center detection triage. Uber open-sourced ADR (Agentic AI Detection and Response), a production system processing over 200,000 agent sessions per day across 30,000 endpoints that reconstructs the full causal chain of AI agent activity. New members Amazon and Visa contributed Strands Agents, Cedar authorization language, and a Vulnerability Agentic Harness.

How it developed
9 August 2026

The Linux Foundation published on August 4 at Black Hat an RFC for confidential AI security incident reporting, backed by more than 120 organizations including Cisco, CrowdStrike, NVIDIA, and Microsoft.

The framework requires customer notice within 72 hours of demonstrable exposure and a preliminary public report within 30 days, with near misses required to be reported alongside confirmed incidents. Members released open-source tools alongside it, including Uber's ADR system processing over 200,000 agent sessions per day and CrowdStrike's fine-tuned model reporting 96% accuracy on SOC detection triage.

First citedsecurityweek.com
8 August 2026

The Open Secure AI Alliance, a coalition of more than 120 organizations including Cisco, NVIDIA, and Microsoft, published an RFC for the Shared AI Findings Exchange (SAFE) on August 4 at the Black Hat conference in Las Vegas.

SAFE proposes a vendor-neutral framework for sharing agentic AI security incidents and near misses confidentially, modeled after NASA's Aviation Safety Reporting System, requiring immediate notification of affected parties and a preliminary public report within 30 days. The RFC is an open proposal seeking community input on GitHub, not a finished standard. Members also released open-source tools alongside it, including Uber's ADR system, which processes over 200,000 agent sessions per day across 30,000 endpoints.

4 August 2026

Open Secure AI Alliance publishes the SAFE RFC at Black Hat conference in Las Vegas, alongside open-source security tool releases from member organizations including NVIDIA, CrowdStrike, Uber, Amazon, and Visa

Sources
4 more sources
The daily email

Want this in your inbox?

I send a short email each morning with the stories that moved. If you would rather just read here, that works too.

Subscribe free