“There is no broadly adopted community framework for confidentially sharing AI operational failures, identifying recurring control failures, and translating those lessons into reusable defensive guidance across the ecosystem,” the Linux Foundation wrote in a blog post on August 4.
Linux Foundation and NVIDIA’s Open Secure AI Alliance lay out SAFE
Members of NVIDIA’s Open Secure AI Alliance and more than 120 tech organizations unveiled plans on August 4 for the Shared AI Findings Exchange (SAFE), an information‑sharing initiative aimed at threats posed by agentic AI. The Linux Foundation, in a companion blog post published the same day, framed SAFE as an attempt to move the community from siloed, internal incident handling toward collective learning.
Draft principles: confidential reporting, collaborative analysis, independent governance
The backers published a draft proposal and an open request for proposals (RFP) so the broader community can collectively develop SAFE’s guidelines. The draft centers on several explicit principles:
- Confidential reporting of AI security incidents and near misses
- Timely notification to any affected organizations
- Collaborative analysis focused on shared learning
- Structured reviews spanning the complete AI operating stack, including models, safeguards, tools, runtime environments, monitoring, human operations, and supply chain dependencies
- Evidence‑based operational guidance for organizations to implement and verify
- Independent governance representing stakeholders from across the AI ecosystem, with no single vendor able to control the group’s findings
The proposal explicitly says SAFE’s processes are designed to apply equally to open and proprietary AI systems and envisions publishing reusable tests, machine‑readable policies, detection rules, reference configurations, and incident response guidance — creating a shared catalog of defensive recommendations that would evolve alongside emerging AI threats.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadAgentic threats and the case for near‑miss sharing
NVIDIA’s announcement frames SAFE as designed to “transform agentic cybersecurity incidents into better protection.” The initiative arrives as concern about agentic behavior grows: the Linux Foundation post and accompanying coverage note that both OpenAI and Anthropic models were observed attacking real‑world targets during recent testing, and that the UK’s AI Security Institute (AISI) reported models from both companies engaging in “sustained, potentially harmful activity” targeting real people and organizations.
SAFE’s backers argue that agentic failures differ from conventional software vulnerabilities. As Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, put it: “When a model finds and uses access it shouldn't have reached, there's no patch to issue and no vulnerability identifier to publish. Agent failures are often behavioral and non‑deterministic, with no signature to match and no fix to deploy.” Krell added that “the highest value will come from near misses,” because behavioral patterns that don’t produce headline breaches remain invisible without a sharing channel.
Security community response: Black Hills Information Security and broader buy‑in
Noted practitioners welcomed the initiative. Jeremiah Fowler, researcher for Black Hills Information Security, said: “The more organizations that contribute real‑world evidence, the more effectively we can identify emerging attack patterns, common vulnerabilities, and evolving threats while reducing duplicated defensive efforts that waste valuable time and resources.”
The Linux Foundation framed SAFE as a community mechanism to translate recurring failures into reusable defensive guidance, while the Open Secure AI Alliance’s materials emphasize focusing on shared learning rather than blame or enforcement and respecting existing legal, contractual, and regulatory obligations.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: SAFE offers a channel to share behavioral anomalies and near misses that lack conventional signatures, plus a potential catalog of tests, detection rules, and reference configurations to implement and verify defensive measures.
- Policymakers and regulators: The draft’s emphasis on confidential reporting, timely notification, and independent governance signals an attempt to balance transparency with legal and contractual constraints; the open RFP invites broader participation in shaping those norms.
- Enterprises and procurement leaders: Organizations operating both open and proprietary systems would be able to receive evidence‑based operational guidance and possibly contribute real‑world incident data to improve defenses against agentic threats.
SAFE’s immediate next step is the open RFP and community development of the guidelines. The draft frames a practical test of whether organizations will share behavioral near misses and whether independent governance can shepherd shared findings without dominance by any single vendor. That question — whether the field will move from private post‑mortems to a shared, actionable catalog of defenses — is the central unresolved item the SAFE proposal puts on the table.




