NVIDIA and 120+ industry members propose SAFE guidelines for sharing AI security incidents
NVIDIA and more than 120 other members of the Open Secure AI Alliance proposed a new industry framework called SAFE — Shared AI Findings Exchange — on August 4, 2026, timed to the Black Hat security conference in Las Vegas, according to NVIDIA's official blog post on the announcement.
What's new
NVIDIA describes SAFE as "a proposed set of guidelines designed to turn agentic cybersecurity incidents into shared protection for the entire ecosystem." The framework's stated purpose is to "confidentially collect and analyze AI incidents and near misses, inform those impacted, identify recurring control failures and publish evidence-based operating recommendations that reduce systemic risk."
- NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat are named as contributors to the initial proposal
- Amazon and Microsoft are highlighted among companies contributing tools and frameworks to the broader Alliance effort
- The Alliance's work spans identity controls, agent harnesses, runtime guardrails, models designed for security, observability, and data protection
- The Linux Foundation published a Request for Comments on the SAFE guidelines to coincide with the announcement
Context
The proposal responds to a structural problem in AI security: individual companies discover agentic-AI incidents and near misses in isolation, with no shared channel to warn the rest of the ecosystem about a control failure that could recur elsewhere. Traditional cybersecurity has long relied on threat-sharing bodies (ISACs, CERTs) for exactly this kind of confidential incident exchange — SAFE is an attempt to build an equivalent for AI-agent-specific incidents.
The announcement also lands the same day Mistral AI released Shieldstral, an open safety classifier explicitly tied to Mistral's membership in the same Open Secure AI Alliance — suggesting member labs are shipping both guidelines and concrete tooling in coordination around this Black Hat window.
Why it matters
Agentic AI systems increasingly take real-world actions — executing code, calling tools, controlling infrastructure — which raises the stakes of security failures well beyond a chatbot giving a bad answer. A shared, confidential incident-exchange framework, if adopted broadly, would let the industry catch recurring failure patterns (a specific jailbreak class, a specific tool-use exploit) faster than any single company could on its own.
The list of contributors — spanning AI labs (NVIDIA, Hugging Face), security vendors (CrowdStrike, Cisco), and cloud/infrastructure providers (Amazon, Microsoft, Red Hat) — signals unusually broad buy-in for an AI governance proposal at this stage. Because it is still an RFC rather than a ratified standard, the real test will be whether member organizations commit to actually reporting incidents into it once the mechanism exists, rather than treating it as a one-time announcement.
Corroborating sources
- Blogs.nvidia
https://blogs.nvidia.com/blog/open-secure-ai-alliance-contributions/
“a proposed set of guidelines designed to turn agentic cybersecurity incidents into shared protection for the entire ecosystem”