Linux Foundation opens review of SAFE AI incident exchange

The Linux Foundation issued a Request for Comments on SAFE, a framework from the Open Secure AI Alliance to standardize sharing of agentic AI incident data and produce actionable threat intelligence.
The Linux Foundation has opened a Request for Comments on SAFE, a proposed Shared AI Findings Exchange from the Open Secure AI Alliance. Announced at the Black Hat security conference in Las Vegas, the proposal aims to standardize how incidents involving agentic AI are reported, analyzed and shared as threat intelligence.
The Open Secure AI Alliance, a coalition of more than 120 organizations, is driving the SAFE effort. Named participants include Nvidia, Cisco, CrowdStrike, Hugging Face and Red Hat. The Request for Comments invites input from security teams, vendors and researchers on the technical design, privacy protections and governance of the exchange.
SAFE describes a confidential pipeline for collecting incident reports and technical evidence, standardizing analyses of control failures, and distributing recommendations as actionable indicators or protective controls. The framework is intended to let organizations share structured intelligence without exposing sensitive data.
Several alliance members have released open source tools that map to parts of the SAFE concept. Nvidia contributed NOOA, a research harness for auditing agent behavior, OpenShell, a runtime that limits agent system access, and Garak, a scanner for prompt injection and data leakage. Red Hat published Asago, a project that links external governance rules, including EU AI Act requirements, to live runtime controls for agents.
Amazon and Visa provided frameworks for defining and testing agent boundaries. Amazon also open-sourced Cedar, an authorization language for verifiable access controls. Microsoft supplied PyRIT and RAMPART, tools for red teams to run automated tests and convert findings into repeatable software checks. Okta is working on implementations that use the Cross App Access protocol to secure agent connections inside OpenShell sandboxes.
The proposal follows recent test incidents in which large AI models performed harmful or unintended actions while under evaluation. OpenAI and Anthropic reported cases where models executed actions that targeted real organizations. The alliance notes that agentic systems combine identity controls, runtimes and execution harnesses, a mix that can make it difficult for single organizations to track and respond to new exploit techniques.
Under the draft SAFE process, incident reports would be collected confidentially, control-failure analyses would use a common format, and mitigations would be shared as technical indicators or configuration checks. The Linux Foundation said the RFC period is intended to refine the guidelines ahead of wider use.
The Open Secure AI Alliance plans to expand its open source and interoperability work so operators can run consistent tests and apply the same defensive checks across environments. The RFC frames SAFE as complementary to existing vulnerability-sharing mechanisms while targeting failure modes specific to agentic AI systems.








