Backed by more than 120 leading AI, cybersecurity, and technology companies, the draft calls for confidential reviews of AI incidents, notices to affected organizations, and public recommendations based on repeated security failures.
The Open Secure AI Alliance proposed SAFE guidelines for companies to share AI security incidents and near misses confidentially, warn affected organizations, and publish recommendations that could help prevent similar failures.
The Linux Foundation published the proposal under the name Shared AI Findings Exchange, or SAFE, and invited the public to provide input.
NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat are among the alliance members developing the proposed guidelines.
SAFE looks to turn incidents into shared defenses
The proposed process would confidentially collect and examine reports of cyberattacks, other cybersecurity failures and near misses involving AI agents.
The proposal calls for organizations affected by an incident to be notified. Reported cases would also be examined to identify security controls that failed repeatedly and develop public recommendations based on the evidence.
The proposal would give participating companies a way to share useful security information without immediately making sensitive incident details public. Published recommendations could allow other organizations to strengthen their own controls before they experience the same type of failure.
NVIDIA did not disclose specific reporting deadlines or say when the guidelines could be finalized.
Members add tools for controlling and testing AI agents
The SAFE proposal is part of a larger collection of open security tools that alliance members are making available for companies to inspect and adapt.
NVIDIA contributed software that records how AI agents behave during tests and restricts their access and actions. It also contributed tools that help companies enforce safety rules, protect sensitive data, and test AI models for data leaks or attempts to bypass safeguards.
Other contributions focus on identity and access. Okta is developing a way for AI agents operating in restricted environments to connect securely to company applications. Palo Alto Networks contributed tools that help developers control agent identities and retrieve passwords or other digital credentials securely.
Red Hat contributed a project that turns company policies and outside requirements into restrictions on what AI agents can do. It also records each restriction and maps them back to the corresponding policy or requirement.
Amazon contributed tools that let developers inspect agent behavior and set precise limits on which agent actions can reach company systems.
Microsoft contributed software that converts security incidents and written safety requirements into repeatable tests. Companies can run those tests again after software changes to check whether earlier problems have returned.
Cisco and CrowdStrike contributed more specialized tools for cyber defense. Cisco’s projects help companies apply security controls while AI agents are operating and locate known software weaknesses. CrowdStrike is adapting an NVIDIA model to help security teams generate investigation searches and sort security alerts.
Alliance grows beyond its original membership
The update follows the formation of the Open Secure AI Alliance with more than 50 AI, cybersecurity, and enterprise technology organizations.
When launched in July, the alliance announced plans to develop shared tools for verifying AI agent identities, controlling access, examining behavior, and isolating agents when necessary. NVIDIA presented the group partly as a response to the Hugging Face security incident, which showed the need for defensive AI tools that companies can inspect, adapt, and run on their own systems.
The alliance now has more than 120 members. Amazon and Visa are among the newest members, and NVIDIA said more security contributions are coming.

