HyperAIHyperAI

Command Palette

Search for a command to run...

Open Secure AI Alliance Proposes SAFE Guidelines for Cybersecurity Transparency

Members of the Open Secure AI Alliance, a consortium of over 120 organizations, have advanced new cybersecurity frameworks to address threats to agentic AI systems. Launching alongside the Black Hat conference in Las Vegas, the Linux Foundation issued a Request for Comments for the Shared AI Findings Exchange, or SAFE, a proposed standard designed to strengthen cybersecurity transparency and foster collective defense across the AI ecosystem. The SAFE guidelines, developed by an alliance working group comprising NVIDIA, Cisco, CrowdStrike, Hugging Face, Red Hat, and other members, establish a protocol for the confidential collection and analysis of AI incidents and near misses. The framework aims to inform impacted parties of security events, identify recurring control failures, and publish evidence-based operating recommendations to reduce systemic risk. This initiative reflects the industry consensus that securing AI agents requires rapid collaboration; defenders must share threat intelligence openly to transform individual vulnerabilities into ecosystem-wide protection. Beyond guidelines, the alliance is delivering a comprehensive suite of open-source tools spanning the full AI security stack. NVIDIA continues to expand its infrastructure with the NOOA research harness for agent behavior auditing, the OpenShell runtime for enforcing privacy and access controls, and the Garak vulnerability scanner. The company also ships open-weight model families and cryptographically signed agent skills to ensure trust at the capability layer. Other contributors have released targeted solutions across identity, orchestration, and defense layers. Okta, Palo Alto Networks, and Red Hat have advanced identity and permissions tools, including Cross App Access references, Agent Guard, and the asago governance mapper, which aligns runtime agent actions with regulatory requirements such as the EU AI Act. In tooling and harnesses, Amazon contributed Strands Agents and the Cedar authorization language for deterministic access control. Microsoft open-sourced PyRIT, RAMPART, and Assert to automate red-teaming and safety evaluations, while Wiz, Capital One, Cloudflare, and Visa added autonomous vulnerability research engines and specialized agentic harnesses. Specialized models and resilience mechanisms are also being deployed to harden the landscape. Cisco introduced DefenseClaw for automated runtime governance and Antares security small language models to detect code vulnerabilities. CrowdStrike highlighted the performance of fine-tuned NVIDIA Nemotron Nano models for high-accuracy security operations and triage. Resilience efforts include LangChain's recovery capabilities for interrupted agent work and Veeam's Kanister framework for protecting AI workloads on Kubernetes. Additionally, Perplexity released the Numbat agent security suite for endpoints, and Uber open-sourced its Agentic AI Detection and Response system to reconstruct causal chains of agent activity across production environments. The alliance will host a group gathering at Black Hat on Tuesday, August 4, at 5:15 PM PT outside the Main Stage at the Mandalay Bay Convention Center. The Linux Foundation invites industry stakeholders to review the SAFE proposal and explore opportunities to join the Open Secure AI Alliance in advancing open, inspectable security standards for agentic AI.

Related Links