Members of the Open Secure AI Alliance have proposed SAFE, short for Shared AI Findings Exchange, as a set of guidelines for sharing agentic AI cybersecurity findings.
NVIDIA published the update on August 4 as the Black Hat conference opened in Las Vegas. The post says the Linux Foundation shared a request for comments on SAFE, with contributions from organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat.
The practical point is process. Agentic AI incidents can touch model providers, infrastructure platforms, tool vendors, customers, and downstream services at once. A shared disclosure pattern can help those parties separate confidential intake, technical analysis, affected-party notification, and broader operating guidance.
Agent security needs a common evidence format
The recent Hugging Face and OpenAI evaluation incident showed why ad hoc statements are not enough. When an AI agent probes systems, chains tool actions, or crosses a boundary during testing, responders need more than a public summary.
They need traces: what model or system ran, which tools were enabled, what environment was used, what actions occurred, what systems were touched, how the run was stopped, and what mitigations followed. The sensitive parts may need to stay private, but the structure has to be clear enough for others to learn from the event.
SAFE is still a proposal, not a binding security standard. That distinction matters. The request-for-comments stage is the right place to decide what can be shared publicly, what should remain confidential, how coordinated disclosure should work, and how to avoid turning incident reports into misuse instructions.
Open tools are becoming defensive infrastructure
NVIDIA’s earlier Open Secure AI Alliance announcement framed open models, harnesses, datasets, and safety tools as security infrastructure. The August 4 update extends that idea from tools to governance mechanics.
That is important because open defensive tooling and responsible disclosure are complementary. Tools help teams reproduce and evaluate agent behavior. Disclosure guidelines help them decide how to communicate findings without exposing customers or enabling copycat attacks.
The market consequence is straightforward: enterprise agent buyers will increasingly ask vendors how agent incidents are logged, retained, analyzed, shared, and disclosed.
Sources
- NVIDIA: AI leaders propose SAFE guidelines for cybersecurity transparency
- NVIDIA: Industry leaders unite in Open Secure AI Alliance
- The AI Feed: Hugging Face CEO calls for agent-hack disclosure rules
- The AI Feed: NVIDIA and Anthropic split the open-weight safety debate
- The AI Feed: NVIDIA company profile





