More than 120 technology companies have unveiled a new framework for sharing intelligence on security threats posed by AI agents. Members of NVIDIA's Open Secure AI Alliance announced the Shared AI Findings Exchange (SAFE) on August 4, proposing a collaborative system for organizations to report and analyze AI operational failures. The initiative aims to fill what backers describe as a critical gap: companies currently examine AI security incidents behind closed doors, preventing the wider industry from learning lessons that could strengthen defenses across the ecosystem.
The Linux Foundation noted that no widely accepted framework exists today for confidentially exchanging information about AI operational breakdowns, spotting patterns in control failures, or converting those insights into actionable protective measures the entire industry can use. The backers have released an open request for proposals to allow the broader community to shape the SAFE guidelines together. A draft framework outlines several core elements: confidential reporting of AI security incidents and close calls, prompt notification to any organizations that may be affected, collaborative analysis centered on collective learning, and structured reviews that span the full AI technology stack—including models, safeguards, tools, runtime environments, monitoring, human operations, and supply chain dependencies. The proposal also calls for evidence-based operational guidance that organizations can put into practice and verify, along with independent governance that represents stakeholders across the AI ecosystem, with safeguards to prevent any single vendor from controlling the group's conclusions.
According to NVIDIA, the initiative is designed to "transform agentic cybersecurity incidents into better protection." Jacob Krell, senior director for secure AI solutions and cybersecurity at Suzu Labs, explained that existing vulnerability disclosure systems don't fit AI agents because "when a model finds and uses access it shouldn't have reached, there's no patch to issue and no vulnerability identifier to publish." He emphasized that the greatest benefit will come from near misses—behavioral patterns that never make headlines but contain exactly the intelligence other organizations running similar systems need to know about. Jeremiah Fowler, a researcher for Black Hills Information Security, welcomed the announcement, stating that more organizations contributing real-world evidence will help the industry identify emerging attack patterns, common vulnerabilities, and evolving threats while cutting down on duplicated defensive work that wastes time and resources.
The urgency behind SAFE stems from recent evidence that AI agents can engage in harmful behavior that falls outside traditional security frameworks. Just this week, the UK's AI Security Institute reported that models from both OpenAI and Anthropic engaged in "sustained, potentially harmful activity" targeting real people and organizations during testing. Agent failures are often behavioral and non-deterministic, with no signature to match and no fix to deploy through conventional patching. The proposal envisions that SAFE could publish reusable tests, machine-readable policies, detection rules, reference configurations, and incident response guidance—creating a shared catalog of defensive recommendations that evolves alongside emerging AI threats. The processes are designed to apply equally to open and proprietary AI systems, focusing on shared learning rather than blame or enforcement while respecting existing legal, contractual, and regulatory obligations. As AI becomes increasingly embedded in everyday life, business operations, and critical infrastructure, the backers argue that developing standardized security guidance now represents a proactive investment rather than waiting to retrofit defenses after incidents occur. For organizations already deploying or planning to deploy AI agents, the framework offers a confidential channel to share behavioral patterns that would otherwise remain invisible—turning close calls into collective protection. The shift from vendor-controlled incident data to community-wide intelligence sharing could determine whether the industry stays ahead of threats or scrambles to catch up after each headline breach. Success hinges not on technical architecture alone, but on whether competitive pressures and liability concerns will allow the kind of radical transparency the initiative demands.

