Nvidia, Cisco Lead Industry-Wide Effort for AI Agent Security Incident Reporting
About 120 organizations, including Nvidia, Cisco, and CrowdStrike, are working together to establish a joint framework for reporting security incidents involving artificial intelligence (AI) agents.
This move reflects the industry's need to share control failures and security incidents as more AI agents perform tasks across multiple computer systems and tools without human intervention.
The Open Secure AI Alliance has prepared a draft guideline for a cyber incident reporting system called SAFE, or Shared AI Findings Exchange. This includes companies that deploy and develop AI models, cloud providers, independent researchers, and operators of key infrastructure.
The draft requires member companies to report cases where an AI system accessed or attacked a third-party system without authorization, compromised confidential information, or continued probing a live operating system despite suspecting it lacked access rights. Certain levels of near misses are also subject to reporting.