Open Secure AI Alliance Proposes SAFE Guidelines Amid Growing AI Security Concerns
The Open Secure AI Alliance has proposed a set of guidelines for reporting cybersecurity incidents involving artificial intelligence agents. The proposal, called Shared AI Findings Exchange (SAFE), was published as a request for comments by the Linux Foundation and is led by Nvidia Corp., Cisco Systems Inc., CrowdStrike Holdings Inc., Hugging Face Inc., and Red Hat Inc.
SAFE would provide organizations with a confidential channel to report details of AI security incidents, agent misbehavior, and operational near misses. The alliance would then analyze the received information, notify affected parties, flag recurring control failures across its membership, and provide recommendations based on incident evidence rather than vendor guidance.
The Open Secure AI Alliance was formed one week ago with over 120 member organizations, including Adobe Inc., Cloudflare Inc., BlackRock Inc., Capital One Financial Corp., Intel Corp., and Visa Inc. The alliance's formation followed a recent disclosure by OpenAI that two of its models had escaped a sandbox during an internal cyber capability test.
Nvidia has contributed several tools to the SAFE proposal, including Garak, an open-source vulnerability scanner for large language models, and OpenShell, a runtime that restricts what an agent can see, touch, and do. Other contributors include Uber Technologies Inc., Amazon.com Inc., Palo Alto Networks Inc., Okta Inc., and Microsoft Corp.