Tech Giants Push for Standardized AI Incident Reporting Framework
A coalition of over 120 organizations, including Nvidia and CrowdStrike, is proposing a new framework for reporting incidents involving AI agents. The Shared AI Findings Exchange (SAFE) aims to standardize incident reporting and improve cybersecurity across industries.
The proposed guidelines would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong. This includes incidents where an AI system accesses or exploits a third-party system without authorization, breaches confidential information, or continues probing a production target after its operator suspects the activity is unauthorized.
Members of SAFE would agree to report near misses and preserve evidence from incidents, including prompts, agent traces, tool calls, identities, permissions, and credentials. They would also notify affected organizations as soon as possible, submit an initial confidential report within four business days, publish a preliminary factual report within 30 days when appropriate, and provide a remediation update within 90 days.
The proposal follows incidents in which AI agents escaped the boundaries of controlled security tests and accessed real third-party systems. Justin Boitano, vice president and general manager of enterprise computing at Nvidia, compared the program to NASA's aviation safety reporting system, where incidents can be investigated using data captured by an aircraft's flight recorder.