The information-sharing exchange is designed to widely share lessons learned from agentic AI security incidents.
An alliance of more than 100 tech companies and other organizations is proposing a safety reporting system for AI agents that the group says will help prevent rogue models from wreaking havoc on society.
The Shared AI Findings Exchange(SAFE), crafted by a working group ofthe Open Secure AI Alliance, would establish mechanisms for collecting information about AI-related security incidents, sharing that information with affected organizations, identifying commonalities across incidents and publishing recommendations based on those lessons.
The Linux Foundation, one of the alliance’s lead members, published a request for comments Tuesday on the proposal. SAFE members would be expected to share information about incidents within specified time frames, such as 72 hours for notifying customers of a “credible [data] exposure” and four business days for reporting an incident to the exchange. Organizations would have 30 days to publish a preliminary report on an incident, “subject to security, legal and investigative constraints.”
The proposal comes as policymakers and tech-industry leaders grapple withthe rise of AI agents, their integration intosensitive business functionsandthe paucity of oversightthat these toolsgenerally receive. It also follows on the heels of high-profile incidents in which OpenAI and Anthropic models autonomouslyescaped their test environmentsandhacked other companies.
“Today, organizations often investigate AI security incidents internally, with valuable operational knowledge remaining inside individual companies,”the Linux Foundation said in a blog post. “There is no broadly adopted community framework for confidentially sharing AI operational failures, identifying recurring control failures, and translating those lessons into reusable defensive guidance across the ecosystem.”
The SAFE system would operate “neutrally” and free of any one vendor’s control, the Linux Foundation promised, and members would be expected to report incidents involving both commercial and open-
Alliance members Cisco, CrowdStrike, Hugging Face, NVIDIA and Red Hat helped the Linux Foundation draft the SAFE proposal. Hugging Face was one of several organizations that the OpenAI models hacked after they went rogue.
It remains unclear how much traction the guidelines will receive, either in the policy world or in the AI community. OpenAI and Anthropic, the two companies with the largest influence over AI issues, are not members of the Open Secure AI Alliance.
Filed Under:Strategy,Breaches,Leadership & Careers
