AI Leaders Propose SAFE Guidelines for Cybersecurity Transparency
15:00 · August 4, 2026 · NVIDIA

Members of the Open Secure AI Alliance — now more than 120 organizations strong — are developing new guidelines to strengthen agentic AI cybersecurity as the annual Black Hat conference begins in Las Vegas today. The Linux Foundation today shared a Request for Comments on Shared AI Findings Exchange (SAFE), a proposed set of guidelines […]
Summary
The Open Secure AI Alliance, now comprising more than 120 organizations, and the Linux Foundation have released a Request for Comments on the Shared AI Findings Exchange (SAFE) guidelines. These aim to convert agentic AI security incidents and near-misses into shared, ecosystem-wide protections by confidentially collecting and analyzing events, notifying affected parties, identifying recurring control failures, and issuing evidence-based recommendations that reduce systemic risk.
Alliance members are contributing open-source components that address distinct layers of the AI security stack rather than isolated models. NVIDIA has released the Object-Oriented Agent research harness, the OpenShell runtime for restricting agent actions, the Garak vulnerability scanner, and several open-weight model families with accompanying skill cards that document provenance and risk checks. Red Hat’s asago project maps an organization’s custom governance rules, including references to the EU AI Act, directly to runtime agent permissions and produces a unified audit trail.
Additional contributions span identity controls, orchestration harnesses, specialized defense models, and resilience mechanisms. Okta and Palo Alto Networks provide reference implementations for agent identity and secret management. Microsoft has open-sourced PyRIT for automated red teaming, RAMPART for turning findings into repeatable tests, and Assert for converting natural-language safety requirements into executable evaluations. Amazon contributes the Strands Agents toolkit and the Cedar authorization language, while CrowdStrike fine-tunes a Nemotron Nano variant for security operations triage. LangChain and Veeam add retry, recovery, and data-protection capabilities for production agent workloads.
These tools collectively enable inspection, testing, and governance of agent behavior across identity, execution, evaluation, and recovery stages, supporting coordinated defense as agentic systems scale.
Why it matters
This article highlights major collaborative advancements in AI cybersecurity and governance, which are critical for safe AI deployment. The explicit inclusion of tools designed to map to the EU AI Act makes it highly pertinent for Dutch enterprises and policymakers focused on ethical and compliant AI.








