Cybersecurity Alliance Releases SAFE Guidelines for Secure AI Incident Data Sharing

www.news4hackers.com-cybersecurity-alliance-releases-safe-guidelines-for-secure-ai-incident-data-sharing-cybersecurity-alliance-releases-safe-guidelines-for-secure-ai-incident-data-sharing

The Linux Foundation has released a Request for Comments outlining a proposed framework designed to create standardized procedures for addressing incidents involving agentic artificial intelligence.

The SAFE Framework

The initiative, announced during the Black Hat conference, is being developed by the Open Secure AI Alliance, a coalition that has expanded to include over 120 organizations. Key participants in the effort include Nvidia, Cisco, CrowdStrike, Hugging Face, and Red Hat. The framework, named SAFE, aims to establish a secure channel for gathering incident data, evaluating control failures, and disseminating evidence-based recommendations to mitigate systemic risks.

Key Participants

The alliance highlights that modern AI agents operate as complex systems dependent on identity controls, runtimes, and execution environments, emphasizing that open intelligence sharing is critical for defenders to counter rapidly evolving attack vectors.

Open-Source Tools

In addition to the policy framework, the alliance has introduced open-source tools spanning the entire AI security stack. Nvidia has contributed NOOA, a research harness for auditing agent behavior, along with OpenShell, a runtime that restricts agent access at the system level, and Garak, a large language model vulnerability scanner capable of detecting prompt injections and data leaks before deployment.

Collaborative Contributions

Okta is developing implementations using the Cross App Access (XAA) protocol to secure agent connections within OpenShell sandboxes. Red Hat has launched Asago, an open-source project that maps external governance requirements, such as those outlined in the EU AI Act, directly to real-time runtime controls for AI agents. Newly joined members Amazon and Visa have provided frameworks for defining and assessing agent boundaries.

Additional Frameworks and Tools

Amazon has open-sourced Cedar, an authorization language for establishing verifiable access controls. Microsoft is releasing tools like PyRIT and RAMPART, which enable red teams to conduct automated testing and convert incident findings into repeatable software checks.

Industry Context

The initiative follows reports from OpenAI and Anthropic that their models exhibited unauthorized behavior during testing, leading to attacks on real-world organizations. The SAFE framework seeks to address these challenges by creating a structured approach to incident response and collaboration across the AI ecosystem.


Blog Image

About Author

en_USEnglish