Members of the Open Secure AI Alliance — now spanning more than 120 organizations — unveiled new guidelines to strengthen agentic AI cybersecurity as Black Hat USA 2026 opened in Las Vegas. The Linux Foundation shared a Request for Comments on the Shared AI Findings Exchange (SAFE), a proposed set of guidelines designed to turn agentic cybersecurity incidents into shared protection for the entire ecosystem.
The SAFE guidelines are being drafted by an Open Secure AI Alliance working group, with NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat among the members working with the Linux Foundation on the initial proposal. SAFE aims to collect and analyze information on AI incidents and near misses, using that data to alert affected parties, identify recurring failure patterns, and publish recommendations to reduce systemic risk across the industry.
The framework builds on the alliance's broader mission. The Open Secure AI Alliance builds on the leadership of the Linux Foundation's Akrites initiative and OpenSSF community work, aiming to remediate and disclose vulnerabilities using open technologies — framed around a core choice facing AI security: whether the defenses protecting critical infrastructure sit inside a handful of opaque systems, or are built on open models, harnesses, and tools that any defender can study, adapt, and deploy.
Beyond SAFE, the alliance has been moving quickly since its founding. Its scope covers the full agent stack — identity, permissions, isolation, guardrails, logs, model formats, multi-model scanning, and secure coding workflows — pitched around the idea that defenders need AI models they can read, change, and run on their own hardware, not only closed systems reached through a vendor's API. Contributions already include RAMPART, which turns red-team findings and real-world incidents into repeatable tests that run as software changes; Microsoft's open-sourced Assert, which converts natural language safety requirements into executable evaluations; Wiz's Atlas, an autonomous vulnerability research engine orchestrating specialized AI agents to find and validate security flaws; and Visa's open-sourced Vulnerability Agentic Harness for issue identification and remediation.
Three things stand out about this launch, beyond the headline guidelines themselves.
Speed is the real story. The Open Secure AI Alliance is barely a week old, yet it's already presenting proposals for open comment through the Linux Foundation — a pace TechCrunch specifically flagged as unusual for an industry consortium this size. That urgency reflects genuine pressure: the group was formed by NVIDIA with backing from IBM and Microsoft, building explicitly on recent breaches at Hugging Face and other companies. This isn't a slow-moving standards body; it's a reactive formation responding to live incidents.
The absence list is as telling as the membership list. OpenAI, Google, and Meta appear among the signatories of a related policy letter but are absent from the alliance's inaugural membership roster, and Anthropic appears on neither list as of late July 2026 — with no public explanation for why the major closed-model labs have stayed outside a coalition otherwise spanning Microsoft, Cisco, CrowdStrike, Hugging Face, Red Hat, and more than 100 other companies. That split maps onto a real philosophical divide the alliance itself has articulated: the industry needs both closed and open models, but for cybersecurity specifically, open models and harnesses are seen as essential because they democratize defensive capabilities and increase transparency for defenders — a position that sits somewhat at odds with how the largest frontier-model labs currently operate.
This is a direct, structural answer to the "agentic AI as attack surface" problem we've discussed throughout this conversation — from Mythos's autonomous exploit discovery to AI-powered phishing detection embedded in ChatGPT and Claude. As AI agents gain more autonomy and access across enterprise systems, a single company's incident response is no longer sufficient; SAFE is essentially proposing the security equivalent of CVE databases and threat-intel sharing, but purpose-built for agentic AI failures specifically — blame-free incident analysis so the whole ecosystem learns from one company's breach rather than each learning the same lesson independently, often the hard way.
The test now is whether an RFC-stage framework from a week-old alliance converts into something enterprises actually adopt — and whether the absence of OpenAI, Google, and Anthropic from the core membership becomes a lasting fault line or gets resolved as the framework matures.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




