SAFE Guidelines Aim to Set a Common Cybersecurity Standard for Agentic AI
Linux Foundation seeks feedback on SAFE guidelines as NVIDIA, Amazon, Microsoft and others expand open tools to secure agentic AI systems and sensitive data.
Summary
Reported facts: On August 4, 2026, the Linux Foundation issued a Request for Comments on Shared AI Findings Exchange, or SAFE, as the Black Hat conference opened in Las Vegas. The proposed guidelines are being developed by a working group within the Open Secure AI Alliance, which NVIDIA says now includes more than 120 organizations. Initial contributors include NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat. SAFE is intended to create a confidential process for collecting and analyzing agentic AI incidents and near misses, notifying affected parties, identifying recurring control failures and publishing recommendations based on accumulated evidence.
The proposal addresses the fact that an AI agent is a broader system rather than an isolated model. Its security depends on identity controls, orchestration software, tools, runtime restrictions, logs, evaluations and data safeguards. The alliance argues that sharing incident intelligence and reusable mitigations could help defenders respond at the speed of automated agents. However, SAFE is still open for comment: the article does not specify a final publication date, participation requirements, an enforcement mechanism or how confidential information would be governed across organizations and jurisdictions.
The announcement also catalogs NVIDIA’s open security technologies. These include the NVIDIA Labs Object-Oriented Agent research harness for testing and auditing behavior; the OpenShell runtime for limiting what agents can access or do; and verified agent skills that are scanned, documented and cryptographically signed. NeMo Guardrails, NeMo Anonymizer and NeMo Safe Synthesizer address policy enforcement and data privacy, while Garak scans large language models for leaks, prompt injection and jailbreak risks. NVIDIA also highlights open model families spanning general agents, physical AI, robotics, healthcare and autonomous vehicles, although several performance and scale descriptions come from NVIDIA itself.
Other alliance members are contributing controls across the stack. Amazon joined the alliance on August 4 and supplied Strands Agents and the Cedar authorization language. Okta is developing agent identity implementations using Cross App Access, while Red Hat’s asago maps governance requirements to runtime controls. Microsoft has released PyRIT, RAMPART, Clarity and Assert for red teaming, incident testing, design review and executable evaluation. Cisco contributed DefenseClaw and security-focused Antares models; Mistral released Shieldstral under Apache 2.0; and Visa joined with an open vulnerability-testing harness. LangChain and Veeam are separately working on recovery, fallback and data-protection capabilities.
Two reported deployments indicate that some of this work has moved beyond prototypes. CrowdStrike said internal testing of a Nemotron Nano model produced investigation queries for Falcon LogScale with 96% accuracy, though the article does not provide an independent benchmark or detailed methodology. Uber said its open-sourced Agentic AI Detection and Response components support more than 200,000 agent sessions each day across 30,000 endpoints. The broader significance is that enterprises deploying agents may gain inspectable building blocks and shared lessons instead of designing every defense alone. What happens next depends on feedback to the SAFE request, the alliance’s ability to establish trusted disclosure practices and whether organizations adopt interoperable controls rather than a collection of disconnected tools.
Positives
- The Open Secure AI Alliance has grown to more than 120 organizations, giving the SAFE proposal participation from companies including NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat.
- SAFE proposes confidential analysis of both incidents and near misses, along with notifications to affected parties and evidence-based recommendations for reducing repeated failures.
- Amazon and Visa joined the alliance on August 4, 2026, adding open-source agent-building, authorization and vulnerability-testing technologies to the shared ecosystem.
- Uber reports that its Agentic AI Detection and Response system handles more than 200,000 agent sessions per day across 30,000 endpoints, demonstrating production-scale monitoring.
- Alliance members are covering multiple security layers, including Okta’s identity work, Microsoft’s red-team tools, NVIDIA’s runtime restrictions and LangChain’s recovery capabilities.
Risks & concerns
- SAFE remains a Request for Comments, and the article provides no deadline for final guidelines, adoption commitments or enforcement arrangements.
- The proposal calls for confidential incident sharing but does not explain how sensitive disclosures, legal liability or cross-border data requirements would be managed.
- CrowdStrike’s reported 96% accuracy for generating Falcon LogScale investigation queries is based on internal testing, with no independent validation or detailed benchmark methodology cited.
- The large number of separate identity, runtime, evaluation and recovery projects creates a potential integration problem because the article does not establish that these tools are interoperable.
- The source is an NVIDIA corporate blog that prominently features NVIDIA products, so product performance and comparative claims should be treated as company-supplied rather than independent findings.
