Summary
- The Linux Foundation has opened an RFC for a Shared AI Findings Exchange working group.
- SAFE is intended to help organisations learn confidentially from AI incidents, near misses, and recurring control failures.
- The proposal comes from the Open Secure AI Alliance, which NVIDIA says now includes more than 120 organisations.
Members of the Open Secure AI Alliance are proposing a shared mechanism for learning from AI security incidents and near misses as autonomous systems gain access to browsers, code execution, enterprise identities, and external tools.
The Linux Foundation has opened a request for comments on the Shared AI Findings Exchange, or SAFE, a proposed working group intended to help organisations confidentially analyse failures and turn them into broader security guidance.
NVIDIA says the Open Secure AI Alliance has grown to more than 120 organisations. Participants involved in the SAFE proposal include technology and security companies working across AI models, infrastructure, open-source software, and enterprise security.
The proposal remains an RFC rather than a standard, regulatory reporting requirement, or operational incident-sharing service. The current stage is intended to establish scope, governance, participation rules, and the process through which findings could eventually be shared.
The Linux Foundation describes the project as a way for organisations to learn from AI incidents and near misses without requiring every participant to experience the same failure independently. The proposed model would look for recurring weaknesses and turn them into practical guidance for the wider ecosystem.
That fills a less mature part of AI security. Conventional cybersecurity already has established mechanisms for vulnerability disclosure, threat-information sharing, incident reporting, and common weakness classification. AI failures can be harder to describe consistently because the relevant system may include a model, prompts, orchestration software, retrieved data, tools, identity permissions, and human approvals at the same time.
A browser agent that acts on malicious instructions embedded in a web page may involve no conventional software vulnerability. An autonomous coding system that reaches an unintended external target may be behaving through legitimate network and tool permissions. A model that exposes information may do so only under particular context or sequencing.
Shared incident data could help separate recurring architectural problems from one-off implementation bugs. Similar failures appearing across unrelated deployments would provide stronger evidence for changes to controls than isolated demonstrations considered independently.
SAFE extends an alliance that initially concentrated on open AI security tooling and infrastructure. The new proposal adds a mechanism for learning from what happens after safeguards behave unexpectedly or fail.
The project will also have to solve an incentive problem. Organisations may be reluctant to disclose that an internal AI system accessed the wrong service, exposed information, crossed an authorisation boundary, or performed an unintended action, particularly while liability and regulatory expectations are still evolving.
Removing too much detail, however, would reduce the value of the exchange. Identifying whether several incidents share the same permission design, prompt-injection path, model behaviour, or orchestration failure requires more technical context than a generic incident summary.
European organisations will also need to distinguish voluntary industry sharing from statutory obligations. The EU AI Act, NIS2, DORA, data-protection law, and sector regulation can create reporting or governance requirements in specific circumstances. Contributing information to SAFE would not replace notifications required by law.
The proposal is therefore closer to collective engineering infrastructure than a compliance mechanism. Its value will depend on whether participants submit sufficiently detailed failure data, whether findings can be shared without exposing confidential information, and whether the governance model gives contributors confidence that disclosures will not be controlled by one vendor or market segment.
The RFC provides the industry with a chance to establish those rules before AI incident reporting becomes dominated by incompatible internal taxonomies. As agentic systems accumulate more authority, the quality of evidence about how they fail is likely to become as important as the controls intended to prevent those failures in the first place.




