<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die" -->

---
title: The SAFE Working Group wants to build a shared database...
description: The Linux Foundation and Open Secure AI Alliance have published an RFC for SAFE (Shared AI Findings Exchange), a proposed shared database of AI security...
canonical: https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The SAFE Working Group wants to build a shared database of AI security incidents | daily.dev
og:description: The Linux Foundation and Open Secure AI Alliance have published an RFC for SAFE (Shared AI Findings Exchange), a proposed shared database of AI security...
og:url: https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die
og:image: https://api.daily.dev/og/posts/HYjgy7DIe.png
og:image:alt: The SAFE Working Group wants to build a shared database of AI security incidents
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The SAFE Working Group wants to build a shared database of AI security incidents

**[Collections](https://daily.dev/sources/collections)** · 3 min read · 1 upvotes · 0 comments

## Summary

The Linux Foundation and Open Secure AI Alliance have published an RFC for SAFE (Shared AI Findings Exchange), a proposed shared database of AI security incidents modeled after NASA's Aviation Safety Reporting System. Organizations could report AI operational failures confidentially to help the community identify patterns and build defenses. The initiative, developed with input from Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat, Amazon, and Microsoft, aims to produce evidence-based defensive guidance, reusable detection rules, and incident response playbooks. The Open Secure AI Alliance (120+ members) is also coordinating open source tool contributions covering agent identity, runtime guardrails, observability, and resilience — including NVIDIA's NOOA, the Garak LLM vulnerability scanner, Microsoft's PyRIT and RAMPART, and LangChain's agent recovery capabilities. The RFC is open for community review on GitHub.

## Content

# The Open Secure AI Alliance launches SAFE, a framework for sharing AI security incidents

The Open Secure AI Alliance (OSAA), an industry group spearheaded by NVIDIA with over 120 member organizations, has proposed a new framework for handling AI security incidents. Announced at Black Hat 2024 in Las Vegas, the Shared AI Findings Exchange (SAFE) Working Group published an RFC outlining how organizations could confidentially report AI failures and near misses without fear of blame.

The proposal was developed by contributors from Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat, and others, in collaboration with the Linux Foundation. The RFC is open for community review on GitHub.

## What SAFE is trying to do

The model here is NASA's Aviation Safety Reporting System — a confidential, blame-free channel where pilots and crew report incidents that might otherwise go unmentioned. SAFE would apply the same logic to AI: collect incident reports, identify recurring control failures across organizations, and publish evidence-based defensive guidance.

The framework is designed to be vendor-neutral, covering both open and proprietary AI systems. Beyond incident collection, it envisions publishing reusable tests, detection rules, and incident response playbooks that any organization could adopt.

The focus is specifically on agentic AI systems — the kind that operate with some autonomy, make decisions, and take actions. These are harder to monitor and easier to misuse than traditional software, which makes the lack of shared incident data a real gap.

## Tools already in the mix

Alongside the SAFE proposal, alliance members are cataloging open source tools relevant to AI agent security. A few worth noting:

- **NVIDIA**: NOOA research harness, OpenShell runtime, and the Garak LLM vulnerability scanner
- **Microsoft**: PyRIT (Python Risk Identification Toolkit) and RAMPART
- **CrowdStrike**: A fine-tuned Nemotron Nano model for cyber defense tasks
- **LangChain**: Resilience capabilities for agent recovery
- **Okta**: Agent identity and permissions work
- **Red Hat**: Agent governance tooling
- **Amazon**: Strands Agents framework and Cedar authorization language

The coverage spans the full AI security stack — agent identity, runtime guardrails, observability, and resilience.

## Who's in, who's not

The alliance formed just a week before Black Hat, which makes the pace of output notable. Current members include Adobe, Amazon, BlackRock, Cisco, Intel, Microsoft, and Visa, among others.

Notably absent: Anthropic, OpenAI, and Google. This is awkward given that OpenAI and Google both signed the original open letter that prompted the group's formation. Neither has joined as of the announcement.

The alliance itself emerged partly in response to U.S. government discussions about restricting Chinese open weight AI models — a context that gives the group's vendor-neutral framing some added significance.

The RFC is available on GitHub for anyone who wants to review or contribute.

---

Tags: [#open-source](https://daily.dev/tags/open-source), [#llm](https://daily.dev/tags/llm), [#ai-security](https://daily.dev/tags/ai-security)

[View this post on daily.dev](https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"The SAFE Working Group wants to build a shared database of AI security incidents","url":"https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die"},"datePublished":"2026-08-04T13:22:24.834Z","dateModified":"2026-08-06T09:43:13.172Z","description":"The Linux Foundation and Open Secure AI Alliance have published an RFC for SAFE (Shared AI Findings Exchange), a proposed shared database of AI security...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f62876727c89b845e341a2be735b96f1?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/f62876727c89b845e341a2be735b96f1?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/the-safe-working-group-wants-to-build-a-shared-database-of-ai-security-incidents-hyjgy7die","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"open-source,llm,ai-security","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"The SAFE Working Group wants to build a shared database of AI security incidents"}]}
```

