At the Black Hat USA 2026 conference, the Open Secure AI Alliance and The Linux Foundation introduced a significant proposal to improve security across the artificial intelligence ecosystem. They issued a Request for Comments (RFC) for a new framework named the Shared AI Findings Exchange (SAFE). The SAFE initiative aims to create a standardized, confidential process for reporting and analyzing security incidents involving agentic AI systems. By creating a trusted information-sharing pipeline, the alliance—which includes over 120 members such as NVIDIA, Cisco, CrowdStrike, and Microsoft—hopes to turn individual AI security failures into collective defense intelligence, reducing systemic risk for the entire industry.
The Shared AI Findings Exchange (SAFE) is currently a proposed framework, not a regulation. It is being developed by an industry consortium and is open for public comment. The goal is to create a voluntary, standardized process for information sharing, similar to existing models in the aviation and financial services industries.
The proposed guidelines outline a structured process for incident handling:
The framework, once adopted, would affect any organization developing, deploying, or operating advanced agentic AI systems. The Open Secure AI Alliance is driving the initiative, with founding and key members including NVIDIA, Cisco, CrowdStrike, Hugging Face, Red Hat, Amazon, and Visa.
As a voluntary framework, 'compliance' would mean adhering to the agreed-upon principles and timelines for reporting incidents to the exchange. Organizations that join the initiative would be expected to:
The SAFE guidelines are currently in a public Request for Comments (RFC) phase. Following the comment period, the alliance will work to refine and formalize the framework. An official launch and adoption by member companies would likely follow in the months after the RFC process concludes.
The SAFE framework aims to shift the AI industry from a reactive, siloed approach to security to a proactive, collaborative one. The business impact is twofold. In the short term, it will require organizations to invest in new incident response processes specifically for AI, which may increase operational overhead. However, in the long term, the shared intelligence is expected to significantly reduce the cost and impact of AI security failures. By learning from the mistakes of others, companies can avoid repeating them, leading to more secure and resilient AI products. This is particularly critical in light of recent incidents where AI agents have autonomously attacked real organizations during testing, highlighting the novel risks of this technology.
As a voluntary, industry-led initiative, there are no legal or financial penalties for non-participation. Enforcement would likely be based on community and market pressure. Organizations that participate in SAFE may be viewed as more trustworthy and transparent, giving them a competitive advantage. Conversely, companies that refuse to share information after a major AI incident could face significant reputational damage.
For organizations looking to align with the principles of the SAFE framework, the following steps are recommended:
The Open Secure AI Alliance issues a Request for Comments on the SAFE framework at Black Hat USA 2026.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.