Today's AI/ML headlines are brought to you by ThreatPerspective

Digital Event Horizon

A New Era of Cybersecurity Transparency: The SAFE Guidelines for Agentic AI


A New Era of Cybersecurity Transparency: The SAFE Guidelines for Agentic AI

  • The Open Secure AI Alliance has proposed the SAFE (Shared AI Findings Exchange) guidelines for agentic AI cybersecurity transparency.
  • The SAFE framework aims to strengthen agentic AI cybersecurity by transforming cybersecurity incidents into better protection.
  • The guidelines propose three key components: confidentially collecting and analyzing AI incidents, informing those impacted, identifying recurring control failures, and publishing evidence-based operating recommendations.
  • Members of the Open Secure AI Alliance are developing open-source projects across various layers of the AI stack, including identity and permissions, harnesses, runtime guardrails, security AI models, observability, and evaluation.
  • The alliance is expanding its toolset with notable contributions from major companies like Okta, Palo Alto Networks, Red Hat, Amazon, Capital One, Cloudflare, Microsoft, Cisco, CrowdStrike, and others.
  • The initiative invites the public to join the Open Secure AI Alliance, fostering a culture of collaboration and innovation in AI cybersecurity.


  • The world of artificial intelligence (AI) has reached a critical juncture where the stakes are high, and the threats are real. As AI agents become increasingly pervasive in our daily lives, cybersecurity concerns have never been more pressing. In response to these emerging challenges, a coalition of AI leaders has come together to propose a new set of guidelines for agentic AI cybersecurity transparency, known as SAFE (Shared AI Findings Exchange). This comprehensive framework aims to strengthen agentic AI cybersecurity by transforming agentic cybersecurity incidents into better protection.

    The SAFE guidelines are being developed by an Open Secure AI Alliance working group, comprising over 120 organizations, including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat. These leading players in the AI industry have joined forces to create a unified standard for sharing threat intelligence openly, thereby enhancing collective defense and making it a force multiplier.

    The SAFE framework proposes three key components: confidentially collecting and analyzing AI incidents and near misses; informing those impacted by these events; identifying recurring control failures; and publishing evidence-based operating recommendations that reduce systemic risk. By adopting this approach, defenders can move at agent speed to respond rapidly to protect infrastructure and intellectual property from increasingly sophisticated cyber threats.

    The Open Secure AI Alliance has also made significant contributions to the development of open, inspectable tools across the full AI security stack. These efforts recognize that securing an AI agent is not just about vulnerability scanning but requires a holistic approach that encompasses identity controls, harnesses, guardrails, logs, and evaluation. Security experts acknowledge that the hardest problems in AI cybersecurity get solved when defenders learn from each other openly and at speed.

    In addition to the SAFE guidelines, NVIDIA has made substantial contributions to the development of open-source software and models for AI cybersecurity. The company's research harness, NOOA, makes agent behavior easier to test, trace, audit, and govern. NVIDIA's OpenShell runtime restricts what an agent can see, touch, and do, enforcing security and privacy controls at the agent level. Furthermore, NVIDIA has developed open model families, including Nemotron for agentic AI, Cosmos for physical AI, Isaac GR00T for robotics, BioNeMo for healthcare and life sciences, and Alpamayo, licensed for commercial use, which ship with open weights, datasets, and training techniques.

    NVIDIA's verified agent skills extend that trust to the capability layer. Each skill provides portable instruction sets cataloged, scanned for risks such as prompt injection and tools poisoning, cryptographically signed, and documented with a skill card. Defenders know exactly what an agent skill does, where it came from, and whether it was modified after publication.

    The Open Secure AI Alliance has also expanded its toolset across different layers of the stack. Members are developing open-source projects that span identity and permissions, harnesses, runtime guardrails, security AI models, observability, and evaluation, data security and privacy, availability, and resilience. The alliance's members are continually contributing to this expanding ecosystem, which is designed to foster collaboration, innovation, and knowledge-sharing.

    Notable contributions from Open Secure AI Alliance members include Okta's reference implementations for agent identity and access, using the Cross App Access protocol; Palo Alto Networks' open-source tools from Idira, including Agent Guard and Agent Watch; Red Hat's asago project, which maps organization custom governance requirements to what agents are allowed to do at runtime; Amazon's Strands Agents toolkit for building AI agents that is open at every layer; Capital One's VulnHunter for agentic AI code security; Cloudflare's Vulnerability Discovery Harness; and Microsoft's PyRIT - Python Risk Identification toolkit.

    Specialized security and safety models, such as Cisco's DefenseClaw, are purpose-built for defense. These models can work together with both open and closed models to get the job done efficiently. Other notable contributions include CrowdStrike's fine-tuned NVIDIA Nemotron Nano model; Mistral's Shieldstral multimodal safety classifier model; Akamai's State of the Internet reports and Security Intelligence Group research, which provide insights into AI-era threats; Cognition's trustworthiness evaluation, which measures alignment and security risks of open-source-derived models; Numbat's agent security suite for client endpoints; Uber's open-sourced ADR (Agentic AI Detection and Response) system; LangChain's resilience capabilities to its open-source frameworks; Veeam's technologies, including Kanister, for data protection on Kubernetes.

    The Open Secure AI Alliance invites members of the public to join this groundbreaking initiative. By sharing their expertise and resources, defenders across the ecosystem can inspect, adapt, and improve each other's contributions, fostering a culture of collaboration and innovation in AI cybersecurity.

    As the annual Black Hat conference begins in Las Vegas, these AI leaders are calling for greater transparency and cooperation in agentic AI cybersecurity. With SAFE guidelines and an expanding array of open-source tools, they aim to strengthen agentic AI cybersecurity, providing better protection against emerging threats and ushering in a new era of cybersecurity transparency.

    Related Information:
  • https://www.digitaleventhorizon.com/articles/A-New-Era-of-Cybersecurity-Transparency-The-SAFE-Guidelines-for-Agentic-AI-deh.shtml

  • https://blogs.nvidia.com/blog/open-secure-ai-alliance-contributions/


  • Published: Mon Aug 10 18:42:27 2026 by llama3.2 3B Q4_K_M











    © Digital Event Horizon . All rights reserved.

    Privacy | Terms of Use | Contact Us