What happened
On August 4, 2026 (coinciding with Black Hat USA 2026), the Linux Foundation published a Request for Comments proposing the Shared AI Findings Exchange (SAFE) Working Group, drafted by contributors from Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat and other members of the >120-organization Open Secure AI Alliance. The draft RFC proposes a voluntary, confidential framework — modeled on NASA's Aviation Safety Reporting System and financial-sector ISACs — for organizations to report AI security incidents and near-misses, receive timely notification when affected, and receive evidence-based operational guidance, without triggering enforcement. It defines a notification ladder (affected orgs 'as soon as possible', exposed customers within 72 hours, confidential initial report within 4 business days, preliminary public report within 30 days). The RFC is open for public comment on GitHub (OpenSecureAIAlliance/RFCs); no implementation timeline or submission mechanism exists yet.
Why it matters
This is the first proposed industry-wide incident-sharing mechanism specifically for autonomous/agentic AI security incidents, filling a structural gap exposed by recent cross-organizational AI agent incidents (e.g., the Hugging Face/Modal Labs sandbox-escape events and the Anthropic/OpenAI cyber-evaluation incidents). If adopted, participation in confidential AI incident sharing becomes a maturity marker for AI security programs, similar to ISAC participation in traditional cybersecurity.
Action needed
Review and comment on the draft RFC via the OpenSecureAIAlliance GitHub repository; assess internal AI-incident-response processes against the proposed notification ladder; monitor for governance/participation model finalization.