Open Secure AI Alliance moves to Linux Foundation as it proposes shared AI incident exchange
The NVIDIA-founded alliance will operate under Linux Foundation governance while developing open-source AI security tools, standards, and a proposed system for sharing incidents and near misses
The Open Secure AI Alliance has moved under Linux Foundation governance and is developing open-source tools and shared approaches for securing AI systems and agents
The Open Secure AI Alliance has moved under the Linux Foundation, shifting the NVIDIA-founded initiative to neutral open-source governance as it develops shared defenses for securing AI systems and agents.
The alliance is working on open-source models, tools, standards, and security practices that organizations can inspect and adapt across different vendors and platforms. Its scope extends beyond protecting individual AI models to the wider systems around them, including agent software, permissions, identity controls, monitoring, and recovery mechanisms.
Announcing the transition on LinkedIn, the Linux Foundation said the change was intended to support "a shared, open security stack for AI."
One of the alliance's first major proposals is the Shared AI Findings Exchange, or SAFE, an incident-learning initiative designed to collect information about AI failures and near misses and turn recurring problems into shared defensive controls.
SAFE is currently a Request for Comments, meaning its proposed structure and requirements are open for feedback rather than operating as a finalized system.
SAFE would require members to report AI security incidents
The proposed framework would cover incidents where an AI system accesses, exploits, disrupts, or changes a third-party system without authorization, escapes a sandbox or other technical boundary, accesses confidential third-party information without consent, or continues interacting with a production target after an operator knows or suspects the activity is unauthorized.
Importantly, the proposal says intent would not determine whether an incident must be reported. An AI system acting on an incorrect assumption that it was operating inside a simulation, for example, would not remove the reporting requirement.
The draft also sets out specific notification timelines. Affected organizations would be notified as soon as possible, while customers with credible exposure would be informed within 72 hours. Members would submit an initial confidential SAFE incident report within four business days.
Where warranted, a wider customer advisory would follow within 14 days. The proposal calls for a preliminary factual report within 30 days and a remediation update within 90 days, subject to security, legal, and investigative restrictions.
Near misses would also be reportable.
The alliance states: "Report honest mistakes and close calls early so the community can prevent the next incident."
Reviews would examine more than the AI model
The proposal reflects a broader view of AI security than model behavior alone. SAFE incident reviews would examine the model itself, its instructions and safeguards, the tools it could access, permissions and credentials, the surrounding technical environment, monitoring, human operating procedures, and dependencies on cloud, evaluation, data, or tooling providers.
Members would also be expected to retain evidence including prompts, model traces, tool calls, system logs, configurations, safeguard versions, approval events, files created or changed, and records of containment and recovery.
That approach matches the alliance's wider argument that AI agents should be treated as complete software systems.
"An AI agent is more than a language model," the alliance states. "It's a software system built from models, the harnesses that let it observe context and take action, and the guardrails that constrain what it can do."
The proposed SAFE structure would include model developers, organizations deploying AI, cloud and tool providers, independent security researchers, critical-infrastructure operators, civil society, and government and standards organizations acting as non-controlling observers.
It is also intended to apply to both open and closed AI systems. The proposal states: "Open systems are not automatically safe, and closed systems are not safe by declaration."
From individual failures to shared defenses
The alliance's objective is not simply to catalogue failures. Under the SAFE proposal, each incident review would be expected to generate defensive recommendations that other AI providers, deployers, evaluators, and customers could test and implement.
Those recommendations could include machine-readable policies, detection rules, reference configurations, security tests, and incident-response guidance where publication would not create additional risk.
For incidents involving unintended access to real systems, the proposal gives examples including default-deny network access, explicit lists of permitted targets, independent checks that an environment is properly isolated, real-time action monitoring, and automatic stops when the scope of an AI system's authority becomes uncertain.
The Open Secure AI Alliance is now open to industry, researchers, and government partners under the Linux Foundation. Organizations can contribute tools, models, and research, collaborate on standards, and participate in developing the SAFE proposal.