Skip to main content
Models & Technology

NVIDIA, Cisco and 120 Other Organizations Propose AI Agent Incident-Tracking Mechanism

The Open Secure AI Alliance is developing guidelines for what it calls the “Shared AI Findings Exchange” (SAFE), a proposed framework for reporting cybersecurity incidents involving AI agents.

NVIDIA, Cisco and 120 Other Organizations Propose AI Agent Incident-Tracking Mechanism

According to Axios, a coalition of more than 120 organizations, including NVIDIA, Cisco, and CrowdStrike, is proposing a new incident-reporting framework for AI agents. The framework would require participating companies to disclose certain agent incidents and maintain detailed incident records.

As AI agents gain greater autonomy in computer systems, the industry lacks a standard way to report security failures and learn from them.

The Open Secure AI Alliance is developing guidelines for what it calls the “Shared AI Findings Exchange” (SAFE), a proposed framework for reporting cybersecurity incidents involving AI agents.

The draft calls on model deployers, AI developers, cloud and tool providers, independent researchers, critical infrastructure operators, and other groups to participate. Government agencies will also be invited to join as “non-controlling observers.”

SAFE members would agree to report incidents in which AI systems gain unauthorized access to or exploit third-party systems, disclose confidential information, or continue probing production targets after operators suspect the activity is unauthorized.

Members would also report certain near misses and preserve incident evidence, including prompts, agent traces, tool calls, identities, permissions, and credentials.

Under the proposed timeline, members should notify affected organizations as soon as possible after an incident, submit an initial confidential report to SAFE within four business days, publish an initial factual report within 30 days when appropriate, and provide a remediation update within 90 days.

SAFE would analyze incidents, identify recurring failures, and propose shared security control recommendations.

Justin Boitano, NVIDIA’s vice president and general manager of enterprise computing, told Axios at the Black Hat conference that the plan is modeled on NASA’s Aviation Safety Reporting System, which can use data captured by aircraft flight recorders to investigate accidents.

The coalition believes that the existing culture of sharing threat intelligence in cybersecurity will encourage companies to participate anyway. “There’s been almost no resistance. We’re seeing people willing to participate; they’re eager to share,” said Julien Soriano, NVIDIA’s deputy chief information security officer and vice president.

The Open Secure AI Alliance is seeking community feedback on the proposal through a request-for-comments process hosted by the Linux Foundation.

NVIDIA, Cisco and 120 Other Organizations Propose AI Agent Incident-Tracking Mechanism