Skip to main content
Live
Main content

Nvidia's Open Secure AI Alliance ships SAFE proposals one week in

The 120-company group unveiled draft incident-sharing guidelines at Black Hat, with the Linux Foundation managing comments.

Jaeden Schafer
Editor in Chief · · 5 min read
Nvidia logo

The Open Secure AI Alliance, the Nvidia-led open AI industry group formed a week ago, has already grown to over 120 companies and shipped its first draft guidelines through a working group called the Shared AI Findings Exchange, or SAFE. Members hashed out the proposals in person at Black Hat in Las Vegas this week, and the Linux Foundation is now managing the open-comment process. For a coalition that did not exist eight days ago, that is an unusually fast cadence.

The SAFE drafts are deliberately modest for a first pass. They cover how member companies should confidentially report AI cybersecurity incidents, alert affected parties, and conduct blame-free post-mortems so the broader ecosystem can learn from them. The template is familiar from traditional infosec incident response — the news is that AI-specific incidents now get their own channel.

Alongside the guidelines, member companies are contributing open-source components that could eventually plug together into a shared defensive stack for enterprise AI. Nvidia has flagged its family of open models and Garak, its open-source LLM vulnerability scanner. Okta is working on agent identity. Red Hat is contributing agent governance work. Amazon has put forward Strands Agents, an open agent-building tool, and Cedar, an authorization language.

Key facts

  • 01The Open Secure AI Alliance has grown to over 120 companies one week after its formation.
  • 02Its Shared AI Findings Exchange (SAFE) working group published draft proposals at Black Hat in Las Vegas this week.
  • 03The Linux Foundation is managing the open-comment process for SAFE proposals.
  • 04The original open letter that spawned OSAA was signed by over 200 tech companies.
  • 05Anthropic, OpenAI, and Google are not members, though OpenAI and Google signed the original letter.

The member list now includes Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa alongside Nvidia and Hugging Face. The absences are as telling as the roster. Anthropic, OpenAI, and Google are not in. OpenAI and Google both signed the original open letter that spawned OSAA, and both ship open-weight models of their own, so their non-participation in the working group is a choice rather than an oversight.

The context matters. A couple of weeks ago, reporting surfaced that the Trump administration was weighing a ban on Chinese open-weight models. That prompted the open letter championed by Nvidia and signed by over 200 tech companies, urging the White House to support rather than restrict US open-source AI work. OSAA is the operational follow-through — an attempt to show regulators that the open ecosystem can self-govern on safety before Washington writes the rules for it.

The through-line from letter to alliance to draft guidelines in roughly two weeks is unusually crisp for an industry consortium. Most standards bodies spend that long picking a logo. Whether SAFE evolves into something enterprises actually deploy — an open reference architecture for securing AI agents, or for defending against rogue ones like the OpenAI-based model that infiltrated Hugging Face earlier — will depend on whether the initial contributions from Nvidia, Okta, Red Hat, and Amazon interoperate in practice.

Openness may be one of the most important paths to AI safety and security
Open Secure AI Alliance, Industry group letter

The competitive frame is also worth stating plainly. Arcee co-founder and CTO, representing one of the US open-weight labs in the ecosystem, has argued that openness is the strongest answer to any threat, real or imagined, from Chinese AI labs. That view — that the US should out-open rather than out-close its rivals — is now the operating thesis of a 120-company coalition rather than the position of a handful of open-source advocates.

The obvious caveats apply. First-draft guidelines with no enforcement teeth are just documents until members actually route real incidents through them. The Linux Foundation stewardship helps — it is a known quantity for managing open governance at scale — but nothing in the SAFE drafts obligates a member to disclose an embarrassing AI breach on any particular timeline. The absence of Anthropic, OpenAI, and Google also caps how comprehensive any shared-findings exchange can be, since those three sit on the largest deployed model surfaces.

Related · from this week
Nvidia, Microsoft, IBM launch Open Secure AI Alliance to defend agents
Jaeden Schafer · 5 min read →

For Nvidia, OSAA is a useful piece of positioning as Washington debates open-weight policy. Following its move to open-source cuFile and rally 40-plus storage vendors around AI infrastructure, which we covered earlier, this is the second industry coalition Nvidia has stood up in short order. The pattern is consistent: convene the ecosystem around an open standard, contribute the reference implementation, and let the rest of the stack settle around Nvidia's silicon. The security story is real, and it is also good business.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Nvidia logo
Security

Nvidia, Microsoft, IBM launch Open Secure AI Alliance to defend agents

Thirty-plus companies back an open-source coalition arguing that closed AI leaves cyber defenders blind at the moment of attack.

Jaeden Schafer5 min read
Nvidia logo
Security

Open Secure AI Alliance drafts SAFE guidelines for agentic AI incident sharing

The 120-member Linux Foundation group opened a Request for Comments on shared incident reporting as Black Hat kicks off in Las Vegas.

Jaeden Schafer5 min read
Hugging Face's Delangue: half the Fortune 500 now runs on open source AI
Business

Hugging Face's Delangue: half the Fortune 500 now runs on open source AI

The CEO argues frontier API costs push companies to open models as they scale, and warns a handful of firms could otherwise control everything.

Jaeden Schafer5 min read