The Open Secure AI Alliance, now comprising over 120 organizations, is releasing draft SAFE guidelines and showcasing co
Members of the Open Secure AI Alliance, which has grown to more than 120 organizations, are developing new guidelines to strengthen agentic AI cybersecurity as the annual Black Hat conference begins in Las Vegas today. The Linux Foundation has shared a Request for Comments on the Shared AI Findings Exchange, or SAFE, a proposed set of guidelines designed to turn agentic cybersecurity incidents into shared protection for the entire ecosystem. These guidelines are being drafted by an Alliance working group, with NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat collaborating with the Linux Foundation on the initial proposal. The SAFE framework proposes the confidential collection and analysis of AI incidents and near misses, notification of affected parties, identification of recurring control failures, and publication of evidence-based operating recommendations to reduce systemic risk. As the announcement states, Cybersecurity is a race without a finish line, and every major technology shift creates new attack surfaces. Defenders must move at agent speed to protect infrastructure and intellectual property, and the best approach is collective defense through open threat intelligence sharing.
The SAFE framework complements broader efforts by Alliance members to build and share open, inspectable tools across the full AI security stack. The post emphasizes that an AI agent is not merely a model but a complete system encompassing identity controls, harnesses, guardrails, logs, and evaluation, meaning security requires more than basic vulnerability scanning. Historical experience shows that security is strongest when communities openly share knowledge at speed. NVIDIA is contributing across the entire stack, beginning with the NVIDIA Labs Object-Oriented Agent, or NOOA, research harness on GitHub, which simplifies testing, tracing, auditing, and governing agent behavior. Its OpenShell runtime restricts agent visibility and actions to enforce security and privacy controls at the agent level. NVIDIA also ships open weights, datasets, and training techniques for its open model families, including Nemotron for agentic AI, Cosmos for physical AI, Isaac GR00T for robotics, BioNeMo for healthcare and life sciences, and Alpamayo, noted as the world’s largest model for autonomous vehicles licensed for commercial use. To extend trust to the capability layer, NVIDIA offers open source verified agent skills that provide portable instruction sets, cataloged and scanned for risks like prompt injection and tool poisoning, cryptographically signed, and documented with skill cards. Additional NVIDIA tools include NeMo Guardrails, NeMo Anonymizer, and NeMo Safe Synthesizer for enforcing safety policies and protecting sensitive data, alongside Garak, an open source LLM vulnerability scanner for checking models before deployment.
Other Alliance members are similarly advancing defensive capabilities across multiple layers. Okta is developing reference implementations for agent identity and access, demonstrating how Cross App Access, an open protocol, enables AI agents in OpenShell sandbox environments to securely connect to enterprise applications. Palo Alto Networks has contributed open source tools from its Idira identity security platform, specifically Agent Guard and Agent Watch, to help developers apply identity security best practices and safely retrieve secrets. Red Hat founded asago, an open source project that maps organizational governance requirements referenced in NIST, OWASP, and the EU AI Act directly to runtime agent permissions, maintaining a single audit trail from policy clause to live control. Recognizing that harnesses act as orchestrators determining how agents are deployed and constrained, several companies are contributing tooling to this emerging layer. Amazon, recently joining the Alliance, contributes Strands Agents, an open source toolkit providing full visibility into agent behavior and production evaluation capabilities, along with Cedar, an open source authorization language that enforces deterministic, verifiable boundaries for agent permissions. Capital One open sourced VulnHunter for agentic AI code security, while Cloudflare offers its Vulnerability Discovery Harness as an open source skill. Microsoft AI Red Team has released PyRIT for automated red teaming, RAMPART to convert findings into repeatable tests, Clarity to challenge design assumptions, and Assert to translate natural language requirements into executable evaluations. Wiz contributed Atlas, an autonomous vulnerability research engine using specialized AI agents to discover flaws, and Visa joined the Alliance with its open sourced Visa Vulnerability Agentic Harness for issue identification and remediation support.
Finally, the post highlights that specialized security and safety models are purpose-built for defense, trained to understand code, locate vulnerabilities, and reason about threats at scale. Cisco introduced DefenseClaw, an open source agentic governance layer built on NVIDIA OpenShell for automated runtime security, alongside two Antares security small language models to pinpoint known codebase vulnerabilities and Project CodeGuard to embed secure-by-default practices into AI coding workflows. CrowdStrike is fine-tuning the NVIDIA Nemotron Nano model for cyber defense, reporting internal testing that achieved 96 percent accuracy in generating investigation queries within Falcon LogScale to boost investigative efficiency, and has published research demonstrating how a specialized NVIDIA model enhances these capabilities. As the organization notes, You can’t secure what you can’t identify, underscoring the necessity of transparent, layered, and community-driven defenses as the industry continues to expand its open-source contributions across the AI security stack.