Safety

Industry-led Open Secure AI Alliance launches SAFE working group to coordinate AI security practices

The Open Secure AI Alliance (OSAA), led by Nvidia and comprising over 120 companies, has formed the Shared AI Findings Exchange (SAFE) to develop guidelines and tooling for AI cybersecurity.

Industry-led Open Secure AI Alliance launches SAFE working group to coordinate AI security practices

The Open Secure AI Alliance (OSAA), an industry coalition formed about a week ago and led by Nvidia, has created a new working group named the Shared AI Findings Exchange (SAFE). The alliance already includes more than 120 companies and SAFE is intended to coordinate shared practices around AI cybersecurity.

What is happening now

SAFE has put forward proposals for public comment, and the Linux Foundation is managing those proposals. Members of OSAA developed the documents while meeting at the Black Hat conference in Las Vegas, which is taking place this week.

Focus of the proposals

The current guidelines are practical rather than radical. They address topics such as:

  • confidential reporting of AI-related cybersecurity incidents,
  • notifying affected parties after incidents,
  • and conducting blame-free post-incident analysis so organizations can learn from events.

These measures are designed to promote information sharing and collective learning without punitive blame that might deter disclosure.

Open-source contributions and technical pieces

OSAA members are also contributing and cataloging open-source technologies that could help secure enterprise AI agents or defend against malicious AI attacks. Examples mentioned by members include:

  • Nvidia: a family of open models and Garak, an open-source LLM vulnerability scanner;
  • Okta: work on agent identity technology;
  • Red Hat: work on agent governance;
  • Amazon: contributions of Strands Agents (an open agent-building tool) and Cedar (an authorization language).

The alliance also counts major firms such as Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa among its members.

Notable absences and context

Some prominent organizations are not yet part of OSAA: Anthropic, OpenAI, and Google. Notably, both OpenAI and Google signed the original open letter that helped spur this coalition; that letter was published last week and was signed by over 200 tech companies. The letter urged the White House to support, rather than suppress, open-source AI efforts.

According to reporting, Anthropic’s decision not to sign or join the group so far is not surprising; OpenAI and Google have nevertheless released their own open-weight models in the past. Whether they join OSAA as it gains momentum remains to be seen.

Why this matters

The alliance’s rapid organization comes amid broader political and industry debate: recent reporting indicated the Trump administration was considering banning Chinese open-weight models in the U.S., a prospect that prompted industry concern and helped catalyze the open letter. Regardless of how U.S. policy toward Chinese models ultimately develops, OSAA’s fast formation and SAFE’s early proposals appear likely to benefit the U.S. open AI ecosystem.

The industry letter argued that “openness may be one of the most important paths to AI safety and security.” With SAFE, OSAA members are beginning to put that principle into practice by drafting guidelines and sharing open-source tools.