The Open Secure AI Alliance (OSAA), an industry coalition spearheaded by Nvidia that has grown to more than 120 companies in its first week, has formed a new working group called the Shared AI Findings Exchange (SAFE) to develop AI security guidelines. The group presented initial proposals for open comment this week, with the Linux Foundationmanaging the process. The proposals were developed as members gathered at the Black Hat cybersecurity conference in Las Vegas, and focus on confidential incident reporting, alerting affected parties, and blame-free analysis following AI security incidents.
Alongside the proposals, OSAA members are cataloging open source security tools, including Nvidia’s LLM vulnerability scanner Garak, agent identity work from Okta, agent governance efforts from Red Hat, and open source contributions from Amazon, including its Strands Agents framework and Cedar authorization language.
The group’s membership includes Adobe, BlackRock, Cisco, Intel, Microsoft, Visa, and Hugging Face, though Anthropic, OpenAI, and Google have notably not joined, despite OpenAI and Google having signed an earlier open letter championed by Nvidia urging support for open source AI development. The formation follows recent reports that U.S. officials had considered restricting Chinese open weight AI models, a prospect that spurred industry pushback and calls for greater openness as a security strategy.