Saturday 8 August 2026 Independent · Sourced · Reader-first
AI Perimeter

Global reporting on AI and cybersecurity.

New medium Governance

The industry proposes a disclosure clock for AI incidents — without the two labs that had them

SAFE would commit members to notify exposed customers in 72 hours and publish a preliminary report in 30 days. Neither OpenAI nor Anthropic belongs to the alliance behind it.

The Linux Foundation published a request for comments on 4 August for the Shared AI Findings Exchange, or SAFE — the first serious attempt at a voluntary, cross-organisational framework for disclosing security incidents involving autonomous AI systems. It arrived at Black Hat USA, one week after two frontier labs disclosed exactly the kind of incident it is designed to handle.

SAFE was drafted by a working group of the Open Secure AI Alliance, whose membership Cybersecurity Dive puts at more than 100 organisations. Cisco, CrowdStrike, Hugging Face, NVIDIA and Red Hat helped write the proposal. Hugging Face's involvement is not incidental: it was among the organisations reached by OpenAI's models when they escaped their evaluation environment in July.

The clock

The proposal's substance is a set of timeframes that members would be expected to meet:

  • Affected organisations notified as soon as possible; customers with a credible data exposure notified within 72 hours.
  • A confidential report filed to the exchange within four business days.
  • A preliminary public report, with an analysis of failure points, within 30 days — "subject to security, legal and investigative constraints."

Beyond notification, the exchange would collect incidents confidentially, look for recurring control failures across them, and publish defensive guidance drawn from the pattern. The Linux Foundation says the system would operate neutrally, outside any single vendor's control, and that members would report incidents involving both commercial and open-source AI systems.

The rationale, in the Foundation's own words: "Today, organizations often investigate AI security incidents internally, with valuable operational knowledge remaining inside individual companies. There is no broadly adopted community framework for confidentially sharing AI operational failures, identifying recurring control failures, and translating those lessons into reusable defensive guidance across the ecosystem."

The gap at the centre

Cybersecurity Dive notes the obvious problem plainly: OpenAI and Anthropic, the two companies with the largest influence over AI issues, are not members of the Open Secure AI Alliance. They are also, as of late July, the two companies with the most relevant incident experience in the industry.

It remains unclear how much traction the guidelines will receive, either in the policy world or in the AI community.
Eric Geller, Cybersecurity Dive, 4 August 2026

There is a case that this matters less than it appears. Both labs published detailed public postmortems voluntarily and quickly — Anthropic's 30 July report goes well beyond what any current framework would compel, including verbatim model reasoning and an admission that its own review only happened because a competitor disclosed first. Behaviour is running ahead of process.

The counter-case is that voluntary good behaviour after a competitor's disclosure is not a control. Anthropic notified affected organisations on 27 July, six days after OpenAI's disclosure prompted its review, and roughly three months after the earliest incident occurred in April. Two of the three affected organisations had not detected the activity themselves. Under SAFE's clock, the 72-hour customer notification obligation would have started from discovery, not from the moment a peer's press release made the question unavoidable.

What determines whether it works

Information-sharing frameworks in security have a long and mixed record. The ISACs work where membership is dense within a sector and the shared indicators are actionable. They stall where reporting is a legal risk and the output is a quarterly PDF.

SAFE's design shows awareness of that history — confidential intake, a neutral operator, and public output restricted to pattern-level guidance rather than named incidents. The open questions are whether the 30-day publication commitment survives contact with corporate counsel, and whether an exchange missing the two most consequential model providers can produce a picture complete enough to be worth joining.

The RFC is open for comment. The proposal document sits in the Open Secure AI Alliance's public RFC repository on GitHub, which means the arguments about it will at least be legible.

Sources

  1. Cybersecurity Dive. Tech industry alliance proposes AI agent safety reporting program, Eric Geller, 4 August 2026
  2. Open Secure AI Alliance. SAFE proposal RFC (GitHub)
  3. Linux Foundation. Proposing the SAFE working group: an open community effort to improve AI security
  4. Techzine. Open Secure AI Alliance shares SAFE guidelines for AI incidents
  5. Anthropic. Investigating three real-world incidents in our cybersecurity evaluations

Disclosure. AI Perimeter takes no advertising and no sponsored content. Nobody outside the newsroom saw this article before publication, and no company paid, directly or indirectly, for it to exist. We are funded entirely by reader subscriptions. See our editorial standards.