The open source community has shown time and again that collaboration produces better software, stronger security, and more resilient infrastructure. As AI becomes increasingly integrated into enterprise applications, developer workflows, and critical infrastructure, we have an opportunity to apply those same principles to one of the industry's newest challenges: learning from AI security incidents.
Today, participants in the Open Secure AI Alliance have published a Request for Comments (RFC) for the Shared AI Findings Exchange (SAFE) Working Group. The draft proposal is intended to start an open community discussion around how organizations can confidentially learn from AI security incidents and near misses, transforming those experiences into practical guidance that strengthens security across the broader AI ecosystem.
The initial RFC was developed as a draft proposal by contributors from Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat, and other members of the Open Secure AI Alliance. Beginning today, the proposal is open for community review, discussion, and contributions through the Open Secure AI Alliance RFC repository:
https://github.com/OpenSecureAIAlliance/RFCs
Cyberattacks will happen. AI systems will fail in unexpected ways. Safeguards and operating assumptions will sometimes break down.
Safety-critical industries have learned the value of mechanisms that enable information sharing and transparent learning. For example, NASA’s Aviation Safety Reporting System acts as a voluntary, confidential reporting system, designed to analyze and respond to flight accidents in a manner that allows the industry to learn and improve.
Today, organizations often investigate AI security incidents internally, with valuable operational knowledge remaining inside individual companies. There is no broadly adopted community framework for confidentially sharing AI operational failures, identifying recurring control failures, and translating those lessons into reusable defensive guidance across the ecosystem.
The SAFE proposal is intended to help the industry collaborate in moving that conversation forward.
It proposes a framework for confidentially collecting and analyzing AI incidents and near misses, notifying affected organizations, identifying recurring control failures, and developing evidence-based recommendations that help reduce systemic risk across the AI ecosystem. Rather than focusing on blame or enforcement, SAFE is designed to promote shared learning while respecting existing legal, contractual, and regulatory obligations.
Rather than publishing a finished specification, participants from the Open Secure AI Alliance begin with an open RFP so AI developers, enterprises, cloud providers, researchers, infrastructure operators, standards organizations, and the broader security community can collectively shape how SAFE should evolve.
The draft RFC proposes a framework built around several core principles:
Importantly, the proposal recommends that SAFE operate neutrally so that no single vendor or industry segment controls its findings. Its processes are intended to apply equally to both open and proprietary AI systems. As the proposal states, trust is not a security control. Shared evidence and verifiable improvements are how trust is earned.
The proposal also envisions that, where appropriate, SAFE could publish reusable tests, machine-readable policies, detection rules, reference configurations, and incident response guidance, creating a shared catalog of defensive recommendations that evolves alongside emerging AI threats.
Whether you're building AI models, deploying AI systems, operating cloud infrastructure, conducting security research, or developing governance and standards, your perspective can help shape how the community approaches AI incident learning.
We invite you to review the proposal, read more in NVIDIA's blog, join the discussion, open issues, submit pull requests, and help evolve SAFE into a practical framework that serves the broader AI ecosystem.
Read the draft RFC and participate in the discussion:
https://github.com/OpenSecureAIAlliance/RFCs
We look forward to building SAFE together.