Open Secure AI Alliance Releases Draft Guidelines for Agentic AI Security
More than 120 organizations are collaborating on shared vulnerability reporting and open-source defensive tools as AI agents enter production.

Alliance proposes shared vulnerability framework
The Open Secure AI Alliance, which has grown to more than 120 member organizations, is developing new guidelines designed to strengthen cybersecurity for agentic AI systems. The Linux Foundation released a Request for Comments on the Shared AI Findings Exchange (SAFE), a proposed framework for confidentially collecting and analyzing AI security incidents across the ecosystem.
According to details first reported by NVIDIA, the SAFE guidelines would enable organizations to report AI incidents and near-misses, notify affected parties, identify recurring control failures, and publish evidence-based recommendations to reduce systemic risk. The working group drafting the proposal includes NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat.
The announcement coincides with the Black Hat security conference in Las Vegas, where alliance members are showcasing a growing collection of open-source security tools spanning the full AI stack.
Why it matters
As AI agents move from research labs into production environments—where they can execute code, access enterprise systems, and make autonomous decisions—the attack surface expands dramatically. Unlike traditional software vulnerabilities, agentic AI introduces risks around prompt injection, tool poisoning, and unpredictable behavior at runtime. A shared vulnerability reporting framework could accelerate collective defense, but only if organizations overcome competitive instincts and contribute incident data openly.
Members contribute defensive tools across the stack
Alliance members are releasing open-source tools that address different layers of agentic AI security:
Identity and access control: Okta is developing reference implementations for agent identity using the Cross App Access protocol. Palo Alto Networks contributed Agent Guard and Agent Watch from its Idira platform. Red Hat founded asago, an open-source project that maps governance requirements from frameworks like NIST and the EU AI Act directly to runtime agent permissions.
Agent harnesses and orchestration: Amazon, a new alliance member, contributes Strands Agents for building inspectable AI agents and Cedar, an authorization language that enforces deterministic boundaries on agent actions. Microsoft's AI Red Team released PyRIT for automated red teaming, RAMPART for converting incidents into repeatable tests, and Assert for turning natural language requirements into executable evaluations. Wiz contributed Atlas, an autonomous vulnerability research engine.
Specialized security models: Cisco released DefenseClaw, an agentic governance layer, plus two Antares security models for vulnerability detection. CrowdStrike is fine-tuning NVIDIA's Nemotron Nano model for cyber defense, achieving 96% accuracy in generating investigation queries. Cognition released a trustworthiness evaluation for measuring alignment and security risks in open-source models.
Observability and response: Perplexity open-sourced Numbat, an agent security suite that detects and investigates agent activity across operating systems. Uber contributed components of ADR (Agentic AI Detection and Response), which reconstructs the full causal chain of agent activity and currently supports more than 200,000 agent sessions daily across 30,000 endpoints.
Resilience: LangChain is adding resilience capabilities to its frameworks, enabling agents to retry interrupted work and resume from saved states. Veeam contributes Kanister, a framework for data protection on Kubernetes.
NVIDIA's own contributions include the Object-Oriented Agent research harness, OpenShell runtime for enforcing agent-level controls, open model families with published weights and datasets, verified agent skills with cryptographic signing, and Garak, an LLM vulnerability scanner.
These details were first reported by NVIDIA in a blog post announcing the alliance's activities at Black Hat.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call