Fetching from the wire…
Public story · 2026-08-05 · high
A 120+ member alliance including NVIDIA, Cisco and CrowdStrike wants agentic AI failures reported confidentially, timed to Black Hat.
Why now: Linux Foundation published the SAFE RFC August 4, opening public comment as members roll out matching security tooling around Black Hat.
The Linux Foundation opened public comment August 4 on SAFE, a confidential incident-reporting system for agentic AI, per an Open Secure AI Alliance RFC.
The RFC comes from a working group spanning more than 120 organizations, including NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat. That gives security teams at any of those companies a channel to learn from each other's agent failures instead of just their own.
SAFE would collect agentic AI incidents confidentially and notify the parties affected. It would also flag recurring control failures across submissions and publish recommendations based on the pattern, not any single company's story. The RFC doesn't mention a public breach-disclosure requirement, just the aggregated recommendations on the other side.
SAFE lands at Black Hat alongside a batch of open-source security tooling: NVIDIA's NOOA harness and Garak scanner, Microsoft's PyRIT, and Cisco's DefenseClaw. Tools for finding agent failures and a system for reporting them, released together.
Confidentiality is why any of these 120-plus companies might report a failure instead of burying it. It's also why no one outside the alliance can check if the fixes work. The recommendations might trace back to real incidents, or just the ones members felt comfortable admitting to. Watch whether SAFE publishes incident counts, even anonymized ones, once the comment period closes.
Each link below shares sources, entities, or timing with this story.
Announced July 27 with Microsoft, IBM, Red Hat, Palantir, CrowdStrike, Cloudflare, Databricks, Hugging Face, LangChain, Nous Research, Reflection AI, Thinking Machines Lab, SpaceXAI and the Linux Foundation. Huang's framing is pointed: during the Hugging Face incident "closed...
Huang used his inaugural X post on July 24 to publish "Open Weights and American AI Leadership," a three-page letter on Nvidia's own servers signed by 25 companies including Meta, Microsoft, IBM, Mistral, Mozilla, Hugging Face, a16z, Palantir and the Linux Foundation. Within a...
Founding signatories include AWS, Anthropic, Google, OpenAI, NVIDIA, Microsoft and GitHub, IBM, Red Hat, Cisco, JPMorganChase, Citi, the Rust Foundation, Zscaler, and Sonatype, with OpenSSF, CNCF, and OpenInfra participating. The open letter drew 455 points on HN. (Akrites / L...
This is a supply-chain fact, and most people are still treating it as a geopolitics argument. Sequoia published "America's Open-Model Paradox" on July 24 with the number that reframes the whole conversation: Qwen's share of open-model fine-tunes went from 1% in January 2024 to...
Signatories on August 27 include OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, Fortinet, Capital One, Mastercard, Visa, Adobe, Oracle and IBM, saying there's "a limited window" to build unified defenses and naming hospitals, water treatment plants and internet infra...
If you wrote an MCP server before July, it's on a protocol shape the maintainers have already removed. Not deprecated-with-a-migration-window. Removed from the spec. MCP lead maintainers David Soria Parra and Den Delimarsky published an updated roadmap on August 22, and the re...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.