The AI industry is securing the ecosystem through open collaboration.
NVIDIA and the Open Secure AI Alliance have drafted the Shared AI Findings Exchange (SAFE) framework and introduced several open-source tools to champion AI security. The SAFE RFC document proposes a framework for reporting, collaboratively analyzing and recommending operational guidance after breaches.
Additionally, the alliance members have also released open-source tools for vulnerability detection, governance and safe recovery from AI failures.
The alliance is calling developers, researchers and AI enterprises to share their security knowledge in an effort to shape the SAFE guidelines.
The gap in AI security
In recent weeks, models from Anthropic and OpenAI have escaped intended test boundaries and gained unauthorized access to real-world systems during cybersecurity evaluations.
In one incident, GPT-5.6 Sol and a more capable pre-release OpenAI model gained unauthorized access to Hugging Face’s production infrastructure and obtained test solutions from its production database. During the attack, the Hugging Face security team detected and stopped the incident with an open model before OpenAI’s security team also reached out.
Beside the security compromise, there’s one detail that’s worth emphasizing: Hugging Face used an open model to facilitate their remediation efforts (and not a closed frontier model).
Jensen Huang, CEO of NVIDIA had this to say: “During the Hugging Face incident, closed AI blocked essential forensics. An open-weight frontier model helped contain the intrusion. That’s why we created the Open Secure AI Alliance.” From his argument on the role of open tools, we can see how the need open collaboration on AI security developed.
NVIDIA, Microsoft and others rally to build open tools for AI
About a week after the Hugging Face incident, NVIDIA and founding partners announced the launch of Open Secure AI Alliance.
Now, the alliance has produced one of its first tangible results.
As part of the organizations spearheading open security efforts, NVIDIA has already shared a host of open tools including, topical guardrails for LLMs, an LLM vulnerability scanner and verified agent skills.
Other members like Amazon, Microsoft and Visa have also released open-source tools to support the AI security stack. Microsoft and Visa have built vulnerability agent harnesses, while Amazon has contributed a framework to build fully open agents.
These efforts by companies that seemingly competing corporate interests show a unified and committed stance toward agentic security.
How enterprises will benefit
The SAFE RFC has proposed methods for confidentially reporting AI security incidents, standardized remediation efforts and responsible vulnerability disclosure. The takeaway for enterprises is that they’ll have a structured incident management process from detection to disclosure, without having to create internal policy documents from scratch.
One of the key goals of this SAFE standard is to avoid duplicate efforts created when teams manage AI breaches in silos. With this proposed approach, learnings from previous breaches can be shared in a coordinated manner to avoid repetitions of the same efforts.
As more members join the Open Secure AI Alliance, we can expect more funding and tools toward agentic security. The greater question for enterprises remains whether they will adopt the recommended practices or if they will choose to independently develop their own processes.
Read more: As more employees deploy AI tools and automations outside traditional engineering teams, builder culture is creating new security and governance challenges.





