NVIDIA and the Open Secure AI Alliance have proposed a new industry framework called Shared AI Findings Exchange (SAFE) to standardize how organizations report and share AI-related cybersecurity incidents.
Published through the Linux Foundation as a Request for Comments, the guidelines are intended to help organizations share information on AI attacks, vulnerabilities and near misses to improve collective cyber defenses.
The alliance also announced new open-source contributions, including AI security models, datasets, evaluation tools and research designed to improve the security of AI systems and agents.
NVIDIA said the Open Secure AI Alliance has grown to more than 120 member organizations, including technology companies, cybersecurity firms and open-source foundations collaborating to develop shared AI security tools and best practices.
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs had this to say:
“SAFE is required because AI agent failures don’t fit existing vulnerability disclosure. When a model finds and uses access it shouldn’t have reached, there’s no patch to issue and no vulnerability identifier to publish. Agent failures are often behavioral and non-deterministic, with no signature to match and no fix to deploy.
“Aviation’s safety reporting system has been running since 1976, the financial sector’s threat-sharing body since 1999. Both protect reporters from liability and operate at industry speed. AI threats outpace government coordination, making private-sector self-organization the right model.
“Identity is the piece that makes the rest of the defensive stack enforceable. The alliance’s work on agent identity and access controls lets organizations verify what an agent is before it acts. SAFE adds information sharing on top of that identity and runtime layer. Together, organizations learn from each other’s agent failures fast enough to defend proactively.
“The highest value will come from near-misses. Breaches make headlines, but an agent that probes a boundary and fails never gets published. That behavioral pattern is exactly the intelligence other organizations running similar systems need, and SAFE creates the channel for sharing what would otherwise stay invisible.”
Jeremiah Fowler, Researcher for Black Hills Information Security, Inc. follows with this:
“I believe this is a positive step in the right direction. Organizations that experience AI related attacks gain valuable insights that could help protect others but only if that information is shared. Establishing a framework for responsible information sharing promotes transparency, peer review, and independently evaluated security findings. The more organizations that contribute real-world evidence, the more effectively we can identify emerging attack patterns, common vulnerabilities, and evolving threats while reducing duplicated defensive efforts that waste valuable time and resources.
“As AI becomes increasingly integrated into everyday life, business operations, and critical infrastructure, developing standardized security guidance now is a proactive investment rather than waiting to retrofit a defense after incidents occur. Sharing information about unsuccessful attacks is just as valuable as documenting confirmed compromises, because near misses can often expose weaknesses, configuration issues, or emerging attack tactics before they evolve into critical security incidents. I used to always say “it is not if you will have a data incident, it is when you will have a data incident”. AI has supercharged the threat landscape in ways we couldn’t have imagined just a few years ago. Reporting and sharing AI related cybersecurity incidents is a great first step. I am happy to see organizations take the initiative instead of waiting around for regulators or lawmakers.”
Standards are good. But I will have to see this in action to get an idea of how well this works. Because there’s nothing worse than a standard that nobody uses.
NVIDIA Acquires Hugging Face
Posted in Commentary with tags NVIDIA on September 3, 2026 by itnerdNVIDIA is acquiring Hugging Face. Here are the details:
Over the past decade, Clem, Julien, Thomas and the team at Hugging Face have built something remarkable: a vibrant home for the open model developer community.
More than 18 million developers, researchers and creators use Hugging Face to share more than 3 million models, 500,000 datasets and 1 million applications. More than 200,000 companies use the platform to discover, evaluate, customize and deploy AI.
Hugging Face will remain an open platform for the entire AI ecosystem. Developers will choose the models they want, the frameworks they want, the clouds and inference service providers they want and the computing platforms they want. NVIDIA compute will not be required to build on or deploy through Hugging Face.
Hugging Face will continue to support open source and open weight models from across the ecosystem, from every model builder. It will continue to support multi-cloud and multi-accelerator development and deployment, so builders can use the hardware and infrastructure that best fit their work.
Ryan McCurdy, VP, Liquibase:
“NVIDIA’s acquisition of Hugging Face is another sign that the value in AI is moving beyond the models themselves. Models are becoming more available, developers are creating software faster than ever, and AI agents are starting to take action across enterprise systems.
“For enterprises, that creates a new challenge. AI doesn’t just accelerate how quickly change can be created. It increases the volume and speed of changes that can reach critical systems. A bad database change can take an application offline, expose sensitive data, or create an audit and compliance issue.
“That makes the control layer more important. The question isn’t just what AI can create. It’s what AI should be allowed to change, what can reach production, and whether those decisions can be governed and audited. As AI becomes more autonomous, enterprises will need those controls built into the path to production rather than relying on humans to catch problems after the fact.”
AI clearly has value. So based on that I fully expect that this will not be the last purchase that NVIDIA makes.
Leave a comment »