SAFE defines a confidential reporting pipeline: an organization that detects an incident or near-miss in an agentic system reports the findings in a standardized format. Reports are analyzed for patterns and root causes (which controls failed), and recommendations and warnings for the ecosystem are published on that basis. The framework proposes public notification deadlines: affected organizations as soon as possible, and customers within a defined window (a proposed 72 hours) based on credible evidence, while keeping the source data confidential.
Findings about agentic-AI security incidents (e.g. successful jailbreaks, prompt injection, tool misuse) are today fragmented and rarely shared between organizations, so the same weaknesses are exploited repeatedly. There is no common, confidential exchange channel or shared vocabulary for describing incidents.
A standardized, confidential way to submit findings about incidents and near-misses.
Identifying recurring patterns and the control mechanisms that failed.
Publishing evidence-based recommendations and advisories for the ecosystem.
Public deadlines for notifying affected organizations and customers (a proposed 72 hours for customers).
Official
The value of shared knowledge grows with the number of reporters; low adoption limits usefulness.
Disclosing too fast can harm affected organizations; too slowly harms the rest of the ecosystem.
The Open Secure AI Alliance (hosted by the Linux Foundation) announced the SAFE draft as a Request for Comments at Black Hat USA in early August 2026; alliance membership topped 120 organizations.