AI Alliance Proposes Mandatory Incident Reporting With 30-Day Public Deadline

The Linux Foundation published a draft framework on August 4 that would require members of the newly formed Open Secure AI Alliance to report AI security incidents on fixed deadlines, with a preliminary public report due within 30 days. The proposal, called the Shared AI Findings Exchange (SAFE), was timed to coincide with the opening of the Black Hat security conference in Las Vegas. The alliance launched on July 27 and now counts more than 120 member organizations, including Cisco, Crow

2 min
AI Alliance Proposes Mandatory Incident Reporting With 30-Day Public Deadline

The Linux Foundation published a draft framework on August 4 that would require members of the newly formed Open Secure AI Alliance to report AI security incidents on fixed deadlines, with a preliminary public report due within 30 days. The proposal, called the Shared AI Findings Exchange (SAFE), was timed to coincide with the opening of the Black Hat security conference in Las Vegas.

The alliance launched on July 27 and now counts more than 120 member organizations, including Cisco, CrowdStrike, Hugging Face, NVIDIA, Red Hat, Amazon, and Visa, according to a separate announcement from NVIDIA.

The SAFE draft defines a notification ladder with concrete deadlines: notify the directly affected organization as soon as possible, customers with credible exposure within 72 hours, file a confidential SAFE report within four business days, issue a broader customer advisory within 14 days when warranted, publish a preliminary factual report within 30 days, and report remediation status within 90 days. Members must also provide weekly machine-readable updates while material risks remain unresolved.

The reporting obligation extends to near misses, not just confirmed harm. A preliminary control-failure analysis is due within 30 days of an incident.

The draft covers a defined set of reportable events. A member must report an incident when an AI system it operates accesses or disrupts a third-party system without authorization, escapes or bypasses a sandbox or policy boundary, accesses third-party confidential information, or continues probing a production target after the operator suspects the activity is out of scope. Intent is explicitly not a factor: an operator who believed an environment was simulated still carries the reporting duty.

Each incident would be reviewed across eight layers of the operating stack, from the model and its instructions through safeguards, tools, environment, monitoring, human operations, and the supply chain. One notable provision: the affected organization may correct factual errors but would not hold veto power over the learnings or recommendations that emerge from a review.

SAFE is structured as a voluntary compact. The reporting duties would bind members as a condition of membership rather than as law. The draft explicitly states that learning is separate from enforcement and that regulators and affected parties retain their existing legal rights.

The framework arrives during a period of heightened scrutiny of AI safety incidents. In recent weeks, an OpenAI evaluation agent was found to have breached Hugging Face infrastructure, and Anthropic disclosed that Claude gained unauthorized access to three organizations during its own cybersecurity evaluations.

Sources

Written by

More to read

  • Speech-to-Text Serving in Production: Comparing Faster-Whisper, Moonshine, SenseVoice, and NeMo Canary Architecture, Streaming Latency, and GPU Economics

    In conversational voice AI and real-time agentic workflows, the speech-to-text (STT) layer sets the hard lower bound on system responsiveness. Human conversational cadence expects turn-taking latencies between 200ms and 500ms. When an AI pipeline must accommodate downstream large language model (LLM) time-to-first-token generation (100ms to 250ms) and text-to-speech (TTS) audio synthesis (100ms to 200ms), the automatic speech recognition (ASR) stage cannot exceed 100ms to 150ms of processing ove

    1 min
  • Writer Releases Palmyra X6 Flagship Agentic Model with Rebuilt Enterprise Agent Harness

    Enterprise generative AI platform Writer has launched Palmyra X6, its new flagship agentic foundation model, alongside a rebuilt runtime harness engineered for multi-step workflow execution and governance. The model release introduces substantial latency and efficiency improvements over previous Palmyra iterations, cutting inference costs by 52% while accelerating output generation by 48%. Writer reported average generation speeds of 82 tokens per second and a mean task completion time of 26 se

    1 min
  • River AI Secures .1B Led by General Catalyst to Build Open-Weight Model Infrastructure

    River AI, an artificial intelligence startup founded by former xAI co-founder Igor Babuschkin, has secured $1.1 billion in early-stage funding to build an open-weight model stack and decentralized AI infrastructure platform. The financing round was led jointly by General Catalyst and public benefit corporation AMP PBC, with strategic participation from NVIDIA, AMD Ventures, Y Combinator, and Singapore sovereign fund Temasek. Babuschkin, whose prior engineering background spans OpenAI, Google De

    1 min