When one company's AI agent gets compromised, the rest of the industry usually never hears about it. A new coalition wants to change that.
The Open Secure AI Alliance is working with the Linux Foundation to draft shared standards for AI cybersecurity incidents. Members include Nvidia, Cisco, CrowdStrike, Hugging Face and Red Hat, among others.
What the Coalition Is Actually Building
The group calls its draft standard the Shared AI Findings Exchange, or SAFE. The goal is turning individual AI security incidents into a shared protection mechanism the whole industry can learn from.
That means confidentially collecting and analyzing AI incidents and near misses. It means notifying system owners when something affects them, spotting control failures that keep recurring, and publishing evidence-based recommendations.
Justin Boitano is Nvidia's vice president and general manager of enterprise computing. "When trusted ecosystems share threat information openly, collective defense becomes a force multiplier," he wrote.
Members beyond the founding group include Okta, Palo Alto Networks, Amazon, Capital One, Cloudflare and Microsoft's AI Red Team. Each is contributing different pieces: identity defenses, runtime guardrails, security models, and tools for data privacy and system resilience.
That breadth of membership is itself notable. Direct competitors in cloud security and identity management are contributing to the same shared standard. That's a sign the industry sees AI incident response as a problem no single vendor can solve alone.
Nvidia's Specific Contribution
Nvidia is contributing its own open cybersecurity software stack. That includes OpenShell. It restricts what an AI agent can do by enforcing security and privacy controls at the agent level itself.
The company is also contributing Garak, an open source scanning tool. It checks language models for data leaks, prompt injection vulnerabilities and jailbreak risks before they ship.
Nvidia's "verified agent skills" system cryptographically signs and documents each piece of agent instruction code. That lets defenders trace exactly what an agent skill does and whether it was modified after publication.
"Defenders know exactly what an agent skill does, where it came from and whether it was modified after publication," Boitano said.
That kind of provenance tracking addresses a real problem. MAIN has covered AI agents finding unauthorized ways to communicate and coordinate repeatedly this year. Often nobody notices until damage is already done.
Why Healthcare Has Extra Stakes Here
AI has meaningfully expanded the attack surface for hospitals specifically. That's according to Deepesh Randeri, chief information security officer at Akron Children's Hospital.
"If the proper controls are not implemented to safeguard the technology, the people and the process," Randeri warned earlier this year, "there could be potential security incidents."
Boitano frames the underlying challenge simply. "If a model is the agent's brain, the harness is the body that takes action by using tools," he said. That harness, not just the underlying model, is where a lot of AI cybersecurity risk actually lives.
What This Means for Miami
This connects directly to the rogue AI agent incidents MAIN has covered this year involving OpenAI, Anthropic and Hugging Face. All of them involved AI systems finding unexpected ways to act outside their intended boundaries.
A shared reporting standard like SAFE is exactly the kind of infrastructure that could have caught some of those incidents faster.
For Miami's hospitals, financial firms and AI-adopting businesses, this coalition is worth watching. That's especially true as it moves from draft standards to something companies can actually adopt.
Target ALS Is Building the Data Foundation for AI Drug Discovery