# AI Alliance Drafts Confidential Incident Reporting Rules With Public Deadlines

> Source: <https://www.unite.ai/ai-alliance-drafts-confidential-incident-reporting-rules-with-public-deadlines/>
> Published: 2026-08-04 14:06:02+00:00

###
[
Cybersecurity
](https://www.unite.ai/series/cybersecurity/)

# AI Alliance Drafts Confidential Incident Reporting Rules With Public Deadlines

[Add Unite.AI to your preferred sources on Google](https://www.google.com/preferences/source?q=unite.ai)

The [Linux Foundation](https://www.linuxfoundation.org/blog/proposing-the-safe-working-group-an-open-community-effort-to-improve-ai-security) on August 4, 2026, published a Request for Comments for the Shared AI Findings Exchange (SAFE), a draft framework that would bind members of the Open Secure AI Alliance to report AI security incidents on fixed deadlines — confidentially at first, then publicly within 30 days. Contributors from Cisco, CrowdStrike ([CRWD](#) ), Hugging Face, NVIDIA ([NVDA](#) ), Red Hat and other alliance members drafted the initial proposal, timed to the opening of the Black Hat conference in Las Vegas.

The [draft SAFE proposal](https://github.com/OpenSecureAIAlliance/RFCs) describes a confidential incident-learning system: members report AI security incidents and near misses, affected organizations get notified, recurring control failures get identified, and the results become published, evidence-based operating recommendations. The alliance, launched on July 27, 2026, now counts more than 120 member organizations, [NVIDIA said in its own announcement](https://blogs.nvidia.com/blog/open-secure-ai-alliance-contributions/), with Amazon ([AMZN](#) ) and Visa among the newest to join.

## What the draft actually commits members to

The SAFE draft goes further in two specific places: a defined set of reportable events, and a notification schedule with dates attached.

Under the draft’s reporting compact, a member would have to report an incident when an AI system it operates accesses or disrupts a third-party system without authorization, escapes or bypasses a sandbox, network, identity, policy or tool boundary in a way that affects a third party, accesses third-party confidential information, or keeps probing a production target after the operator suspects the activity is out of scope. The draft adds that intent does not determine whether an event is reportable — an operator that believed an environment was simulated still carries the duty to report.

The notification ladder is where the deadlines live: notify the directly affected organization as soon as possible, customers with credible exposure within 72 hours, a confidential initial SAFE report within four business days, a broader customer advisory within 14 days when warranted, a preliminary factual report published within 30 days, remediation status published within 90 days, and machine-readable updates weekly while material risks remain unresolved. Members would also owe a preliminary control-failure analysis within 30 days — and would have to report near misses, not just confirmed harm.

Each incident would be reviewed across eight layers of the operating stack, from the model and its instructions through safeguards, tools, environment, monitoring, human operations and supply chain. One provision worth noting: the affected organization may correct factual errors, but the draft says it should not hold veto power over the learnings or recommendations that come out of a review.

## Voluntary membership, binding terms, no enforcement arm

SAFE is structured as a voluntary compact — the reporting duties would bind members as a condition of membership, not as law. The draft states that learning is separate from enforcement, that regulators and affected parties retain their legal rights, and that the timelines do not replace existing notification obligations under coordinated vulnerability disclosure practice, contracts, or legal duties to regulators and law enforcement. Intentional or criminal conduct would sit outside the confidential channel’s protection.

The draft also proposes that SAFE operate independently, so that no single vendor or industry segment controls its findings, with government and standards bodies participating as non-controlling observers. The proposal’s own framing is blunt on the point: “Trust is not a security control. Shared evidence and verifiable improvements are how trust is earned.” Whether that independence holds once real incidents name real members is the question the comment period exists to answer — but the draft at least puts the obligation in writing before the first test arrives.

## The incident that made the case

The alliance formed eight days ago, on July 27, 2026, as a coalition of roughly three dozen companies and open source foundations, explicitly citing the [July 16, 2026, Hugging Face security disclosure](https://huggingface.co/blog/security-incident-july-2026) as the trigger. Hugging Face reported that an autonomous agent framework had run an intrusion into its production infrastructure end to end, and that when the company tried to analyze more than 17,000 recorded attacker actions, commercial API models blocked the forensic work — their guardrails could not distinguish an incident responder from an attacker. The team completed the analysis on the open-weight GLM-5.2 model running on its own infrastructure. Unite.AI covered [the alliance’s launch](https://www.unite.ai/nvidia-launches-open-secure-ai-alliance-to-arm-cyber-defenders/) and [Hugging Face’s forensic account](https://www.unite.ai/hugging-face-traces-the-rogue-agent-to-a-hijacked-sandbox/) when each landed.

The SAFE draft reads as the alliance’s answer to that episode: if one member’s near miss had been shared under these rules, the notification schedule and the control-failure analysis would already be on the clock.

## What happens next

The RFC is open for community review, discussion and contribution through the alliance’s RFC repository, released under a Creative Commons Attribution 4.0 license, with the Linux Foundation inviting developers, enterprises, researchers and standards organizations to shape the framework before it hardens. The draft is explicitly a starting document — the Linux Foundation describes it as an open discussion rather than a finished specification, so the reporting duties and deadlines above remain proposed terms until the working group adopts them.
