{"slug": "tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework", "title": "Tech giants are pushing for a new AI agent incident reporting framework", "summary": "A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records. The Open Secure AI Alliance is developing the Shared AI Findings Exchange (SAFE), which would set timelines for reporting incidents, such as notifying affected organizations as soon as possible and submitting an initial confidential report within four business days. The framework aims to address the lack of standard reporting for AI agent security failures, modeled after NASA's aviation safety reporting system.", "body_md": "A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong.\nWhy it matters: As AI agents gain more autonomy to act across computer systems, the industry lacks a standard way to report security failures and learn from them.\nDriving the news: The Open Secure AI Alliance is developing guidelines for what it's calling the Shared AI Findings Exchange (SAFE), a proposed framework for how organizations report cyber incidents involving AI agents.\nThe draft calls for participation from model deployers, AI developers, cloud and tool providers, independent researchers, critical infrastructure operators, and other groups.\nGovernment agencies would also be invited to participate as \"non-controlling observers,\" per the proposed guidelines.\nZoom in: SAFE members would agree to report incidents in which an AI system accesses or exploits a third-party system without authorization, breaches confidential information, or continues probing a production target after its operator suspects the activity is unauthorized.\nMembers would also report certain near misses and preserve evidence from incidents, including prompts, agent traces, tool calls, identities, permissions and credentials.\nUnder the proposed timeline, members would notify affected organizations as soon as possible, submit an initial confidential report to SAFE within four business days, publish a preliminary factual report within 30 days when appropriate, and provide a remediation update within 90 days.\n\"Intent does not determine whether an event is reportable,\" per the draft guidelines. \"Believing that an environment was simulated may explain an incident, but it does not remove the duty to report it.\"\nSAFE would analyze incidents for recurring failures and recommend shared security controls.\nThe big picture: The proposal follows incidents in which AI agents escaped the boundaries of controlled security tests and accessed real third-party systems.\nJustin Boitano, vice president and general manager of enterprise computing at Nvidia, told Axios at Black Hat that the program is modeled after NASA's aviation safety reporting system, where incidents can be investigated using data captured by an aircraft's flight recorder.\n\"The way I think of it is the harness, which has visibility into everything the agent is doing, is the flight recorder,\" Boitano said. \"If you can get cybersecurity experts access to the flight recorders when these accidents happen, they can make a better determination on the right set of controls for the industry.\"\nBetween the lines: SAFE has no formal safe-harbor protections shielding companies that voluntarily disclose potentially damaging details about an AI incident.\nBut the alliance is betting cybersecurity's existing culture of sharing threat intelligence will make companies willing to participate anyway.\n\"There's been very little pushback,\" Julien Soriano, deputy CISO and vice president at Nvidia, told Axios. \"We see people wanting to get on board. They want to share.\"\nWhat's next: The Open Secure AI Alliance is soliciting community feedback on the proposal through its request-for-comments process, hosted by the Linux Foundation.\nGo deeper: AI's alarming new skill: breaking out of the test lab", "url": "https://wpnews.pro/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework", "canonical_source": "https://www.machinebrief.com/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reportin-wx5e", "published_at": "2026-08-11 17:31:27+00:00", "updated_at": "2026-08-11 21:12:13.105303+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy", "ai-agents", "ai-infrastructure"], "entities": ["Nvidia", "Cisco", "CrowdStrike", "Open Secure AI Alliance", "Shared AI Findings Exchange", "Justin Boitano", "Julien Soriano", "Linux Foundation"], "alternates": {"html": "https://wpnews.pro/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework", "markdown": "https://wpnews.pro/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework.md", "text": "https://wpnews.pro/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework.txt", "jsonld": "https://wpnews.pro/news/tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework.jsonld"}}