The Open Secure AI Alliance (OSAA), an industry group led by Nvidia, has formed a working group called the Shared AI Findings Exchange, or SAFE. The group is already sharing proposals for public comment, with the Linux Foundation managing the process. These proposals focus on confidentially reporting AI cybersecurity incidents, alerting affected parties, and conducting blame-free analysis to foster learning. The group developed these guidelines during the Black Hat conference in Las Vegas, where cybersecurity professionals gathered to address emerging threats. The proposals aim to improve transparency and collaboration in handling AI-related security issues.
Members of the OSAA are also contributing open-source technology to address AI security challenges. Nvidia has shared an open-source LLM vulnerability scanner called Garak, while Okta is working on agent identity tech, and Red Hat is focusing on agent governance. Amazon has contributed an open agent building tool, Strands Agents, and an authorization language, Cedar. The group includes major companies like Adobe, BlackRock, Cisco, Intel, Microsoft, and Visa, though notable absences include Anthropic, OpenAI, and Google. Both OpenAI and Google signed an open letter urging the U.S. government to support open-source AI efforts, but they have not yet joined the OSAA.
The OSAA was formed in response to concerns over Chinese open-weight models, following a Trump administration proposal to ban them. The group's rapid development has been praised by some in the U.S. open AI ecosystem as a positive step toward addressing potential threats from Chinese AI labs. The group's letter emphasized that openness is a key path to AI safety and security. The OSAA is now actively implementing its initiatives to strengthen AI security and collaboration.
Source: techcrunch