{"id":40056,"date":"2026-08-12T04:43:28","date_gmt":"2026-08-11T23:43:28","guid":{"rendered":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=40056"},"modified":"2026-08-12T04:43:28","modified_gmt":"2026-08-11T23:43:28","slug":"tech-giants-are-pushing-for-a-new-ai-agent-incident-reporting-framework","status":"publish","type":"post","link":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/?p=40056","title":{"rendered":"Tech giants are pushing for a new AI agent incident reporting framework"},"content":{"rendered":"<p><script>\r\n  atOptions = {\r\n    'key' : '644b717812d811d6a1c1fc5b6ccd6fa6',\r\n    'format' : 'iframe',\r\n    'height' : 90,\r\n    'width' : 728,\r\n    'params' : {}\r\n  };\r\n<\/script>\r\n<script src=\"https:\/\/www.highperformanceformat.com\/644b717812d811d6a1c1fc5b6ccd6fa6\/invoke.js\"><\/script>\r\n<br \/>\n<br \/><img decoding=\"async\" src=\"https:\/\/images.axios.com\/H3fwACAT8uO_K4c7yQhVvdP0OTs=\/1366x768\/smart\/2020\/07\/14\/221817-1594765097189.jpg\" \/><\/p>\n<p>A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for <a href=\"https:\/\/www.axios.com\/2026\/08\/11\/ai-agents-rogue-autonomy-hugging-face\" target=\"_blank\">AI agents <\/a>that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong.<\/p>\n<p><strong>Why it matters:<\/strong> As AI agents gain more autonomy to act across computer systems, the industry lacks a standard way to report security failures and learn from them.<\/p>\n<hr>\n<p><strong>Driving the news:<\/strong> The Open Secure AI Alliance is developing guidelines for what it&#8217;s calling the Shared AI Findings Exchange (SAFE), a proposed framework for how organizations report cyber incidents involving AI agents. <\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/OpenSecureAIAlliance\/RFCs\/blob\/main\/rfc-safe-proposal.md\" target=\"_blank\">The draft<\/a> calls for participation from model deployers, AI developers, cloud and tool providers, independent researchers, critical infrastructure operators, and other groups. <\/li>\n<li>Government agencies would also be invited to participate as &#8220;non-controlling observers,&#8221; per the proposed guidelines. <\/li>\n<\/ul>\n<p><strong>Zoom in:<\/strong> SAFE members would agree to report incidents in which an AI system accesses or exploits a third-party system without authorization, breaches confidential information, or continues probing a production target after its operator suspects the activity is unauthorized.<\/p>\n<ul>\n<li>Members would also report certain near misses and preserve evidence from incidents, including prompts, agent traces, tool calls, identities, permissions and credentials.<\/li>\n<li>Under the proposed timeline, members would notify affected organizations as soon as possible, submit an initial confidential report to SAFE within four business days, publish a preliminary factual report within 30 days when appropriate, and provide a remediation update within 90 days.<\/li>\n<li>&#8220;Intent does not determine whether an event is reportable,&#8221; per the draft guidelines. &#8220;Believing that an environment was simulated may explain an incident, but it does not remove the duty to report it.&#8221; <\/li>\n<li>SAFE would analyze incidents for recurring failures and recommend shared security controls.<\/li>\n<\/ul>\n<p><strong>The big picture:<\/strong> The proposal follows incidents in which AI agents escaped the boundaries of controlled security tests and accessed real third-party systems.<\/p>\n<ul>\n<li>Justin Boitano, vice president and general manager of enterprise computing at Nvidia, told Axios at Black Hat that the program is modeled after NASA&#8217;s aviation safety reporting system, where incidents can be investigated using data captured by an aircraft&#8217;s flight recorder.<\/li>\n<li>&#8220;The way I think of it is the harness, which has visibility into everything the agent is doing, is the flight recorder,&#8221; Boitano said. &#8220;If you can get cybersecurity experts access to the flight recorders when these accidents happen, they can make a better determination on the right set of controls for the industry.&#8221; <\/li>\n<\/ul>\n<p><strong>Between the lines:<\/strong> SAFE has no formal safe-harbor protections shielding companies that voluntarily disclose potentially damaging details about an AI incident.<\/p>\n<ul>\n<li>But the alliance is betting cybersecurity&#8217;s existing culture of sharing threat intelligence will make companies willing to participate anyway.<\/li>\n<li>&#8220;There&#8217;s been very little pushback,&#8221; Julien Soriano, deputy CISO and vice president at Nvidia, told Axios. &#8220;We see people wanting to get on board. They want to share.&#8221;<\/li>\n<\/ul>\n<p><strong>What&#8217;s next:<\/strong> The Open Secure AI Alliance is <a href=\"https:\/\/github.com\/OpenSecureAIAlliance\/RFCs?tab=readme-ov-file\" target=\"_blank\">soliciting<\/a> community feedback on the proposal through its request-for-comments process, hosted by the Linux Foundation.<\/p>\n<p><strong>Go deeper<\/strong>: <a href=\"https:\/\/www.axios.com\/2026\/07\/23\/openai-hugging-face-cyber-hacks-testing\" target=\"_blank\">AI&#8217;s alarming new skill: breaking out of the test lab<\/a><\/p>\n<script async=\"async\" data-cfasync=\"false\" src=\"https:\/\/pl30214220.effectivecpmnetwork.com\/9ab3d4df8a7e1a6171e16ddbf732cc19\/invoke.js\"><\/script>\r\n<div id=\"container-9ab3d4df8a7e1a6171e16ddbf732cc19\"><\/div>\r\n\n","protected":false},"excerpt":{"rendered":"<p>A coalition of more than 120 organizations, including Nvidia, Cisco and CrowdStrike, is proposing a new incident-reporting framework for AI agents that would require participating companies to disclose certain agent mishaps and preserve detailed records of what went wrong. Why it matters: As AI agents gain more autonomy to act across computer systems, the industry&#8230;<\/p>\n","protected":false},"author":1,"featured_media":40057,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/images.axios.com\/H3fwACAT8uO_K4c7yQhVvdP0OTs=\/1366x768\/smart\/2020\/07\/14\/221817-1594765097189.jpg","fifu_image_alt":"","footnotes":""},"categories":[17],"tags":[],"class_list":["post-40056","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-political-news"],"brizy_media":[],"_links":{"self":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/40056","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=40056"}],"version-history":[{"count":0,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/posts\/40056\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=\/wp\/v2\/media\/40057"}],"wp:attachment":[{"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=40056"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=40056"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usnews-14267fa.ingress-comporellon.ewp.live\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=40056"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}