Linux Foundation workgroup drafts shared AI incident response guidelines

NVIDIA, Cisco, CrowdStrike, and others are working with the Linux Foundation on SAFE, a standard for sharing AI cybersecurity incident data. The framework aims to let organizations collectively contain agentic AI failures and recover without losing critical state.

Categorized in: AI News Healthcare
Published on: Aug 27, 2026
Linux Foundation workgroup drafts shared AI incident response guidelines

A coalition of AI and cybersecurity vendors, including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat, is working with the Linux Foundation to draft the Shared AI Findings Exchange (SAFE) guidelines. The goal is to create rapid response standards for infrastructure and intellectual property threats by turning agentic cybersecurity incidents into a shared protection mechanism. The SAFE workgroup is developing protocols that help AI systems contain failures and recover safely without losing critical state.

The effort falls under the Open Secure AI Alliance, a multi-vendor coalition building transparent and adaptable open tools for AI safety. The group is consolidating cybersecurity proposals to confidentially collect and analyze AI incidents and near misses, inform impacted system owners, identify recurring control failures, and publish evidence-based operating recommendations.

Open threat sharing as collective defense

"When trusted ecosystems share threat information openly, collective defense becomes a force multiplier," wrote Justin Boitano, vice president and general manager of enterprise computing at NVIDIA, in a blog post about the effort. "Alliance members are contributing tooling, harnesses and supporting technologies across this emerging layer of the AI security stack."

Members including Okta, Palo Alto Networks, Amazon, Capital One, Cloudflare, the Microsoft AI Red Team, Cisco, and CrowdStrike have been building identity and permissions defenses, harnesses, runtime guardrails, security AI models, and tools for observability, evaluation, data security, privacy, availability, and resilience, according to the blog.

NVIDIA is contributing its full stack of open cybersecurity software and models, including research for testing, tracing, auditing, and governing agent behavior. The company also contributed OpenShell, which restricts agents by enforcing security and privacy controls at the agent level. NVIDIA's models, including BioNeMo for health and life sciences, ship with open weights, datasets, and training techniques.

Verified agent skills offer portable instructions that are cataloged and scanned for risks like prompt injection and tool poisoning. They are cryptographically signed and documented. "Defenders know exactly what an agent skill does, where it came from and whether it was modified after publication," said Boitano.

Other NVIDIA platforms enforce safety policies, protect sensitive data, and generate privacy-safe synthetic data. Garak, the company's open source large language model vulnerability scanner, can check models for data leaks, prompt injections, and jailbreak scenarios before they ship. For professionals working in cybersecurity roles, this type of open collaboration directly applies to how AI for Cybersecurity Analysts is evolving beyond single-vendor defenses.

Growing attack surface in healthcare

AI has increased the attack surface for hospitals and health systems, requiring higher levels of governance for securing IT systems against new risks, said Deepesh Randeri, CISO and vice president of information security and infrastructure at Akron Children's Hospital. "If the proper controls are not implemented to safeguard the technology, the people and the process, there could be potential security incidents," he told Healthcare IT News earlier this year.

In June, the rapid pace of frontier model development revealed more dire cybersecurity implications when Anthropic's Fable 5 model produced code to exploit software vulnerabilities. The model was subsequently updated with additional safety classifiers. Anthropic also launched Project Glasswing, a collaborative cybersecurity initiative to improve vital software hardening against AI-initiated attacks across industries.

Why this matters for healthcare

Healthcare organizations run on interconnected systems where a compromised AI agent could expose patient data or disrupt clinical operations. The SAFE framework's approach to sharing incident data across trusted ecosystems gives hospital IT teams a practical way to learn from failures elsewhere without waiting for a breach of their own. CISOs and security teams should watch for the published operating recommendations from this workgroup, since they will likely inform how AI governance expectations evolve for health systems. Those looking to build internal capacity can explore targeted AI for Healthcare training to prepare staff for these emerging requirements.

"AI agents are more than a model - they tap into systems of open and closed models, harnesses, tools and runtimes to get work done," Boitano wrote. "If a model is the agent's brain, the harness is the body that takes action by using tools. The harness surrounding the model acts like an orchestrator that determines how agents are deployed, coordinated and constrained."


Get Daily AI News

Your membership also unlocks:

700+ AI Courses
700+ Certifications
Personalized AI Learning Plan
6500+ AI Tools (no Ads)
Daily AI News by job industry (no Ads)