The Linux Foundation has proposed "SAFE (Shared AI Findings Exchange)," a set of guidelines for collecting and analyzing security incidents involving agentic AI while maintaining confidentiality, and for publishing evidence-based operational recommendations. This initiative is supported by members of the Open Secure AI Alliance, including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat.
Since AI agents are systems combining identity control, execution environments (harnesses), guardrails, logs, and evaluations—rather than standalone models—it is argued that measures beyond simple vulnerability scanning are necessary. In response, various companies are providing technical contributions across each layer of the defense stack.
NVIDIA is providing "NOOA," a research framework that makes it easier to test and audit agent behavior; "OpenShell," a runtime that limits permissions during execution; and "NeMo Safe Synthesizer" for generating secure synthetic data. Additionally, CrowdStrike reported that it has fine-tuned NVIDIA's "Nemotron Nano" model for cyber defense, achieving high precision in generating investigation queries.
Other contributions include Okta developing reference implementations for agent identity and access management, and Amazon contributing "Strands Agents," which enables visualization of agent behavior, and "Cedar" for permission control. Microsoft has released tools such as "PyRIT," which supports automated red teaming, as open source.
Source: