Skip to main content
Akamai proposes SAFE cybersecurity guidelines for AI threats, showing a secure network with data flowing.

Editorial illustration for Akamai Proposes SAFE Cybersecurity Guidelines for AI Threats

Akamai's SAFE Guidelines Combat AI Security Threats

Akamai Proposes SAFE Cybersecurity Guidelines for AI Threats

4 min read

The Linux Foundation released a Request for Comments today on Shared AI Findings Exchange, a proposal to turn agentic AI security incidents into intelligence the whole industry can use. The timing lines up with Black Hat, which opens today in Las Vegas. SAFE comes out of the Open Secure AI Alliance, a group that has grown past 120 organizations since it formed, with a working group drafting the guidelines now. NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat are among the members feeding into the initial proposal alongside the Linux Foundation.

The pitch is straightforward: collect AI incidents and near misses confidentially, notify the parties affected, flag control failures that keep repeating, and publish recommendations grounded in actual evidence rather than guesswork. That's aimed squarely at agentic AI, where systems act on their own and mistakes can propagate faster than a human team can catch them. Akamai has thrown its support behind the framework as part of the broader alliance effort, arguing that incident-sharing at this scale needs infrastructure that doesn't currently exist in the AI security world. What SAFE is meant to solve, according to the group backing it, comes down to speed and scale.

The SAFE guidelines include proposals to confidentially collect and analyze AI incidents and near misses, inform those impacted, identify recurring control failures and publish evidence-based operating recommendations that reduce systemic risk.

Why this matters

SAFE is a bet that AI security works better as a shared utility than a proprietary moat, and that's worth watching closely. A 120-member alliance drafting incident-sharing standards through the Linux Foundation, timed to Black Hat, signals that agentic AI risk has outgrown any single vendor's telemetry. Akamai's contribution, its State of the Internet data and Security Intelligence Group research, only matters if it actually gets folded into a common exchange rather than staying a marketing footnote in someone's blog post. Same goes for Cognition's trustworthiness evaluation: a useful tool only if it feeds a shared standard instead of becoming another one-off benchmark nobody cross-references.

For developers and founders building agentic systems now, the real signal isn't the RFC itself, it's whether competitors will actually disclose exploit data to each other. History with bug bounty and threat-intel sharing says adoption is slow and uneven even when the incentives are obvious. We'd treat SAFE as a draft to track, not a standard to build against yet. Watch who actually contributes incident data once the comment period closes, not who signed the announcement.

Common Questions Answered

What is the Shared AI Findings Exchange (SAFE) proposal and who is developing it?

SAFE is a proposal released by the Linux Foundation to turn agentic AI security incidents into intelligence that the entire industry can use. It is being developed by the Open Secure AI Alliance, a group that has grown to over 120 organizations including NVIDIA, Cisco, CrowdStrike, Hugging Face, and Red Hat, with a dedicated working group currently drafting the guidelines.

What specific capabilities does the SAFE framework propose for handling AI security incidents?

The SAFE guidelines propose to confidentially collect and analyze AI incidents and near misses, inform those impacted by the incidents, identify recurring control failures across organizations, and publish evidence-based operating recommendations designed to reduce systemic risk. These capabilities aim to create a shared approach to AI security rather than individual vendor-specific responses.

Why is the timing of SAFE's release at Black Hat significant for the AI security industry?

The release of SAFE at Black Hat signals that agentic AI risk has become significant enough to outgrow any single vendor's telemetry or proprietary security approach. The timing demonstrates industry-wide recognition that AI security threats require collaborative, standardized incident-sharing mechanisms coordinated through a neutral organization like the Linux Foundation.

How does SAFE represent a shift in how the AI industry approaches cybersecurity?

SAFE represents a fundamental shift from treating AI security as a proprietary competitive advantage to viewing it as a shared utility that benefits the entire industry. By establishing common standards for confidential incident collection and analysis through a 120-member alliance, SAFE prioritizes collective risk reduction over individual vendor differentiation.

LIVE16:12Apple: 12 More Ex-Employees May Have Taken Data to OpenAI