[Photo: Shutterstock]

About 120 organisations including Nvidia, Cisco and CrowdStrike are pursuing a joint framework to systematically report and record security incidents involving artificial intelligence (AI) agents.

The move reflects a need for the industry to share control failures and security incidents as more AI agents perform tasks by moving across multiple computer systems and tools without human intervention.

Axios reported on Aug. 11 that the Open Secure AI Alliance has prepared a draft guideline for a cyber incident reporting system related to AI agents called SAFE, or Shared AI Findings Exchange. Participants include companies that deploy and develop AI models, cloud and tool providers, independent researchers and operators of key infrastructure. Government agencies can participate as observers without voting rights.

Under the draft, member companies must report cases in which an AI system accessed or attacked a third-party system without authorisation, compromised confidential information, or continued probing a live operating system despite suspecting it lacked access rights. Certain levels of near misses are also subject to reporting.

If an incident occurs, the draft calls for preserving detailed materials including prompts, agent task trace data, tool invocation logs, user identity, and authorisation and authentication information. It also includes notifying affected organisations as quickly as possible and submitting an initial confidential report to SAFE within 4 business days. If necessary, it would disclose preliminary facts within 30 days and share corrective measures within 90 days.

In particular, the draft states that AI intent does not determine whether an incident must be reported. It means that even if it was believed to be a test environment, the duty to report does not disappear if the system accessed a real system.

The initiative follows a series of cases in which AI agents moved beyond controlled security test environments and accessed real third-party systems. Justin Boitano (저스틴 보이타노), Nvidia's vice president and general manager for enterprise computing, explained that the concept of flight recorders used in the U.S. aviation industry to investigate air safety accidents was applied to SAFE. The aim is to use a system that records all agent actions like a flight recorder to analyse the causes of incidents and establish industry-wide security controls.

SAFE still has no official safe harbour that would exempt companies from legal liability when they voluntarily disclose sensitive incident information. Even so, participating companies believe voluntary participation will be possible based on an existing culture of sharing threat information in cybersecurity.

The Open Secure AI Alliance plans to gather views from industry and researchers on the SAFE draft through a Linux Foundation-run feedback process and then prepare a final version.

Keyword

#Nvidia #Cisco #CrowdStrike #Open Secure AI Alliance #SAFE
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.