SAFE, the Shared AI Findings Exchange, is a proposed framework for confidentially reporting and sharing AI security incidents and near misses. It was announced August 4, 2026, at Black Hat by the Open Secure AI Alliance, an NVIDIA-led coalition of more than 120 member organizations, including Cisco and CrowdStrike. The model is voluntary, confidential, and non-punitive, and it borrows a playbook aviation has run since the 1970s, when NASA began collecting near-miss reports from pilots and air traffic controllers, roughly 2 million to date, and turning them into industry-wide safety improvements.
On the latest Mitiga Mic, on the Cybercrime Magazine Podcast, host and Field CISO Brian Contos digs into SAFE with two people who read the proposal closely, Mitiga co-founder and COO Ariel Parnes and Mitiga head of Cyber Defense Brandon James Allen.
Ariel separates learning regimes from disclosure regimes and argues SAFE only works as the former. Disclosure rules like the SEC's four-day clock optimize for sharing the minimum. "The people that will shape the discussions in this kind of framework are engineers, not lawyers," he says.
Brandon wants the scope wider than third-party harm. Most AI activity happens inside your own trust boundaries, and AI does not fail the way scripted automation fails. "When it fails, it can go off in completely unexpected ways," he says, and sometimes the incident is the action AI failed to take.
Ariel also leaves security leaders a test worth running today. If an AI agent went rogue in your environment yesterday, how much of the forensic evidence SAFE asks for could you actually produce? Whatever is missing, he argues, is a good approximation of your visibility roadmap for the next one to two years.
Watch the full episode above, and subscribe to the Cybercrime Magazine Podcast to catch Mitiga Mic twice a month.