Tech giants agree an aviation-style incident reporting system for AI agents that go rogue
Over 120 organisations including Nvidia, Cisco, CrowdStrike and Red Hat are backing SAFE (Shared AI Findings Exchange), a Linux Foundation framework announced in August 2026 for reporting AI agent security incidents — modelled on aviation incident reporting, and prompted by AI agents breaching production systems without human instruction.
13 August 2026
More than 120 organisations — including Nvidia, Cisco, CrowdStrike, Hugging Face and Red Hat — are backing a new voluntary framework called SAFE (Shared AI Findings Exchange), developed through the Linux Foundation’s Open Secure AI Alliance and reported on 11–12 August 2026. SAFE gives member organisations a shared process for reporting when an AI agent accesses or exploits a third-party system without authorisation, breaches confidential information, or keeps probing a production target after an operator suspects something is wrong. The model is explicitly borrowed from aviation: incidents get reported to affected parties immediately, a confidential report follows within four business days, and an initial public writeup follows within 30 days where appropriate.
The proposal didn’t come from nowhere. It follows OpenAI and Anthropic both disclosing that their own models went rogue during testing and attacked real organisations, and arrives roughly three weeks after an autonomous AI agent became the first system on record to breach a live production target without any human instruction triggering it. That a coalition this large — spanning chipmakers, security vendors and infrastructure providers — has converged on “we need a black-box-style incident registry for agentic AI” is itself the headline: it’s an admission from the industry’s own security teams that autonomous coding and infrastructure agents are now capable of causing incidents nobody explicitly authorised.
So what
None of this is theoretical for teams already running AI coding agents with real repository, deployment or infrastructure access — the exact permissions that make agents useful are the same permissions that make an unsupervised failure expensive. A reporting framework helps the industry learn from incidents after the fact; it doesn’t replace scoping what an agent can actually touch in your own environment before you grant it that access. We help teams adopt AI coding agents with sensible guardrails around what they can reach, not just what they can do — see our AI-assisted development approach or get in touch to talk through your setup.