Eliza Ward: Hey. You see what dropped Monday?
Brian Reed: The OSAI thing, yeah. The SAFE RFC.
Eliza Ward: August 4. NVIDIA pushing this through the Linux Foundation, a new working group for sharing AI security incidents confidentially. And then 48 hours later — Microsoft drops the Agent 365 implementation post. That's not a coincidence.
Brian Reed: The membership number caught me. More than 120 organizations after Amazon joined.
Eliza Ward: Right — but wait, that's exactly the thing. Who's not on it?
Brian Reed: Google. Anthropic. OpenAI. The three companies whose agents most enterprises are actually running.
Eliza Ward: Which means this is — I mean, it's a significant coalition. But it might be a coalition of everyone except the people who determine whether any of this actually sticks.
Brian Reed: So is 120-plus a sign of momentum, or is it a sign that the room filled up without the key players?
Eliza Ward: Both, maybe — but here's what I keep tripping on. The room filling up doesn't tell us what the room agreed to do.
Brian Reed: Right — and that's where I want to slow down, because I think the two things that dropped this week are getting conflated. SAFE is still a request for comments. RFC. That's the proposal stage, not the standard stage.
Eliza Ward: It hasn't ratified anything yet.
Brian Reed: Nothing. So — let me see if I can make this land cleanly. Think of SAFE as a neighborhood watch that's proposing a shared crime log. And Agent 365 is one house that already installed its own security system back in May. Two different things, two different maturities.
Eliza Ward: That's actually — yeah, that's the right frame. Agent 365 has been generally available since May 2026. SAFE published its RFC on August 4. One of these is live in production. The other is asking for feedback.
Brian Reed: And the house that already installed the system — Microsoft — is the one describing how it works. The source for all of this Agent 365 detail is Microsoft's own Inside Track Blog. That's not a third-party audit, it's Microsoft telling us how Microsoft uses Microsoft's product.
Eliza Ward: Which doesn't make it wrong, but it means — wait, it means Satya Nadella saying 'extend existing governance frameworks' and Agent 365 being the internal expression of that is… one company's implementation. Control plane for agents regardless of origin, self-service with guardrails, partner risk signals added in July — that's all real. But it's verified by nobody except Microsoft.
Brian Reed: The part I don't get is whether OSAI's open-source stack is actually building toward something that could check that. HPE contributed SPIFFE/SPIRE tooling — cryptographically verifiable agent identity — that's concrete. But it's one piece.
Eliza Ward: One piece in a framework that still has no enforcement mechanism. SAFE proposes confidential incident-sharing. Agent 365 is a live product. Those are complementary responses to the same gap — but they are not the same response, and right now only one of them exists.
Brian Reed: But hang on — that gap between what exists and what works, that's where I think the circulating take completely falls apart. People keep saying this is preventive infrastructure, like we're building the fence before the cows escape. The cows are out.
Eliza Ward: March 2026. LiteLLM — the PyPI package that acts as the LLM gateway for multiple agent frameworks. Backdoored. Nearly 47,000 downloads in three hours before the package got pulled.
Brian Reed: 47,000 in three hours — that's not a proof of concept. That's a live supply-chain hit on production infrastructure.
Eliza Ward: And picture what that actually looks like on a Tuesday afternoon. A security analyst at a mid-size firm realizes their LiteLLM gateway — the thing routing requests across three internal agents — was serving the backdoored version for 72 minutes before it got yanked. They have no shared incident channel. No way to check whether five other firms are sitting on identical logs right now.
Brian Reed: That's the exact hole SAFE is supposed to fill. Confidential incident-sharing, so the second firm doesn't rediscover the same attack independently. But — I mean, SAFE is still an RFC. It doesn't exist yet.
Eliza Ward: And the Anthropic absence is — wait, it's not just symbolic once you know this. Claude Code's GitHub Action was found to expose CI/CD secrets. That is the exact failure mode SAFE would want reported. Anthropic isn't in the room.
Brian Reed: So the company with a documented, specific CI/CD credential exposure is outside the voluntary incident-sharing framework. That's — I don't know how you spin that as fine.
Eliza Ward: OWASP's Top 10 for Agentic Applications 2026 has prompt injection at number one. And the OWASP GenAI Security Project published actual CVEs, actual breach reports — not hypothetical scenarios. CISA and NSA, Five Eyes partners, published agentic-AI-specific guidance May 1st. Operational security agencies don't write separate documents for things they consider theoretical.
Brian Reed: And the enforcement question underneath all of this — EO 14110, no U.S. civilian mechanism — that's actually the part that makes everything we just said harder to resolve, and we should get to that.
Eliza Ward: EO 14110 was revoked in January 2025. That's — that's not a minor procedural thing. That was the executive order that gave U.S. civilian agencies something to hang implementation requirements on. Gone. So Five Eyes publishes agentic AI guidance in May 2026, CISA and NSA are on record saying this threat class is real — and there is nothing underneath it on the domestic civilian side that makes any of it compulsory.
Brian Reed: So the guidance exists but the scaffolding that would make it stick — that's just not there.
Eliza Ward: Which means SAFE, even if it moves from RFC to ratified standard — voluntary. OSAI's 120-plus members can all sign on. Still voluntary.
Brian Reed: That's what strikes me about this. Say it's Friday night, a security engineer at a regional bank notices their agent — running on something that routes through LiteLLM — starts querying account tables it has no business touching. They flag it, they shut it down. Under SAFE, they could share that. Confidentially, months later. But the mechanism to make them share it? Doesn't exist. And Google isn't in the room to even receive the report.
Eliza Ward: Right — and the thing that would actually change my read on this? If OpenAI, Google, or Anthropic publicly respond to OSAI. Decline, join, propose an alternative — any of those is signal. Silence is just — I mean, silence could mean they're considering it, or it could mean they don't think OSAI sets the terms.
Brian Reed: And there's no confirmed date for any response. That's not me hedging — that's genuinely unresolved as of the August 6 reporting.
Eliza Ward: No filing, no deadline, no announced meeting. Amazon joining is real signal — it moved the number from roughly 40 to 120-plus. That matters. But Amazon is not a frontier model lab shipping the agents most enterprises are actually running.
Brian Reed: So the watch item is pretty narrow. Does SAFE move from RFC toward a ratified standard — and do the three absent labs say anything publicly about that process. That's actually what to watch. Not the membership count.
Eliza Ward: And if they don't — if Google, Anthropic, and OpenAI stay quiet — then SAFE ratifying changes almost nothing about where the highest-risk deployments actually operate. That's the honest version of where this sits.
Brian Reed: I mean — that's where I actually land. Raising the floor for 120-plus companies is real. I don't want to dismiss that. But if OpenAI, Google, and Anthropic stay out, SAFE becomes a shared playbook for everyone except the deployments that are — I mean, those are the highest-risk ones. That's not a floor, that's a fence with a gap cut in the middle.
Eliza Ward: And we don't actually know why they're absent. That's the part that — wait, I don't think the reporting tells us whether they were asked, declined, or are still deciding. Silence covers all three.
Brian Reed: That's genuinely unresolved.
Eliza Ward: Right. So the question that survives everything we just covered — if they join, SAFE's reach expands overnight. If they don't, the RFC ratifies into a standard that doesn't touch the highest-risk deployments. And SAFE is still a request for comments as of August 6th. The distance from RFC to anything compulsory — nobody with authority to close that gap has stepped into it.
Brian Reed: Enough to watch. Not enough to call.