Onpode
Cover art for NVIDIA just launched the SAFE Initiative for sharing agentic threat intelligence while Microsoft rolled out Agent 365 governance—addressing a months-old gap in agent security frameworks

NVIDIA just launched the SAFE Initiative for sharing agentic threat intelligence while Microsoft rolled out Agent 365 governance—addressing a months-old gap in agent security frameworks

August 7, 2026 · 10 min

Eliza Ward & Brian Reed

NVIDIA's SAFE Initiative — an RFC published August 4, 2026 through the Linux Foundation — proposes confidential AI incident-sharing across 120-plus organizations, but Google, Anthropic, and OpenAI are absent. Microsoft's Agent 365, live since May 2026, addresses the same agentic security gap independently. Neither effort is compulsory, and no enforcement mechanism exists.

On August 4, 2026, participants in the Open Secure AI Alliance (OSAI) — a Linux Foundation-backed coalition — published a Request for Comments (RFC) proposing the Shared AI Findings Exchange (SAFE) Working Group.

0:009:43
Get the next episode on AI Agents Ecosystem

Follow it free — new episodes land in your feed.

Or make your own — any topic, in minutes

More Onpode episodes on AI Agents Ecosystem

About this episode

On August 4, NVIDIA pushed a proposal through the Linux Foundation: the SAFE initiative, a working group for sharing AI security incidents confidentially across organizations. More than 120 companies joined, including Amazon. Google, Anthropic, and OpenAI did not. Forty-eight hours later, Microsoft published details on Agent 365, its live agent governance product, generally available since May 2026. The two developments landed in the same news cycle and got treated as the same story. They're not. This episode works through why that distinction matters. SAFE is still a request for comments — nothing has been ratified, no enforcement mechanism exists, and even if it ratifies, participation is voluntary. Agent 365 is a real product, but its security claims are sourced entirely from Microsoft's own blog. One is live in production; the other is asking for feedback. Underneath both is something harder to dismiss: a backdoored LiteLLM package that reached nearly 47,000 downloads in three hours in March 2026 before it was pulled. That's not a proof of concept — that's a live supply-chain hit on the exact infrastructure SAFE is designed to protect. The episode also covers the revocation of EO 14110, what that actually removed from the civilian enforcement picture, and why the silence from the three absent labs covers a wider range of possibilities than most of the current reporting acknowledges. Worth your time if you're tracking where agent security governance actually stands versus where it's being described as standing.

Frequently asked

What is NVIDIA's SAFE Initiative and what does it do?

NVIDIA's SAFE Initiative, proposed August 4, 2026 through the Linux Foundation under the Open Secure AI Alliance, is a request-for-comments framework for confidential AI security incident-sharing among organizations. It had over 120 members as of early August 2026, including Amazon, but remains a proposal — not a ratified standard — with no enforcement mechanism.

Why are Google, Anthropic, and OpenAI not part of the SAFE Initiative?

Google, Anthropic, and OpenAI had not joined the SAFE Initiative as of August 6, 2026 reporting. Their absence is unresolved — available reporting does not confirm whether they were invited, declined, or are still deciding. These are the three companies whose agents most enterprises are actively running, making their silence the central unresolved question about SAFE's real-world reach.

What is Microsoft Agent 365 and how does it relate to agentic AI security?

Microsoft Agent 365, generally available since May 2026, is a governance control plane for AI agents regardless of their origin. It offers self-service deployment with guardrails and added partner risk signals in July 2026. Details come from Microsoft's own Inside Track Blog — not a third-party audit — making it one company's verified-by-itself implementation of agentic security governance.

What was the LiteLLM supply-chain attack?

In March 2026, LiteLLM — a PyPI package widely used as an LLM gateway across multiple agent frameworks — was backdoored. The malicious version received nearly 47,000 downloads in three hours before it was pulled. The attack is a documented live supply-chain compromise of production agentic infrastructure, not a theoretical scenario, and predates SAFE's August 2026 RFC publication.

Did CISA and NSA publish guidance on agentic AI security?

CISA and NSA, alongside Five Eyes partners, published agentic-AI-specific cybersecurity guidance on May 1. The guidance is described in the transcript as addressing a real, non-theoretical threat class. However, EO 14110 — which gave U.S. civilian agencies a mechanism to enforce implementation requirements — was revoked in January 2025, leaving all such guidance voluntary on the domestic civilian side.

Grounded in 7 sources
Tech industry alliance proposes AI agent safety reporting program | Cybersecurity Dive · cybersecuritydive.com
Agentic AI Risks Existing Security Controls Weren't Built For · forcepoint.com
Prompt injection still drives most agentic AI security failures in production - Help Net Security · helpnetsecurity.com
NVIDIA Group Proposes SAFE Initiative for Agentic Threat Intel Sharing · infosecurity-magazine.com
NVIDIA’s Open Security AI Alliance Is Missing Some Big Names - Infosecurity Magazine · infosecurity-magazine.com
Agentic AI Governance at a Crossroads – Lab Space · labs.cloudsecurityalliance.org
Proposing the SAFE Working Group: An Open Community Effort to Improve AI Security · linuxfoundation.org
Read transcript

Eliza Ward: Hey. You see what dropped Monday?

Brian Reed: The OSAI thing, yeah. The SAFE RFC.

Eliza Ward: August 4. NVIDIA pushing this through the Linux Foundation, a new working group for sharing AI security incidents confidentially. And then 48 hours later — Microsoft drops the Agent 365 implementation post. That's not a coincidence.

Brian Reed: The membership number caught me. More than 120 organizations after Amazon joined.

Eliza Ward: Right — but wait, that's exactly the thing. Who's not on it?

Brian Reed: Google. Anthropic. OpenAI. The three companies whose agents most enterprises are actually running.

Eliza Ward: Which means this is — I mean, it's a significant coalition. But it might be a coalition of everyone except the people who determine whether any of this actually sticks.

Brian Reed: So is 120-plus a sign of momentum, or is it a sign that the room filled up without the key players?

Eliza Ward: Both, maybe — but here's what I keep tripping on. The room filling up doesn't tell us what the room agreed to do.

Brian Reed: Right — and that's where I want to slow down, because I think the two things that dropped this week are getting conflated. SAFE is still a request for comments. RFC. That's the proposal stage, not the standard stage.

Eliza Ward: It hasn't ratified anything yet.

Brian Reed: Nothing. So — let me see if I can make this land cleanly. Think of SAFE as a neighborhood watch that's proposing a shared crime log. And Agent 365 is one house that already installed its own security system back in May. Two different things, two different maturities.

Eliza Ward: That's actually — yeah, that's the right frame. Agent 365 has been generally available since May 2026. SAFE published its RFC on August 4. One of these is live in production. The other is asking for feedback.

Brian Reed: And the house that already installed the system — Microsoft — is the one describing how it works. The source for all of this Agent 365 detail is Microsoft's own Inside Track Blog. That's not a third-party audit, it's Microsoft telling us how Microsoft uses Microsoft's product.

Eliza Ward: Which doesn't make it wrong, but it means — wait, it means Satya Nadella saying 'extend existing governance frameworks' and Agent 365 being the internal expression of that is… one company's implementation. Control plane for agents regardless of origin, self-service with guardrails, partner risk signals added in July — that's all real. But it's verified by nobody except Microsoft.

Brian Reed: The part I don't get is whether OSAI's open-source stack is actually building toward something that could check that. HPE contributed SPIFFE/SPIRE tooling — cryptographically verifiable agent identity — that's concrete. But it's one piece.

Eliza Ward: One piece in a framework that still has no enforcement mechanism. SAFE proposes confidential incident-sharing. Agent 365 is a live product. Those are complementary responses to the same gap — but they are not the same response, and right now only one of them exists.

Brian Reed: But hang on — that gap between what exists and what works, that's where I think the circulating take completely falls apart. People keep saying this is preventive infrastructure, like we're building the fence before the cows escape. The cows are out.

Eliza Ward: March 2026. LiteLLM — the PyPI package that acts as the LLM gateway for multiple agent frameworks. Backdoored. Nearly 47,000 downloads in three hours before the package got pulled.

Brian Reed: 47,000 in three hours — that's not a proof of concept. That's a live supply-chain hit on production infrastructure.

Eliza Ward: And picture what that actually looks like on a Tuesday afternoon. A security analyst at a mid-size firm realizes their LiteLLM gateway — the thing routing requests across three internal agents — was serving the backdoored version for 72 minutes before it got yanked. They have no shared incident channel. No way to check whether five other firms are sitting on identical logs right now.

Brian Reed: That's the exact hole SAFE is supposed to fill. Confidential incident-sharing, so the second firm doesn't rediscover the same attack independently. But — I mean, SAFE is still an RFC. It doesn't exist yet.

Eliza Ward: And the Anthropic absence is — wait, it's not just symbolic once you know this. Claude Code's GitHub Action was found to expose CI/CD secrets. That is the exact failure mode SAFE would want reported. Anthropic isn't in the room.

Brian Reed: So the company with a documented, specific CI/CD credential exposure is outside the voluntary incident-sharing framework. That's — I don't know how you spin that as fine.

Eliza Ward: OWASP's Top 10 for Agentic Applications 2026 has prompt injection at number one. And the OWASP GenAI Security Project published actual CVEs, actual breach reports — not hypothetical scenarios. CISA and NSA, Five Eyes partners, published agentic-AI-specific guidance May 1st. Operational security agencies don't write separate documents for things they consider theoretical.

Brian Reed: And the enforcement question underneath all of this — EO 14110, no U.S. civilian mechanism — that's actually the part that makes everything we just said harder to resolve, and we should get to that.

Eliza Ward: EO 14110 was revoked in January 2025. That's — that's not a minor procedural thing. That was the executive order that gave U.S. civilian agencies something to hang implementation requirements on. Gone. So Five Eyes publishes agentic AI guidance in May 2026, CISA and NSA are on record saying this threat class is real — and there is nothing underneath it on the domestic civilian side that makes any of it compulsory.

Brian Reed: So the guidance exists but the scaffolding that would make it stick — that's just not there.

Eliza Ward: Which means SAFE, even if it moves from RFC to ratified standard — voluntary. OSAI's 120-plus members can all sign on. Still voluntary.

Brian Reed: That's what strikes me about this. Say it's Friday night, a security engineer at a regional bank notices their agent — running on something that routes through LiteLLM — starts querying account tables it has no business touching. They flag it, they shut it down. Under SAFE, they could share that. Confidentially, months later. But the mechanism to make them share it? Doesn't exist. And Google isn't in the room to even receive the report.

Eliza Ward: Right — and the thing that would actually change my read on this? If OpenAI, Google, or Anthropic publicly respond to OSAI. Decline, join, propose an alternative — any of those is signal. Silence is just — I mean, silence could mean they're considering it, or it could mean they don't think OSAI sets the terms.

Brian Reed: And there's no confirmed date for any response. That's not me hedging — that's genuinely unresolved as of the August 6 reporting.

Eliza Ward: No filing, no deadline, no announced meeting. Amazon joining is real signal — it moved the number from roughly 40 to 120-plus. That matters. But Amazon is not a frontier model lab shipping the agents most enterprises are actually running.

Brian Reed: So the watch item is pretty narrow. Does SAFE move from RFC toward a ratified standard — and do the three absent labs say anything publicly about that process. That's actually what to watch. Not the membership count.

Eliza Ward: And if they don't — if Google, Anthropic, and OpenAI stay quiet — then SAFE ratifying changes almost nothing about where the highest-risk deployments actually operate. That's the honest version of where this sits.

Brian Reed: I mean — that's where I actually land. Raising the floor for 120-plus companies is real. I don't want to dismiss that. But if OpenAI, Google, and Anthropic stay out, SAFE becomes a shared playbook for everyone except the deployments that are — I mean, those are the highest-risk ones. That's not a floor, that's a fence with a gap cut in the middle.

Eliza Ward: And we don't actually know why they're absent. That's the part that — wait, I don't think the reporting tells us whether they were asked, declined, or are still deciding. Silence covers all three.

Brian Reed: That's genuinely unresolved.

Eliza Ward: Right. So the question that survives everything we just covered — if they join, SAFE's reach expands overnight. If they don't, the RFC ratifies into a standard that doesn't touch the highest-risk deployments. And SAFE is still a request for comments as of August 6th. The distance from RFC to anything compulsory — nobody with authority to close that gap has stepped into it.

Brian Reed: Enough to watch. Not enough to call.