AI incidents would move on a strict clock under a new draft from the Open Secure AI Alliance: affected organizations notified as soon as possible, customers with exposure within 72 hours, a confidential report within four business days, and a preliminary factual report published within 30 days. Remediation status would follow within 90 days.
The Shared AI Findings Exchange framework, published August 4 by the Linux Foundation, would make alliance members report when an AI system they operate accesses or disrupts a third-party system without authorization, escapes a sandbox or other boundary, or keeps probing a production target after the operator suspects the activity is out of scope. The draft makes clear that intent does not determine whether an event is reportable.
Contributors from Cisco, CrowdStrike, Hugging Face, NVIDIA and Red Hat helped draft the proposal, which was timed to the opening of the Black Hat conference in Las Vegas. The alliance, launched July 27, now counts more than 120 member organizations, with Amazon and Visa among the newest.
Near misses must be reported, not just confirmed harm, and each incident gets reviewed across eight layers of the operating stack, from the model and its instructions through safeguards, tools, environment, monitoring and supply chain. Membership is voluntary but the terms bind those who join, and the draft gives affected organizations the right to correct factual errors without veto power over the learnings.