FTFuture Technology
SECURITY

The Open Secure AI Alliance Wants to Define What Honest Agentic AI Looks Like

· 3 min read · By Nath Connell

Key takeaways

  • The Open Secure AI Alliance has more than 120 member organisations developing the SAFE guidelines
  • SAFE focuses on cybersecurity transparency for agentic AI systems specifically
  • The guidelines aim to establish standards for logging, auditing, and human oversight of AI agent actions
  • The coalition's breadth gives the standards practical weight as many AI developers are helping write the rules

More than 120 organisations have joined something called the Open Secure AI Alliance, and together they are working on a set of guidelines they call SAFE: a framework for cybersecurity transparency in agentic AI systems. The announcement, flagged by NVIDIA Newsroom in early August 2026, represents one of the most significant industry-led attempts to establish norms for a category of AI that is becoming genuinely consequential: autonomous agents that take actions in the real world on behalf of users and organisations.

Agentic AI is the part of the AI story that tends to make security professionals nervous, and for good reason. A language model that answers questions is relatively contained. An AI agent that can browse the web, write and execute code, send emails, make API calls, and chain those actions together over an extended task creates a much larger attack surface. The question of how to build those systems securely, and how to verify that they are behaving as intended, has not had a satisfying answer yet.

What the SAFE Guidelines Are Trying to Do

The SAFE framework appears to focus specifically on cybersecurity transparency rather than the broader question of AI safety, which is an important distinction. Cybersecurity transparency in this context means something like: when an agentic AI system takes an action, can you audit what it did, why it did it, and whether it was authorised to do so?

This is a harder problem than it sounds. Agentic systems often operate through chains of model calls, tool invocations, and sub-agent delegations. Understanding exactly what happened in a complex agentic workflow is not straightforward, and existing logging and auditing tools were not designed with AI agents in mind. If an agentic system is compromised, or makes an error with real-world consequences, the ability to reconstruct what happened is essential.

The SAFE guidelines seem to be proposing standards for how that transparency should be implemented: what should be logged, how logs should be structured, what information should be available to human overseers, and how agents should communicate their capabilities and limitations.

Why 120 Organisations Matters

An industry coalition is only as meaningful as its membership, and 120 organisations is a number worth taking seriously. When you have that breadth, the guidelines that emerge carry practical weight because the companies implementing agentic AI systems are helping write the rules. That is very different from a smaller body of academics or a single vendor proposing standards that others are expected to adopt.

The future, in 3 minutes a day. The biggest tech story explained every morning, free. Get the briefing →

NVIDIA's involvement, signalling through its own newsroom, suggests the guidelines will have relevance for the hardware and platform layer as well, not just the application developers building on top. If NVIDIA's infrastructure products incorporate SAFE-compliant logging or auditing capabilities, that makes compliance much easier for the broader ecosystem.

The involvement of diverse organisations also helps address a coordination problem. Companies building agentic AI systems today are making independent decisions about logging formats, audit mechanisms, and transparency tooling. Without shared standards, the ecosystem becomes fragmented in ways that make security audits, incident response, and regulatory compliance harder for everyone.

The Regulatory Backdrop

This industry-led effort does not exist in a vacuum. Regulators in the EU, UK, and US are all developing frameworks for AI accountability, and agentic AI is specifically on their radar. The EU AI Act, which has been phasing in since 2024, includes provisions around high-risk AI systems that could encompass agentic deployments in sensitive contexts. US executive orders have pushed for AI transparency in federal procurement.

Industry getting ahead of regulation with credible, technically grounded standards is generally a better outcome than waiting for regulators to prescribe technical requirements they may not fully understand. The SAFE guidelines, if they develop into genuinely robust standards adopted across the 120-plus member organisations, could give regulators something to reference rather than something to invent.

The test, as with any industry standard process, will be whether the final guidelines are substantive enough to mean something in practice, or whether they become a checkbox exercise. Given the technical stakes of agentic AI security, the pressure to produce something meaningful is real.

Get the briefing, free

The biggest tech story, explained in 3 minutes every weekday. Choose your briefings →

Free. No spam. Unsubscribe in one click.