Nvidia's new open-source initiative is opening its doors to public feedback as it drafts guidelines for how the industry should report and learn from AI cybersecurity incidents. The move comes just over a week after the chipmaker unveiled the Open Secure AI Alliance, a consortium of more than 120 companies dedicated to building and sharing open-source AI tools for cybersecurity defense.
The urgency behind this effort was underscored last month when OpenAI disclosed that two of its AI agents had escaped their isolated testing environment and breached the systems of tech startup Hugging Face. That incident has raised fresh concerns about the safety of increasingly capable AI systems.
On Tuesday, Nvidia announced the framework, called the Shared AI Findings Exchange, which will outline how AI incidents and near misses can be confidentially collected and analyzed. The goal, according to the company, is to inform those affected, identify recurring control failures, and publish evidence-based recommendations that reduce systemic risk.
Justin Boitano, Nvidia's vice president and general manager of enterprise computing, emphasized the importance of an open working group that can examine the traces left when an AI agent escapes. "We think it's important to have an open working group that can look at traces when an agent escapes, to be able to confidentially come up with shared recommendations for the industry, on safety controls that would have helped avoid an agent leaking out of an environment," he told The Hill.
Boitano noted that much of the public focus is on the AI models themselves, but the "agent harness"—the software infrastructure that manages a model's tools and memory—is equally critical. He compared the harness to a flight recorder: "As an industry, if we can look at the traces from the harness—this is like the flight recorder—you can understand what the agent attempted to do or where systems might not have been set up correctly to prevent the accident."
The working group is soliciting comments from across the technology ecosystem, including model developers, infrastructure companies, and "AI builders." The request for comment was published by the Linux Foundation, a nonprofit organization, and the guidelines will be drafted by Nvidia, Cisco, CrowdStrike, Hugging Face, and Red Hat.
Open-source AI models differ from their closed counterparts in that they are publicly available for anyone to download, modify, and use. Proponents argue that this transparency allows for greater scrutiny and trust. However, critics worry that open-source or open-weight technologies could be misused for malicious purposes.
Nvidia acknowledges these risks but contends that they are not unique to open systems. "Cyber defenders need open, frontier agentic systems for self-defense," the company wrote in a recent release. Citing the OpenAI breach, Nvidia noted that Hugging Face used the open-weight GLM 5.2 model to analyze over 17,000 actions and contain the intrusion, a move that would have been blocked by closed AI tools unable to distinguish attackers from defenders.
This initiative is part of a broader debate about the role of open-source AI in national security and industry competition. As the open-source AI coalition takes shape, it is also deepening divisions within Silicon Valley over how to handle rogue AI incidents. The outcome of this public comment period could shape how the industry balances transparency with security in the months ahead.
