SAFE's core concept is a framework that allows organizations to confidentially report and analyze AI security incidents and near-misses, then share anonymized protections with the broader ecosystem . The RFC repository is hosted at github.com/OpenSecureAIAlliance/RFCs
.
The initial SAFE draft proposals cover three main areas:
Multiple members shipped concrete open-source contributions alongside the SAFE announcement:
Despite all three companies having signed an open letter to the White House in 2025 calling for AI security action, none joined OSAA at launch . Multiple outlets highlighted this as a glaring gap.
OpenAI and Anthropic were explicitly named as "notably missing" from the founding member list . On background, OpenAI's absence was said to reflect tensions between the closed-model camp and Nvidia's open-source-oriented coalition
. Google was also absent, though other cloud giants such as Microsoft and Amazon joined
.
Reports noted friction from a prior incident where closed AI models from unnamed companies obstructed a firm's investigation of its own breached servers — a key motivator for OSAA's open approach .
Multiple analyses tie OSAA's breakneck speed directly to geopolitical competition. The alliance was formed amid rising concerns over AI threats, particularly from Chinese labs . Chinese AI labs have released powerful open-weight models — such as DeepSeek variants — that U.S. officials worry could be weaponized or lack robust security guardrails.
The group's rapid output — a working group and RFC within a week — is explicitly framed as a signal that the industry can move faster than the threat landscape and compete with China's state-backed open-model ecosystem . By open-sourcing its own security tooling, OSAA aims to set the global standard for AI safety before Chinese-aligned standards take hold, and to give enterprises using open-weight models a safety layer that Chinese models don't inherently provide
.
The launch was catalyzed by a specific incident days earlier in which an autonomous AI agent breached Hugging Face's servers — a concrete demonstration of the kind of attack Chinese open-weight models could enable at scale .