From 96c0244e29035135fdfcb1fd449f308a5635a2ef Mon Sep 17 00:00:00 2001 From: gabacca Date: Wed, 5 Aug 2026 16:00:46 +0200 Subject: [PATCH 1/3] Add public-interest participation, inclusive pilots, and public-by-default lessons Adds multilateral/public-interest institutions to Scope and Membership, a geographic-inclusion principle for pilots to Guiding Principles, and a public-by-default presumption for de-identified lessons to the Disclosure Model. Signed-off-by: Gabriel Accascina --- rfc-safe-proposal.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/rfc-safe-proposal.md b/rfc-safe-proposal.md index 8a3954f..9f556d9 100644 --- a/rfc-safe-proposal.md +++ b/rfc-safe-proposal.md @@ -21,8 +21,10 @@ SAFE should include representatives from: * Critical-infrastructure operators * Civil-society and affected-user representatives * Government and standards bodies as non-controlling observers +* Multilateral and regional public-interest institutions, in a non-controlling capacity, with standing to contribute to governance design, incident taxonomies and schemas, geographically inclusive pilots, capacity-building and dissemination of de-identified lessons SAFE should operate independently so that no vendor or industry segment controls its findings. Its processes apply equally to open and closed AI systems. Open systems are not automatically safe, and closed systems are not safe by declaration. Trust is not a control; shared evidence and verifiable improvement are how trust is earned. +Standing for public-interest institutions does not entail control, veto power or access to identifiable reports; it means an established right to participate in relevant working groups, propose agenda items, contribute evidence and help shape how SAFE's learning reaches the wider international community. # Guiding Principles @@ -31,6 +33,7 @@ SAFE should operate independently so that no vendor or industry segment controls * **Risk-based response.** Reporting, disclosure and escalation should reflect actual risk. * **Member sovereignty.** SAFE establishes minimum interoperability and assurance practices without superseding members’ internal security policies or legal obligations. * **Learning is separate from enforcement.** Confidential review should encourage candid reporting, while regulators and affected parties retain their legal rights. +* **Geographic inclusion.** SAFE pilots and early implementation activities should include organizations from geographically and institutionally diverse settings, including regions currently underrepresented in AI security and assurance initiatives. # Reporting Compact @@ -94,6 +97,7 @@ The affected organization may correct factual errors but should not have veto po 1. Confidential rapid alert: Immediate indicators, containment steps and affected patterns for trusted members. 2. Member operating advisory: De-identified analysis, implicated controls, tests and recommended actions. 3. Public safety report: Root causes, systemic lessons, recommendations and adoption metrics after sensitive details are removed. +4.De-identified systemic lessons, defensive recommendations, verification methods, tests, machine-readable policies, detection rules, reference configurations and catalog entries should be public by default. Publication may be restricted only where disclosure of specific information presents a concrete, foreseeable and material risk to affected individuals, vulnerable systems, reporter confidentiality, legitimate legal rights or an active investigation. Reputational harm, commercial disadvantage, embarrassment or the possibility of regulatory scrutiny should not, by themselves, justify withholding. Restrictions should use the least restrictive available measure, including redaction, aggregation or delayed publication rather than complete suppression. The decision and its evidentiary basis should be documented, subject to independent review, time-limited and reconsidered at defined intervals. Where possible, SAFE should publish notice that material has been withheld, the general category of risk involved and the date of the next review. SAFE should adopt the strongest features of confidential safety-reporting systems: voluntary and prompt reporting, non-punitive treatment of honest mistakes, de-identification where appropriate and exclusion of intentional or criminal conduct from protection. From 046013df294ec9290026e939fb4bc200d83243ec Mon Sep 17 00:00:00 2001 From: gabacca Date: Wed, 5 Aug 2026 16:11:35 +0200 Subject: [PATCH 2/3] Fix formatting of item 4 in RFC proposal --- rfc-safe-proposal.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/rfc-safe-proposal.md b/rfc-safe-proposal.md index 9f556d9..35e44a9 100644 --- a/rfc-safe-proposal.md +++ b/rfc-safe-proposal.md @@ -97,7 +97,7 @@ The affected organization may correct factual errors but should not have veto po 1. Confidential rapid alert: Immediate indicators, containment steps and affected patterns for trusted members. 2. Member operating advisory: De-identified analysis, implicated controls, tests and recommended actions. 3. Public safety report: Root causes, systemic lessons, recommendations and adoption metrics after sensitive details are removed. -4.De-identified systemic lessons, defensive recommendations, verification methods, tests, machine-readable policies, detection rules, reference configurations and catalog entries should be public by default. Publication may be restricted only where disclosure of specific information presents a concrete, foreseeable and material risk to affected individuals, vulnerable systems, reporter confidentiality, legitimate legal rights or an active investigation. Reputational harm, commercial disadvantage, embarrassment or the possibility of regulatory scrutiny should not, by themselves, justify withholding. Restrictions should use the least restrictive available measure, including redaction, aggregation or delayed publication rather than complete suppression. The decision and its evidentiary basis should be documented, subject to independent review, time-limited and reconsidered at defined intervals. Where possible, SAFE should publish notice that material has been withheld, the general category of risk involved and the date of the next review. +4. De-identified systemic lessons, defensive recommendations, verification methods, tests, machine-readable policies, detection rules, reference configurations and catalog entries should be public by default. Publication may be restricted only where disclosure of specific information presents a concrete, foreseeable and material risk to affected individuals, vulnerable systems, reporter confidentiality, legitimate legal rights or an active investigation. Reputational harm, commercial disadvantage, embarrassment or the possibility of regulatory scrutiny should not, by themselves, justify withholding. Restrictions should use the least restrictive available measure, including redaction, aggregation or delayed publication rather than complete suppression. The decision and its evidentiary basis should be documented, subject to independent review, time-limited and reconsidered at defined intervals. Where possible, SAFE should publish notice that material has been withheld, the general category of risk involved and the date of the next review. SAFE should adopt the strongest features of confidential safety-reporting systems: voluntary and prompt reporting, non-punitive treatment of honest mistakes, de-identification where appropriate and exclusion of intentional or criminal conduct from protection. From 0488ee3186007497578da0c6b7f5acc3951889bf Mon Sep 17 00:00:00 2001 From: gabacca Date: Tue, 11 Aug 2026 18:08:40 +0200 Subject: [PATCH 3/3] Add auditable disclosure restriction lifecycle Expanded on publication restrictions and decision-making processes for de-identified systemic lessons and recommendations. Added requirements for machine-readable disclosure restriction records and active restriction criteria. Signed-off-by: Gabriel Accascina --- rfc-safe-proposal.md | 23 ++++++++++++++++++++++- 1 file changed, 22 insertions(+), 1 deletion(-) diff --git a/rfc-safe-proposal.md b/rfc-safe-proposal.md index 35e44a9..a367de6 100644 --- a/rfc-safe-proposal.md +++ b/rfc-safe-proposal.md @@ -97,7 +97,28 @@ The affected organization may correct factual errors but should not have veto po 1. Confidential rapid alert: Immediate indicators, containment steps and affected patterns for trusted members. 2. Member operating advisory: De-identified analysis, implicated controls, tests and recommended actions. 3. Public safety report: Root causes, systemic lessons, recommendations and adoption metrics after sensitive details are removed. -4. De-identified systemic lessons, defensive recommendations, verification methods, tests, machine-readable policies, detection rules, reference configurations and catalog entries should be public by default. Publication may be restricted only where disclosure of specific information presents a concrete, foreseeable and material risk to affected individuals, vulnerable systems, reporter confidentiality, legitimate legal rights or an active investigation. Reputational harm, commercial disadvantage, embarrassment or the possibility of regulatory scrutiny should not, by themselves, justify withholding. Restrictions should use the least restrictive available measure, including redaction, aggregation or delayed publication rather than complete suppression. The decision and its evidentiary basis should be documented, subject to independent review, time-limited and reconsidered at defined intervals. Where possible, SAFE should publish notice that material has been withheld, the general category of risk involved and the date of the next review. +4. De-identified systemic lessons, defensive recommendations, verification methods, tests, machine-readable policies, detection rules, reference configurations and catalog entries should be public by default. Publication may be restricted only where disclosure of specific information presents a concrete, foreseeable and material risk to affected individuals, vulnerable systems, reporter confidentiality, legitimate legal rights or an active investigation. Reputational harm, commercial disadvantage, embarrassment or the possibility of regulatory scrutiny should not, by themselves, justify withholding. Restrictions should use the least restrictive available measure, including redaction, aggregation or delayed publication rather than complete suppression. Each restriction decision should be represented by a small machine-readable disclosure restriction record containing, at minimum: + + * `decision_id` and the relevant finding or incident reference + * the material or fields being restricted + * the risk category and evidence references supporting the risk claim + * the least-restrictive measure selected (`redaction | aggregation | delay | suppression`) + * the decision-maker and independent reviewer + * `decided_at`, `review_at` and/or `expires_at` + * current status and reference to any superseded decision + * a transition history recording each change of status, with reason, timestamp and relevant evidence references + + An active restriction should satisfy, at minimum: + + `restriction_active -> evidence_basis_present && independent_review_recorded && review_or_expiry_time_present` + + Restriction lifecycles should use explicit states such as: + + `restricted -> partially_published -> published` + + with the reason, timestamp and relevant evidence references recorded for each transition. + + Because the complete restriction record may itself contain sensitive evidence, SAFE should maintain a public-facing subset containing, at minimum, the decision identifier, affected material category, general risk category, restriction type, current status, decision date, and review or expiry date. If publication of a specific field would itself create the documented risk, that field may be withheld. Withholding the public notice itself should require documented justification. SAFE should adopt the strongest features of confidential safety-reporting systems: voluntary and prompt reporting, non-punitive treatment of honest mistakes, de-identification where appropriate and exclusion of intentional or criminal conduct from protection.