The SAFE proposal is a new incident-reporting framework for AI agent systems, backed by over 120 organizations. It specifies nine categories of evidence that must be preserved after a reportable event: prompts, execution traces, tool calls, agent identities, permissions, human approval events, and more. This looks like an evidence policy. But specifying what a legible incident contains is also specifying what, if absent, makes an event institutionally invisible. The evidence list doesn't just describe incidents. It determines which ones exist.
Aviation learned something about this. The ASRS reporting system doesn't just ask pilots to report safety events. It routes reports to NASA rather than the FAA, strips identifying information before anyone else sees it, returns proof of filing to the reporter, and waives penalties for inadvertent violations disclosed within ten days. Each of those design choices addresses a specific reason a rational person would choose silence over disclosure. The result: over a million reports filed across decades, with no reporter's identity ever compromised. The incentive architecture is what produces the information.
SAFE has defined what the sensor should detect. The question worth asking is whether anyone, absent enforcement protection or structural anonymity, has a reason to activate it.
ASRS vs. SAFE: where disclosure incentives stand
Independent recipient? ASRS: NASA, not the FAA. SAFE: No independent third party; reports go to the alliance itself.
Identity protection? ASRS: Structural de-identification; ID strip returned to reporter, not retained. SAFE: De-identification listed as a design principle, not yet implemented.
Enforcement protection? ASRS: FAA waives fines for inadvertent violations reported within 10 days. SAFE: No formal safe harbor shielding companies that disclose.
Exclusions from protection? ASRS: Criminal offenses, accidents, deliberate violations, repeat offenders. SAFE: Not yet applicable since no protection exists to bound.
Status: SAFE remains in RFC stage as of August 2026. The coalition is relying on cybersecurity's existing culture of threat-intelligence sharing to motivate voluntary disclosure.

