Thought Leadership: Security and Vendor response
AI Openness: 3 Years on from Llama 2 Report
A common architecture has emerged across the companies now selling responses to AI-discovered vulnerabilities. Findings produced by frontier models are pooled into a private clearing house, fixes are developed and validated under embargo, and remediated packages reach paying subscribers or vetted coalition members ahead of public disclosure. The justification is that a published patch can be reverse-engineered into a working exploit within hours, so prompt public disclosure now favours the attacker. In effect, the security of open source software will now increasingly be mediated by commercial subscriptions and membership schemes, with access to models capable of finding the flaws itself being rationed by verification regimes.
Chainguard: Athena
Chainguard launched Athena on 15 June 2026 with members including BNY, Cisco, Cloudflare, Corridor, DepthFirst, Docker, JPMorganChase, Kyndryl, LTIMindtree and PwC as a coalition for the orchestrated defence of open source software. Members submit pre-disclosure findings, many of them generated through Anthropic’s Project Glasswing and OpenAI’s Daybreak, through an encrypted portal. Submitters choose the sharing scope and embargo timeline. Athena deduplicates and enriches the findings, traces when a flaw was introduced and whether it is already fixed at head, and publishes the resulting metadata as an OSV feed. Patched builds and hardened private forks reach members through Chainguard Libraries before public disclosure. The commercial mechanism sits alongside the coalition and fixes generated are available to Chainguard customers as a product before it is available to everyone else as a public release. At launch Chainguard reported more than 20,000 findings processed and over 2,000 patches shipped across 500 projects; three weeks later it reported over 40,000 vulnerabilities processed, of which it says 42% were critical or high severity and 86% network reachable, and added Akamai, JFrog, Morgan Stanley and Qualys as members.
IBM and Red Hat: Lightwell
IBM and Red Hat announced Project Lightwell on 28 May 2026 as a $5B commitment backed by more than 20,000 engineers to address a specific operational problem – the standard remedy for a vulnerable dependency is to upgrade to a fixed upstream release. Large organisations running older or heavily customised versions in production frequently cannot or do not wish to do this. Lightwell backports fixes to the versions customers already run, shipping them as digitally signed, certified artefacts with SBOMs delivered into existing build pipelines. Lightwell Network is generally available on an annual subscription whilst Lightwell Clearinghouse Premier is restricted at launch to financial services, with expansion to
government, healthcare and telecommunications planned in later phases. Partners include Bank of America, BNY, Citi, Goldman Sachs, JPMorganChase, Mastercard, Morgan Stanley, Royal Bank of Canada, State Street, Visa and Wells Fargo. Red Hat’s upstream-always commitment sees fixes developed for Lightwell submitted back to the originating project for review and acceptance, which is intended to prevent the catalogue from becoming a permanent private fork of the public ecosystem.
OpenAI: Daybreak
OpenAI’s launched Daybreak, launched on 11 May 2026 making Standard GPT-5.5 generally available; GPT-5.5 with Trusted Access for Cyber is shared only with verified defenders for authorised defensive work; and the more permissive GPT-5.5-Cyber is reserved for approved workflows such as red teaming and exploit validation. Approval is discretionary, turning on identity verification, intended use and organisational capability, and may not be extended to third-party or customer-facing traffic.
OpenAI presents this limitation of distributions as an alternative to withholding capability.
The openly directed component, Patch the Planet, funds researchers and equips them with Codex Security to carry findings through to merged fixes, with more than 30 projects committed including cURL, Go, Python and Sigstore, and an early five-day sprint producing dozens of merged fixes. It is the only part that transfers capability to maintainers rather than to their downstream consumers, and it is small beside the commercial tiers.
Anthropic
Anthropic has taken the opposite approach by keeping Claude Mythos Preview restricted under Project Glasswing on safety and national security grounds.
The Volume Claim
The vendors’ case rests on vast figures for vulnerabilities that are largely self-reported and not directly comparable. Chainguard’s June 2026 quarterly report records 18,016 vulnerability instances across 886 distinct CVEs in its customer base, with high-severity findings 63.1% of instances, a rise of 13% on the preceding quarter. Anthropic estimated that its tooling surfaced 6,202 high- or critical-severity issues across more than 1000 open source projects. IBM’s Lightwell cites the Mythos Preview model as identifying 3,900 high- or critical-severity vulnerabilities in open source software.
GitHub published 1,560 reviewed advisories in May 2026 and processed more than 6,000 advisory decisions a month between March and May, while still reporting that incoming private reports, repository advisories and CVE requests exceeded its review capacity.
Impact on Openness
The three commercial responses narrow access in order to widen protection through limiting access to the models gated by verification, in OpenAI’s case through Trusted Access and in Anthropic’s through outright restriction. Then access to fixes is gated by subscription or membership, through Lightwell’s tiers and Chainguard Libraries. Both are on the same reasoning, that publication in the current conditions arms attackers faster than it protects defenders.
That reasoning is not obviously wrong. Its cost is that the remediation of a public commons is now being performed first for the organisations that can pay for it, with upstream contribution as a consequence rather than the primary channel. The upstream-always commitments are attempts to prevent that outcome, and it is too early to say whether they are sufficient. What is measurable is the interval between a member receiving a hardened build and the corresponding fix landing in the public upstream repository, together with the proportion of processed findings that reach an upstream merge at all. Neither figure is currently published by any vendor.
Conclusion
Security work on open source is moving from a public activity to one intermediated by commercial clearing houses sharing first with paying members, rationing either the models that find flaws or the fixes that resolve them, each paired with a commitment to return value upstream on the basis that machine- generated findings now exceed what maintainer communities can absorb. They suggest that pooling under embargo is the only workable answer. Its corollary is that the commons becomes dependent on the arrangement, and that those able to pay are served first on software everyone else relies on. Whether this becomes accepted practice requires two unreported measures: the interval between a member receiving a hardened build and the fix reaching the public repository, and the share of processed findings that reach an upstream merge at all.
At the time of publication, the technology press shared that Microsoft is preparing to launch Project Perception to compete with these products in securing open source.
First published by OpenUK in 2026 as part of AI Openness: 3 Years on from Llama 2
©OpenUK2026 ![]()
Download Thought Leadership Download Report View all thought leadership

