A major industry coalition created to protect critical open-source software from AI-driven cyber threats expects to launch its vulnerability disclosure and remediation platform in September, according to Infosecurity Magazine. The initiative, named Akrites, was established in late June 2026 by the Linux Foundation and the Open Source Security Foundation (OpenSSF) alongside more than 20 founding members. The coalition brings together AI frontier labs, cloud and tech giants, cybersecurity firms, and large enterprises to coordinate responses to AI-enabled vulnerability reports in open-source projects.

The founding members include AI companies Anthropic and OpenAI; technology firms Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat, and NVIDIA; cybersecurity providers Chainguard, Endor Labs, and Zscaler; plus major enterprises Citi, JPMorgan Chase, Ericsson, and Vodafone. Each coalition member must contribute between one and 10 engineers to the effort and pay membership fees corresponding to one of three tiers—Associate, General, or Premier—with each tier offering different levels of benefits. Christopher 'CRob' Robinson, OpenSSF's chief technology officer and chief security architect, was named CTO of Akrites in June and told Infosecurity he has already received thousands of vulnerability reports in the two months since launch, with roughly 30% being duplicates. The initiative's main platform will be built on Carnegie Mellon University's Vulnerability Information and Coordination Environment (VINCE), a vulnerability management system developed in 2020 by the Computer Emergency and Response Team Coordination Center (CERT/CC).

Robinson described Akrites' core mission as "coordinating AI-enabled vulnerability reports to upstream open-source maintainers so that the fixes are available to the whole ecosystem." The team building the initiative's tooling, including the vulnerability management and shared security incident response team (SIRT) platform, has now completed the first draft of the tool chain, according to the report. Robinson added that "we have a substantial amount of additional capabilities leveraging large language models (LLMs) to do deduplication, patch creation and more." The platform is currently undergoing a penetration test and security audit by experts from Akrites member organizations, followed by testing with a mix of real and synthetic data to verify it functions as designed. Once completed, the finished platform will be open-sourced and available for anyone to use for their own purposes.

The Akrites platform addresses a pressing challenge: the explosion of AI-enabled vulnerability reports flooding open-source projects. The initiative was launched with two major goals—establishing a shared security incident response team for mitigating and remediating vulnerabilities in open-source packages and libraries, and developing a standardized coordinated vulnerability disclosure process built on confidentiality-first principles and industry-standard tooling. By centralizing the intake and coordination of automated vulnerability reports, Akrites aims to prevent maintainers of critical open-source software from being overwhelmed by duplicate reports while ensuring fixes reach the entire ecosystem efficiently. Robinson said he has been trying to create something like Akrites throughout his career, adding that "I feel right now we have the tools, the willpower and access to the technical experts, so I'm very optimistic on our chances that we're going to be able to provide a very valuable service to the global open-source ecosystem." The platform is expected to begin accepting automated vulnerability reports when it goes live in September. The success of this centralized approach could determine whether the open-source community can scale its security response to match the accelerating pace of AI-discovered vulnerabilities. If Akrites fails to streamline the coordination process effectively, maintainers may face an untenable burden that leaves critical infrastructure exposed.