AI Policy Wiki
Dashboard

Akrites

medium confidence · updated 2026-07-05

Linux Foundation-convened industry coalition (launched June 25, 2026) to find, fix, and responsibly disclose vulnerabilities in critical open-source software in the era of AI-assisted vulnerability discovery; founding members include AWS, Anthropic, Google, Microsoft/GitHub, Nvidia, OpenAI, Citi, and JPMorganChase.

Akrites is a coordinated industry effort, convened by the Linux Foundation and announced June 25, 2026, to remediate and responsibly disclose vulnerabilities in the open-source software that critical infrastructure depends on, in response to the acceleration of vulnerability discovery by frontier AI models (Source: linuxfoundation.org).

Overview

The initiative's stated premise is that frontier AI models can now scan a major open-source project and surface vulnerabilities in minutes — work that previously demanded expert effort over weeks — and that once such capabilities are broadly available, actors who previously lacked the expertise to mount sophisticated attacks will be able to do so quickly. Akrites establishes a shared Security Incident Response Team (SIRT) and a single, standardized Coordinated Vulnerability Disclosure (CVD) process, built on confidentiality-first principles and established industry tooling (CVE, TLP, CWE, CVSS, EPSS, SSVC, VEX) (Source: linuxfoundation.org).

Founding commitments came from Amazon Web Services, Anthropic, Chainguard, Cisco, Citi, Endor Labs, Ericsson, Google, IBM, JPMorganChase, Microsoft and GitHub, Nvidia, OpenAI, RapidFort, Red Hat, the Rust Foundation, Sonatype, Vodafone, and Zscaler — a membership spanning major technology companies, frontier AI labs, financial institutions, and security vendors. Alpha-Omega, a directed fund of the Linux Foundation, provides seed funding. To mark the launch, the founding signatories published a joint open letter, "We All Depend on Open Source. We Will Defend It Together." (Source: linuxfoundation.org).

Activities

The initiative describes its operating model as a single trusted place to coordinate, remediate, and disclose: the shared SIRT is intended to act as a predictable partner for open-source maintainers rather than a flood of uncoordinated, duplicative vulnerability reports, replacing a prior pattern in which organizations worked the same problems independently and sometimes shipped conflicting patches. Fixes flow back into each project's original home on maintainers' terms; where a critical package has no active maintainer, Akrites states it will serve as maintainer of last resort. The initiative also commits to working with critical-infrastructure operators on patch deployment before vulnerable systems can be targeted, and to coordinating with government defense efforts (Source: linuxfoundation.org).

Member statements at launch frame the scale of the problem: Endor Labs stated that of the thousands of validated open-source vulnerabilities surfaced in recent months, fewer than 5% had been patched, and Anthropic's deputy CISO Jason Clinton said the existing coordinated-disclosure model "has been outpaced by how quickly AI can now find vulnerabilities." OpenAI cited its "Patch the Planet" program as complementary work putting its models behind maintainer-led fixes (Source: linuxfoundation.org).

The launch came within a week of the first reported ransomware attack run end-to-end by an AI agent (the JADEPUFFER campaign exploiting a Langflow remote-code-execution flaw, disclosed by Sysdig on July 2, 2026), an incident illustrating the offensive side of the AI-vulnerability dynamic the coalition was formed to counter (Source: thehackernews.com).

Relationships