Akrites Security Body: AI tools have gotten remarkably good at finding security flaws in open-source software — so good, in fact, that the old way of reporting and fixing them can no longer keep up. Some of the biggest names in tech just decided the answer is to stop working separately and start coordinating.
Table of Contents
What Is Akrites?
According to The New Stack’s report, the Linux Foundation has launched Akrites, a coordinated body dedicated to discovering, fixing, and disclosing vulnerabilities in critical open-source software before attackers can exploit them. The name comes from the Akritai — soldiers who once guarded the Byzantine Empire’s most exposed frontier borders, a fitting metaphor for defending the software infrastructure the internet quietly depends on.
| Detail | Information |
|---|---|
| Host organization | Linux Foundation |
| Founding members | ~20 organizations |
| Notable members | Anthropic, Google, Microsoft/GitHub, OpenAI, AWS, Cisco, Red Hat, Nvidia, Chainguard |
| Core function | Shared Security Incident Response Team (SIRT) |
| Funding source | Alpha-Omega (OpenSSF project), $7M+ annual budget |
| Membership tiers | Premier, General, Associate (free for open-source foundations) |
Why This Is Happening Now
The launch follows a turbulent stretch in AI-driven cybersecurity. Anthropic had released its Claude Mythos and Fable 5 models specifically for cybersecurity defense work, only for the US government to suspend access to both just days later after researchers found a way to misuse them for cyberattacks. Anthropic — notably one of Akrites’ founding members — appears to be channeling that experience directly into this new collaborative effort.
Endor Labs CEO Varun Badhwar, a founding member, said AI tools have already surfaced thousands of validated open-source vulnerabilities in recent months, with fewer than 5% actually patched. As he put it, finding vulnerabilities was never the hard part — fixing them at scale, fast enough, was.
The Real Problem: Duplicate Reports, Buried Signals
Before Akrites, the open-source security model relied on a loose network of researchers and organizations independently scanning the same widely used libraries. When several organizations report the same flaw separately, maintainers get buried under duplicate noise, and genuinely exploitable issues risk getting lost. Worse, every extra party holding knowledge of an unpatched vulnerability increases the odds it leaks before a fix exists.
Anthropic deputy CISO Jason Clinton summed up the shift bluntly: the existing coordinated disclosure model has been outpaced by how fast AI can now find vulnerabilities.
How the Process Actually Works
| Step | What Happens |
|---|---|
| 1. Discovery | Findings from member organizations flow into a shared SIRT |
| 2. Validation | SIRT confirms which findings are genuine and exploitable |
| 3. Fix Coordination | A single coordinated fix is developed, avoiding duplicate reports |
| 4. Disclosure | Patch goes back to the project on the maintainer’s terms |
| 5. Fallback | Akrites steps in directly for unmaintained projects |
JPMorgan Chase CISO Pat Opet framed the goal clearly: maintainers deserve one reliable signal — confirmed vulnerabilities and well-tested fixes — rather than a flood of conflicting reports from a dozen different sources.
The Bottom Line
Akrites represents a rare moment of direct cooperation between rival tech giants, banks, and infrastructure companies, all betting that AI’s vulnerability-discovery speed demands a centralized, coordinated response rather than a fragmented one. With heavyweight backing from Anthropic, Google, Microsoft, OpenAI, and major financial institutions, this initiative could meaningfully reshape how critical open-source software gets patched in the AI era — assuming the coordination holds up under real-world pressure.
For more updates on AI safety and industry collaboration efforts, check out our AI and tech news section on TechnoSports.





