Skip to content

Security1 publisher3 min readPublished

Akrites switches on in September with 20-odd members and a one-to-10 engineer donation band

The Linux Foundation's coalition for AI-generated vulnerability reports starts taking automated submissions next month. Its membership terms set the ceiling on what it can absorb.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Akrites is expected to operationalize its vulnerability disclosure and remediation platform in September, according to Infosecurity.
  • The initiative, called Akrites, was launched at the end of June 2026 by the Linux Foundation, the Open Source Security Foundation (OpenSSF) and over 20 founding members.
  • Founding members include AI frontier labs Anthropic and OpenAI.
  • Other founding members include Amazon Web Services, Cisco, Google, Microsoft and its subsidiary GitHub, IBM and its subsidiary Red Hat, NVIDIA, Chainguard, Endor Labs, Zscaler, Citi, JPMorganChase, Ericsson and Vodafone.
  • Each member of the coalition must donate between one and 10 engineers to the project.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Akrites, the coalition the Linux Foundation and the Open Source Security Foundation stood up at the end of June 2026 to handle AI-enabled vulnerability reports against critical open source, is expected to operationalize its disclosure and remediation platform in September and begin taking automated reports, according to Infosecurity [1][2][17]. That gives maintainers a date; the coalition's membership terms give them something more useful, which is a rough bound on the human capacity behind the promise [5][6].

Every member must donate between one and 10 engineers to the project and pay fees according to one of three tiers, Associate, General and Premier, each with its own benefit level [5][6]. With more than 20 founding members, the nominal engineering pool runs from roughly 20 people at the floor to roughly 200 at the ceiling [1]. That is an order-of-magnitude band, which means the headline membership count tells a maintainer very little on its own. The signatories include Anthropic and OpenAI [3], alongside Amazon Web Services, Cisco, Google, Microsoft, GitHub, IBM, Red Hat, NVIDIA, Chainguard, Endor Labs, Zscaler, Citi, JPMorganChase, Ericsson and Vodafone [4]. The labs whose tooling helps generate the report volume are funding the body that has to absorb it.

The demand side is already measurable. Christopher "CRob" Robinson, OpenSSF's CTO and chief security architect, who was appointed Akrites CTO in June [9], told Infosecurity he has received thousands of vulnerability reports in the two months since launch, an estimated 30% of them duplicates [14]. That puts the intake figure at roughly late August 2026 [2], and means about one report in three is redundant work arriving before triage even starts [3]. Robinson described the initiative's sole mission as coordinating AI-enabled vulnerability reports to upstream maintainers so that fixes reach the whole ecosystem [10]. At launch the Linux Foundation set out two missions: a shared security incident response team for open-source packages and libraries [7], and a standardized coordinated vulnerability disclosure process built on confidentiality-first principles and industry-standard tooling [8].

The tooling is not finished. Robinson said the team has produced the first draft of the tool chain [11], with the main platform based on Carnegie Mellon University's VINCE, a vulnerability management system built in 2020 by CERT/CC, a unit of the university's Software Engineering Institute [12]. On top of that sit what he called substantial additional capabilities using large language models for deduplication, patch creation and more [13]. Experts from member organisations are now running a penetration test and a security audit, after which the tools will be augmented to accept a mix of real and synthetic data to confirm they behave as designed [15]. The finished platform is to be open-sourced for anyone to use [16].

Three things worth tracking. Whether the September go-live holds once the penetration test and audit findings land [15][17]. Whether the tiered fee structure converts into sustained engineer-months rather than nominal secondments, since the one-to-10 band leaves the real figure unknowable from outside [5][1]. And whether the duplicate rate moves once the LLM deduplication layer is in production, because a 30% waste rate against thousands of reports is the number that decides whether a shared response team relieves maintainers or simply relays the flood [13][14].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories