A coalition of major tech companies led by the Linux Foundation has teamed up to tackle rapidly emerging threats to open-source software fueled by AI. The initiative, called Akrites, was launched on June 25, 2026, bringing together giants like Anthropic, OpenAI, AWS, Microsoft, Google, IBM, and NVIDIA.
At the core of Akrites are two key tools: a unified Security Incident Response Team (SIRT) and a standardized Coordinated Vulnerability Disclosure process that aligns with established frameworks such as CVE and CVSS. This approach aims to streamline how vulnerabilities in popular open-source projects are reported, assessed, and addressed.
The initiative receives initial funds from the Alpha-Omega fund and welcomes contributions in both engineering talent and financial support to scale its impact. On release, the alliance highlighted a stark statistic: less than 5% of security flaws identified in open-source software had been patched by the end of June.
Why Artificial Intelligence Accelerates Risks
Traditional security audits that once took weeks can now be conducted in minutes thanks to advanced AI systems capable of swiftly detecting weaknesses. This speed shifts the security landscape dramatically, making coordinated defenses like Akrites critical.
In a joint statement titled “We All Depend on Open Source. We Will Defend It Together,” the founding members emphasized the necessity of shared infrastructure backed by collective defense efforts.



