Tech

OpenAI and Trail of Bits launch Patch the Planet to bolster open-source security

In its first week, the partnership has engaged 19 major projects, identifying hundreds of legitimate bugs and fixing 19 issues using OpenAI’s GPT-5.5-Cyber and Codex Security models.

Author
Owen Mercer
Markets and Finance Editor
Published
Draft
Source: Engadget · original
OpenAI's new Daybreak⁠ initiative will help open-source projects fend off bugs
New initiative under Daybreak program aims to reduce maintainer burden by filtering false positives before they reach developers

OpenAI has officially launched Patch the Planet, a new cybersecurity initiative operating under its broader Daybreak program, designed to assist open-source projects with bug identification and remediation. The effort is a strategic partnership with cybersecurity firm Trail of Bits, which has committed its entire security research organisation to the project. The initiative seeks to alleviate the pressure on open-source maintainers by deploying AI tools to pre-screen vulnerabilities and filter out false positives before they reach stretched-thin development teams.

The program utilises OpenAI’s GPT-5.5-Cyber and Codex Security models to help researchers identify vulnerabilities and review findings. By having security engineers use these AI tools to sift through potential issues, the initiative aims to reduce the analysis time from hours to minutes. Researchers then collaborate directly with project maintainers to develop and test patches, as well as to establish workflows that allow teams to continue improving their security posture independently.

During its first week of operation, the initiative worked with 19 open-source projects, including cURL, the Go project, and Python. According to Trail of Bits, the security engineers discovered hundreds of legitimate bugs across these codebases. Of the 51 specific issues identified in that initial period, 19 have already been fixed, demonstrating the immediate utility of the AI-assisted workflow.

The participating projects in the first round include cURL, NATS Server, pyca/cryptography, Sigstore, aiohttp, the Go project, freenginx, Python, and python.org. OpenAI has indicated that additional projects will join in future rounds of the initiative, expanding the scope of the security support provided to the open-source community.

OpenAI launched the broader Daybreak program in May as a response to Anthropic’s Project Glasswing. The company positioned Daybreak on the premise that cyber defence should be integrated into software from the start, rather than focusing solely on finding and fixing vulnerabilities after the fact. The overarching goal is to enable the quick generation and testing of patches within repositories, fundamentally changing how open-source security is managed.

While the initiative reports significant early success, the scale of findings requires careful interpretation. The term "hundreds of legitimate bugs" may encompass duplicate findings across different codebases, and the specific model designation GPT-5.5-Cyber remains an internal or cybersecurity-tuned variant not widely documented in public product lineups. Nevertheless, the partnership marks a significant step in applying generative AI to critical infrastructure security.

Trail of Bits noted in its announcement that while models like GPT-5.5-Cyber can produce a high volume of security findings, they often contain false positives. This places a considerable burden on maintainers who must manually verify each alert. By inserting a layer of expert review supported by AI, Patch the Planet aims to streamline this process, ensuring that only verified, actionable vulnerabilities are presented to project teams.

The initiative reflects a growing trend in the technology sector where major AI developers are expanding their focus beyond consumer applications into enterprise and infrastructure security. By partnering with established cybersecurity firms like Trail of Bits, OpenAI is attempting to validate its models in high-stakes environments where accuracy and reliability are paramount.

As the open-source ecosystem continues to underpin much of the global digital infrastructure, the security of these foundational projects remains a critical concern. The Patch the Planet initiative offers a new model for collaboration between AI developers, security researchers, and open-source maintainers, potentially setting a precedent for how future security challenges are addressed.

OpenAI’s move into this space comes at a time when cyber threats are becoming increasingly sophisticated. By leveraging AI to accelerate the detection and remediation of vulnerabilities, the company hopes to demonstrate the practical value of its technology in protecting the digital commons. The results of the first week suggest that this approach has merit, though long-term sustainability and scalability will be key metrics for success.

The initiative also highlights the competitive dynamics between leading AI firms. With Anthropic’s Project Glasswing serving as a direct competitor, OpenAI is keen to showcase the capabilities of its Daybreak program. The focus on open-source security allows OpenAI to position itself as a supporter of the broader technology community, rather than just a commercial entity.

As more projects join the initiative, the data generated will likely provide valuable insights into the effectiveness of AI-assisted security workflows. This information could inform future developments in both AI model training and cybersecurity best practices, potentially leading to more robust and resilient software ecosystems.

The success of Patch the Planet will depend on the continued engagement of open-source maintainers and the ability of the AI models to accurately identify and remediate vulnerabilities. If the initiative can maintain its early momentum and expand its reach, it could become a vital resource for the open-source community, helping to secure the software that powers much of the modern internet.

Continue reading

More from Tech

Read next: Open-source tool claims 97 per cent token savings for AI agents
Read next: Valvoline Unveils August 2026 Promotional Offers for Service and Retail Buyers
Read next: Developer Antirez releases native MiniMax H3 inference engine for Apple Silicon